USENIX Security2019Top-tier venue
JEDI: Many-to-Many End-to-End Encryption and Key Delegation for IoT
Sam Kumar, Yuncong Hu, Michael P. Andersen, Raluca Ada Popa, David E. Culler
Abstract
As the Internet of Things (IoT) emerges over the next decade, developing secure communication for IoT devices is of paramount importance. Achieving end-to-end encryption for large-scale IoT systems, like smart buildings or smart cities, is challenging because multiple principals typically interact indirectly via intermediaries, meaning that the recipient of a message is not known in advance. This paper proposes JEDI (Joining Encryption and Delegation for IoT), a many-to-many end-to-end encryption protocol for IoT. JEDI encrypts and signs messages end-to-end, while conforming to the decoupled communication model typical of IoT systems. JEDI's keys support expiry and fine-grained access to data, common in IoT. Furthermore, JEDI allows principals to delegate their keys, restricted in expiry or scope, to other principals, thereby granting access to data and managing access control in a scalable, distributed way. Through careful protocol design and implementation, JEDI can run across the spectrum of IoT devices, including ultra low-power deeply embedded sensors severely constrained in CPU, memory, and energy consumption. We apply JEDI to an existing IoT messaging system and demonstrate that its overhead is modest.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d9d99db7-abdc-47f7-8c9a-595e261ab3a1Cited by top-tier papers9
- WAVE: A Decentralized Authorization Framework with Transitive DelegationMichael P. Andersen, Sam Kumar, Moustafa AbdelBaky, Gabe Fierro et al.USENIX Security 2019 · 66 citations
- OST: On-Demand TSCH Scheduling with Traffic-AwarenessSeungbeom Jeong, Hyung-Sin Kim, Jeongyeup Paek, Saewoong BahkINFOCOM 2020 · 51 citations
- Merkle2: A Low-Latency Transparency Log SystemYuncong Hu, Kian Hooshmand, Harika Kalidhindi, Seung Jin Yang et al.S&P 2021 · 51 citations
- Ghostor: Toward a Secure Data-Sharing System from Decentralized TrustYuncong Hu, Sam Kumar, Raluca Ada PopaNSDI 2020 · 48 citations
- SafetyPin: Encrypted Backups with Human-Memorable SecretsEmma Dauterman, Henry Corrigan-Gibbs, David MazièresOSDI 2020 · 22 citations
Builds on1
Related papers
- Don't Kick Over the Beehive: Attacks and Security Analysis on ZigbeeXian Wang, Shuang HaoCCS 2022 · 13 citations
- Shattered Chain of Trust: Understanding Security Risks in Cross-Cloud IoT Access DelegationBin Yuan, Yan Jia, Luyi Xing, Dongfang Zhao et al.USENIX Security 2020
- DroneKey: A Drone-Aided Group-Key Generation Scheme for Large-Scale IoT NetworksDianqi Han, Ang Li, Jiawei Li, Yan Zhang et al.CCS 2021 · 13 citations
- Cluster-Based Network Time Synchronization for Resilience with Energy EfficiencyNitin Shivaraman, Patrick Schuster, Saravanan Ramanathan, Arvind Easwaran et al.RTSS 2021 · 7 citations
- WBSLT: A Framework for White-Box Encryption Based on Substitution-Linear Transformation CiphersYang Shi, Tianchen Gao, Yimin Li, Jiayao Gao et al.NDSS 2026 · 1 citation
