SANA: Secure and Scalable Aggregate Network Attestation
Moreno Ambrosin, Mauro Conti, Ahmad Ibrahim, Gregory Neven, Ahmad-Reza Sadeghi, Matthias Schunter
Abstract
Large numbers of smart connected devices, also named as the Internet of Things (IoT), are permeating our environments (homes, factories, cars, and also our body-with wearable devices) to collect data and act on the insight derived. Ensuring software integrity (including OS, apps, and configurations) on such smart devices is then essential to guarantee both privacy and safety. A key mechanism to protect the software integrity of these devices is remote attestation: A process that allows a remote verifier to validate the integrity of the software of a device. This process usually makes use of a signed hash value of the actual device's software, generated by dedicated hardware. While individual device attestation is a well-established technique, to date integrity verification of a very large number of devices remains an open problem, due to scalability issues. In this paper, we present SANA, the first secure and scalable protocol for efficient attestation of large sets of devices that works under realistic assumptions. SANA relies on a novel signature scheme to allow anyone to publicly verify a collective attestation in constant time and space, for virtually an unlimited number of devices. We substantially improve existing swarm attestation schemes [5] by supporting a realistic trust model where: (1) only the targeted devices are required to implement attestation; (2) compromising any device does not harm others; and (3) all aggregators can be untrusted. We implemented SANA and demonstrated its efficiency on tiny sensor devices. Furthermore, we simulated SANA at large scale, to assess its scalability. Our results show that SANA can provide efficient attestation of networks of 1, 000, 000 devices, in only 2.5 seconds.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 103b9369-c117-467e-9679-23966dec7413Cited by top-tier papers8
- DIAT: Data Integrity Attestation for Resilient Collaboration of Autonomous SystemsTigist Abera, Raad Bahmani, Ferdinand Brasser, Ahmad Ibrahim et al.NDSS 2019 · 80 citations
- Compact Certificates of Collective KnowledgeSilvio Micali, Leonid Reyzin, Georgios Vlachos, Riad S. Wahby et al.S&P 2021 · 15 citations
- On the TOCTOU Problem in Remote AttestationIvan De Oliveira Nunes, Sashidhar Jakkamsetti, Norrathep Rattanavipanon, Gene TsudikCCS 2021 · 2 citations
- PIRANHAS: PrIvacy-Preserving Remote Attestation in Non-Hierarchical Asynchronous SwarmsJonas Hofmann, Philipp-Florens Lehwalder, Shahriar Ebrahimi, Parisa Hassanizadeh et al.NDSS 2026 · 2 citations
- ARI: Attestation of Real-time Mission Execution IntegrityJinwen Wang, Yujie Wang, Ao Li, Yang Xiao et al.USENIX Security 2023
Builds on1
Related papers
- SCRAPS: Scalable Collective Remote Attestation for Pub-Sub IoT Networks with Untrusted Proxy VerifierLukas Petzi, Ala Eddine Ben Yahya, Alexandra Dmitrienko, Gene Tsudik et al.USENIX Security 2022
- From Interaction to Independence: zkSNARKs for Transparent and Non-Interactive Remote AttestationShahriar Ebrahimi, Parisa HassanizadehNDSS 2024
- RealSWATT: Remote Software-based Attestation for Embedded Devices under Realtime ConstraintsSebastian Surminski, Christian Niesler, Ferdinand Brasser, Lucas Davi et al.CCS 2021 · 25 citations
- VRASED: A Verified Hardware/Software Co-Design for Remote AttestationIvan De Oliveira Nunes, Karim Eldefrawy, Norrathep Rattanavipanon, Michael Steiner et al.USENIX Security 2019 · 135 citations
- OPERA: Open Remote Attestation for Intel's Secure EnclavesGuoxing Chen, Yinqian Zhang, Ten-Hwang LaiCCS 2019 · 67 citations
