USENIX Security2017Top-tier venue
HELP: Helper-Enabled In-Band Device Pairing Resistant Against Signal Cancellation
Nirnimesh Ghose, Loukas Lazos, Ming Li
Abstract
Bootstrapping trust between wireless devices without entering or preloading secrets is a fundamental security problem in many applications, including home networking, mobile device tethering, and the Internet-of-Things. This is because many new wireless devices lack the necessary interfaces (keyboard, screen, etc.) to manually enter passwords, or are often preloaded with default keys that are easily leaked. Alternatively, two devices can establish a common secret by executing key agreement protocols. However, the latter are vulnerable to Man-in-the-Middle (MitM) attacks. In the wireless domain, MitM attacks can be launched by manipulating the over-the-air transmissions. The strongest form of manipulation is signal cancellation, which completely annihilates the signal at a targeted receiver. Recently, cancellation attacks were shown to be practical under predictable channel conditions, without an effective defense mechanism.
In this paper, we propose HELP, a helper-assisted message integrity verification primitive that detects message manipulation and signal cancellation over the wireless channel (rather than prevent it). By leveraging transmissions from a helper device which has already established trust with one of the devices (e.g., the hub), we enable signal tampering detection with high probability. We then use HELP to build a device pairing protocol, which securely introduces new devices to the network without requiring them to share any secret keys with the existing devices beforehand. We carry out extensive analysis and real-world experiments to validate the security and performance of our proposed protocol.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8bc69cf2-eee5-4182-baae-e8fee6e50ccaCited by top-tier papers2
- Secure Device Bootstrapping Without Secrets Resistant to Signal Manipulation AttacksNirnimesh Ghose, Loukas Lazos, Ming LiS&P 2018 · 11 citations
- Sounds Good? Fast and Secure Contact Exchange in GroupsFlorentin Putz, Steffen Haesler, Matthias HollickCSCW 2024 · 4 citations
Related papers
- Secure Device Trust Bootstrapping Against Collaborative Signal Modification AttacksXiaochan Xue, Shucheng Yu, Min SongINFOCOM 2023 · 1 citation
- Device Pairing at the Touch of an ElectrodeMarc Roeschlin, Ivan Martinovic, Kasper Bonne RasmussenNDSS 2018 · 26 citations
- Fake It till You Make It: Enhancing Security of Bluetooth Secure Connections via Deferrable AuthenticationMarc Fischlin, Olga SaninaCCS 2024 · 2 citations
- Extrapolating Formal Analysis to Uncover Attacks in Bluetooth Passkey Entry PairingMohit Kumar Jangid, Yue Zhang, Zhiqiang LinNDSS 2023
- Harnessing the Ambient Radio Frequency Noise for Wearable Device PairingWenqiang Jin, Ming Li, Srinivasan Murali, Linke GuoCCS 2020 · 19 citations
