论文标题

出生的隐私性:保护感知的数据免受恶意传感器的影响

Privacy-from-Birth: Protecting Sensed Data from Malicious Sensors with VERSA

论文作者

Nunes, Ivan De Oliveira, Hwang, Seoyeon, Jakkamsetti, Sashidhar, Tsudik, Gene

论文摘要

在物联网/CPS系统中,有许多众所周知的技术可以保护感知的数据,例如,通过对通信终点进行身份验证,在传输前加密数据并混淆流量模式。这种技术在假设传感设备本身是安全的同时,保护感应的数据免受外部对手的影响。同时,以物联网攻击的规模和频率正在增长。这提示了一个自然的问题:即使设备上的所有软件都受到损害,如何保护感知的数据?理想情况下,为了实现这一目标,必须保护感应的数据免受其起源的保护,即从将物理模拟数量转换为数字对应物并可以被软件访问的时间。我们将此属性称为pfb:隐私 - 出生。 在这项工作中,我们对PFB进行了形式化和设计经过验证的遥感授权(VERSA) - 可证明安全且正式验证的体系结构,确保只有正确执行预期和明确授权的软件才能访问和操纵感应接口,具体来说,特定于通用目的输入/输出(GPIO),这是模拟世界和IOT equine equine in iot设备之间的正常边界。通过最小的硬件支持获得此保证,即使所有设备软件都受到损害,也可以保证。 Versa确保恶意软件既不能在GPIO映射内存上访问感知的数据,也无法获得其任何跟踪。 Versa经过正式验证,其开源实现目标是资源约束的物联网边缘设备,该设备通常用于传感。实验结果表明,对于此类设备,PFB既可以实现又负担得起。

There are many well-known techniques to secure sensed data in IoT/CPS systems, e.g., by authenticating communication end-points, encrypting data before transmission, and obfuscating traffic patterns. Such techniques protect sensed data from external adversaries while assuming that the sensing device itself is secure. Meanwhile, both the scale and frequency of IoT-focused attacks are growing. This prompts a natural question: how to protect sensed data even if all software on the device is compromised? Ideally, in order to achieve this, sensed data must be protected from its genesis, i.e., from the time when a physical analog quantity is converted into its digital counterpart and becomes accessible to software. We refer to this property as PfB: Privacy-from-Birth. In this work, we formalize PfB and design Verified Remote Sensing Authorization (VERSA) -- a provably secure and formally verified architecture guaranteeing that only correct execution of expected and explicitly authorized software can access and manipulate sensing interfaces, specifically, General Purpose Input/Output (GPIO), which is the usual boundary between analog and digital worlds on IoT devices. This guarantee is obtained with minimal hardware support and holds even if all device software is compromised. VERSA ensures that malware can neither gain access to sensed data on the GPIO-mapped memory nor obtain any trace thereof. VERSA is formally verified and its open-sourced implementation targets resource-constrained IoT edge devices, commonly used for sensing. Experimental results show that PfB is both achievable and affordable for such devices.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源