1 Emerging Security Challenges for Ubiquitous Devices
17
From the point of view of the adversary, holding a lot of keys the situation is more
complicated. It may hold many false candidates for the key k used in this phase. As
Dec k (Enc k (A ⊕ η)) provides unpredictable results, it may happen that it is close
enough to some valid identifier U . In this way the adversary may get a lot of data
confusing its tracing attack.
1.4 Conclusion and Future Directions
In this chapter, we focused on pointing out some of the challenges in developing
large scale networks of severely constrained devices. Due to computational constraints the traditional approach to multiparty security and privacy has to give way
to methods based on symmetric cryptography and information obfuscation. While
considering threats caused by malicious protocol implementation, we presented
several schemes utilizing an additional device, a watchdog, that may be provided
by a third party, and hinders any covert channel aimed at secret leakage.
Future directions include inspecting the possibilities of leakage prevention in the
case of collusion between a reader and a device. The additional device described
in Sect. 1.2 prevents understanding of the messages exchanged between the verified
device and the reader, however as the watchdog is not integrated into the device
there is no guarantee that the device and the reader are not creating a covert
channel. A natural approach would be to enable the possibility of signal jamming
by the watchdog, however this solution is ineffective due to power requirements.
Moreover, since each user may be in possession of multiple devices, the case of a
single watchdog responsible for all a user’s devices and batch authorization might
be considered.
In the second part of the chapter, we pointed out the problem of violating privacy
requirements, especially via user tracking, in ubiquitous systems. One of the major
challenges is establishing a shared key, as ‘generating’ a new one with methods
derived from the Diffie-Hellman protocol is not feasible and using a constant pool
of predistributed keys allows a tracking adversary to identify devices during the key
discovery phase. We described some methods based on a key evolution approach
and on the obfuscation of information. The latter is obtained by utilizing hash
functions or introducing a small error into the transmitted message. It should be
noted that these solutions are not fully satisfactory, at least if we are confined to
symmetric methods. If asymmetric cryptography can be used, then the situation is
quite different (see Chap. 5).
Acknowledgments Authors “Mirosław Kutyłowski and Piotr Syga” supported by Polish National
Science Centre, project OPUS no 2014/15/B/ST6/02837.
Précédent

- 32/268

Suivant