4
M. Kutyłowski et al.
Another threat which is specific to ubiquitous systems is the possibility of
tracking a device even if it communicates over encrypted channels: e.g., establishing
a shared key by two devices may enable identifying these devices. Device tracking
may result in various personal threats, ranging from profiling the device holder
(resulting in targeted advertisements) to criminal activities such as stalking and
impersonation. Apart from risks to the individuals, there is a threat of massive
tracking being done for illegal business purposes, organized crime, or subversive
or terrorist purposes, as well suppressing personal freedom. So far, methods for
preventing tracking have not been adequately developed. In this chapter we identify
the aforementioned threats and present some solutions that are feasible in ubiquitous
systems.
The chapter is organized into two main parts. In Sect. 1.2 we focus on the
threat posed by a device designed to leak the user’s secrets via covert channels. As a countermeasure against leaking information in supposedly random
parts of a communication, we propose using a watchdog device. We describe
modifications of cryptographic primitives that allow the use of a watchdog: in
Sects. 1.2.3.1 and 1.2.3.2 we discuss commitments, in Sects. 1.2.3.3 and 1.2.3.4
we focus on generating and answering challenges, and Sect. 1.2.3.5 is devoted to
distance bounding. In Sect. 1.3 a privacy aspect of the protocols is discussed, in
particular we aim to prevent the adversary from identifying a device as partaking in
two different communications. Section 1.3.2 discusses some basic ideas for coping
with communication linking in ubiquitous systems using predistributed keys. In
Sect. 1.3.3 we present a notion of using ‘general pseudonyms’, common to a group
of devices, in order to preserve their privacy, whereas in Sects. 1.3.4 and 1.3.5 we
discuss modifying the transmitted keys by a permanent evolution in the former case,
and by transmitting the identifiers with a pseudorandom perturbation in the latter.
1.2 Malicious Devices and Watchdog Concept
1.2.1 Attacks by Malicious Devices
In ubiquitous systems, controlling hardware devices in terms of their security
features may be a major problem. Methods such as certification of products, strict
manufacturing regimes and controlling the supply chain might be relatively costly
compared with the purpose and application area of such systems. On the other hand,
there are numerous smart methods to cheat users: a device may look inoffensive,
while it may leak secret data to an adversary using various types of covert channels.
In fact, no extra message has to be sent: covert channels can be hidden in regular
innocent-looking messages. The main problem areas are:
1. Protocol steps where random elements are created by a malicious device and
subsequently presented in some form.
2. Erroneous executions where (random) faults in protocol execution may encode
information.
Précédent

- 19/268

Suivant