论文标题
声学完整性代码:使用短距离声通信的安全设备配对
Acoustic Integrity Codes: Secure Device Pairing Using Short-Range Acoustic Communication
论文作者
论文摘要
安全设备配对(SDP)依靠带外通道来验证设备。这需要一个通用的硬件接口,该界面限制了现有SDP系统的使用。我们建议使用短距离声通信进行初始配对。音频硬件通常在现有的现成设备上可用,可以从用户空间访问而无需固件或硬件修改。我们通过设计声学完整性代码(AIC):一种调制方案来改进以前的方法,该方案在声学物理层上提供了消息身份验证。我们分析了他们的安全性,并证明我们可以通过设计低自相关的信号来防御信号取消攻击。我们的系统可以使用具有阈值的三元决策功能来检测越图的攻击。在评估该SDP方案的安全性和鲁棒性时,我们的位误差比以低于0.1%的净比特率达到100 bps的0.1%,信噪比(SNR)为14 dB。使用我们在Android智能手机上的开源概念验证实现,我们演示了不同智能手机型号之间的配对。
Secure Device Pairing (SDP) relies on an out-of-band channel to authenticate devices. This requires a common hardware interface, which limits the use of existing SDP systems. We propose to use short-range acoustic communication for the initial pairing. Audio hardware is commonly available on existing off-the-shelf devices and can be accessed from user space without requiring firmware or hardware modifications. We improve upon previous approaches by designing Acoustic Integrity Codes (AICs): a modulation scheme that provides message authentication on the acoustic physical layer. We analyze their security and demonstrate that we can defend against signal cancellation attacks by designing signals with low autocorrelation. Our system can detect overshadowing attacks using a ternary decision function with a threshold. In our evaluation of this SDP scheme's security and robustness, we achieve a bit error ratio below 0.1% for a net bit rate of 100 bps with a signal-to-noise ratio (SNR) of 14 dB. Using our open-source proof-of-concept implementation on Android smartphones, we demonstrate pairing between different smartphone models.