AutoPKI: public key infrastructure for IoT with automated trust transfer


연구 분야: Infrastructure



학회: International Journal of Information Security


초록

IoT deployments grow in numbers and size, which makes questions of long-term support and maintainability increasingly important. Without scalable and standard-compliant capabilities to transfer the control of IoT devices between service providers, IoT system owners cannot ensure long-term maintainability, and risk vendor lock-in. The manual overhead must be kept low for large-scale IoT installations to be economically feasible. We propose AutoPKI, a lightweight protocol to update the IoT PKI credentials and shift the trusted domains, enabling the transfer of control between IoT service providers, building upon the latest IoT standards for secure communication and efficient encodings. We show that the overhead for the involved IoT devices is small and that the overall required manual overhead can be minimized. We analyse the fulfilment of the security requirements, and for a subset of them, we demonstrate that the desired security properties hold through formal verification using the Tamarin prover.


Author Profile
Joel Höglund

RISE Research Institutes of Sweden Stockholm Sweden

Sweden
Author Profile
Simon Bouget

RISE Research Institutes of Sweden Stockholm Sweden

Sweden
Author Profile
Martin Furuhed

Nexus Group Stockholm Sweden

Sweden

📄 논문 정보

발행 연도 2024년
인용수 0
출판 국가 Sweden
사이트 Springer
좋아요 수 0

연관 논문 목록 (275건)