1 Emerging Security Challenges for Ubiquitous Devices
9
2. the Device chooses r at random, computes s := Enc k (r ) and sends s to the
Watchdog,
3. the Watchdog computes σ := α ⊕ s and sends
• σ to the Reader,
• α to the Device (if necessary, the Watchdog attaches also an opening to the
commitment).
With this approach, the random challenge is r = Dec k (σ ).
For the Device, the final shape of r is unpredictable so there is no way to hide
information in r. On the other hand, the Watchdog cannot influence r (for instance,
enforce repetition of the same r), as α has to be determined before the (random)
ciphertext s is presented to it.
Note that if the random challenge is presented in clear, then a simplified version
of the above procedure can be used.
1.2.3.4 Answers to Challenges
One of the moments when information can be leaked to the adversary is when
the Device is responding to a challenge sent by the Reader by computing some
deterministic algorithm, but any verification procedure for the response requires
knowledge of a key shared by the Reader and the Device. This key must not be
available to the Watchdog due to security reasons. In this case no censorship by the
Watchdog is possible. On the other hand, the Reader may discover the manipulation
when it is already too late, since the malicious message has been already on the air,
available to the adversary.
The solution to this problem is to encrypt the communications from the Watchdog
to the Reader with a random session key that is unknown to the Device. Such an
encryption results in randomization destroying, any covert channel.
The procedure to establish the session key is as follows:
1. the Reader creates a commitment u to a random key z and sends u to the
Watchdog of the Device,
2. at the same time the Reader creates a ciphertext c 0 = Enc k (z ) with the key k
shared with the Device, and sends it to the Device through the Watchdog,
3. the Device decrypts c 0 and reveals z to its Watchdog,
4. the Watchdog checks the correctness of z against the commitment u and chooses
a key z at random,
5. the Watchdog sends Enc z (z) to the Reader,
6. from now on, in the current session all messages forwarded by the Watchdog
from the Device to the Reader are additionally encrypted with the key z.
Note that for the steps 1 and 2 one can apply the procedures from Sects. 1.2.3.2
and 1.2.3.3. Thereby, the protocol can be secured against a malicious Reader as well.
Note also that the Device knows z so it could learn z from Enc z (z). However, the
Précédent

- 24/268

Suivant