1 Emerging Security Challenges for Ubiquitous Devices
11
RBE:
RBE is executed as in the standard protocol except that the
Watchdog, after receiving the ith response A[i] from the
Device, converts it to
A
[i] := A[i] ⊕ B(z)[i]
and forwards A [i] to the Reader.
VERIFICATION: Aside from the usual operations, the Reader additionally
removes the blinding by XORing each A [i] with B(z)[i].
1.3 Privacy
Deploying ubiquitous systems means not only substantial advantages for many
application areas, but at the same time emerging and significant privacy problems.
For instance, if device identifiers are explicitly transmitted when two devices
establish a communication session, then it is relatively easy to create a global
tracking system and misuse the information collected in this way. Note that in the
case of symmetric cryptography, one cannot first securely establish a session key
(e.g., with the Diffie-Hellman protocol), and then send the identifiers encrypted with
this key. Theoretically, parties A and B sharing a symmetric key k may recognize
each other without transmitting any identifier:
1. party A chooses a nonce n at random and for each of its partners i:
(a) chooses a nonce n i at random,
(b) computes M i = Enc k i (n, n i ), where k i is the key shared with this partner,
2. party A broadcasts (n, M 1 , M 2 , . . . , ),
3. party B decrypts each M i with all shared keys it knows; if the first half of the
plaintext is n, then this is the right key and it responds with n i .
The obvious problem with such a protocol is its lack of scalability, so it cannot be
applied in large-scale ubiquitous systems.
Fortunately, in the case of ubiquitous systems the size of the system may be an
advantage: even if the adversary can monitor communication at many places, one
can assume that the adversary is not omnipresent and consequently only a fraction
of the interactions are available to him. Some defense methods are based on this
fact.
Another factor that may hinder adversarial actions is that a device may have some
a priori knowledge about its potential communication partners and therefore its
computation effort can be limited to these partners. On the other hand, an adversary
having no idea who is attempting to communicate may be forced to consider all
possible pairs of partner devices—the computational effort in this case might be
higher by an order of magnitude. Moreover, it may lead to many false candidates—
while for the attacked device this problem does not arise, as its range of partner
choices is limited.
Précédent

- 26/268

Suivant