Device Identification and Personal Data Attestation in Networks

Clémentine Gritti1+, Melek Önen2, Refik Molva2, Willy Susilo3, and Thomas Plantard3

 

1NTNU, Norway

clementine.gritti@ntnu.no

2Eurecom, France

{melek.onen, refik.molva}@eurecom.fr

3University of Wollongong, Australia

{wsusilo, thomaspl}@uow.edu.au

 

Abstract

A powerful world connecting digital and physical environments is promised through the Internet of Things (IoT). However, because of the heterogeneous nature of devices and of the diversity of their provenance, security and privacy vulnerabilities threaten IoT-based implementations. Moreover, constrained resources from devices bring technical challenges, compelling protocols to be as lightweight Similarly to Gritti et al.’s approach, a secure bootstrap is first processed to enable a reliable authentication of devices in a local network, and then, a message attestation phase is executed to allow authentication of personal messages of devices. While devices are limited to pre-determined common messages in Gritti et al.’s solution, they can authenticate their own personal messages in our paper. We ensure that our solution is suitable in IoT settings by proving it secure and privacy-preserving as well as satisfying operational requirements. In addition, we provide benchmarking results on both the scheme from Gritti et al.’s scheme and our scheme.

Keywords: Internet of Things, Identity-Based Cryptography, Aggregate Signature

 

+: Corresponding author: Clémentine Gritti
Elektro B, Gloshaugen, Department of Information Security and Communication Technology,

NTNU, Trondheim, Norway

 
Journal of Wireless Mobile Networks, Ubiquitous Computing, and Dependable Applications
 (JoWUA)

Vol. 9, No. 4, pp. 1-25, December 2018 [pdf]
DOI: 10.22667/JOWUA.2018.12.31.001