Secure Device Trust Bootstrapping Against Collaborative Signal Modification Attacks
Xiaochan Xue, Shucheng Yu, Min Song
摘要
Bootstrapping security among wireless devices without prior-shared secrets is frequently demanded in emerging wireless and mobile applications. One promising approach for this problem is to utilize in-band physical-layer radio-frequency (RF) signals for authenticated key establishment because of the efficiency and high usability. However, existing in-band authenticated key agreement (AKA) protocols are mostly vulnerable to Man-in-the-Middle (MitM) attacks, which can be launched by modifying the transmitted wireless signals over the air. By annihilating legitimate signals and injecting malicious signals, signal modification attackers are able to completely control the communication channels and spoof victim wireless devices. State-of-the-art (SOTA) techniques addressing such attacks require additional auxiliary hardware or are limited to single attackers. This paper proposes a novel in-band security bootstrapping technique that can thwart colluding signal modification attackers. Different from SOTA solutions, our design is compatible with commodity devices without requiring additional hardware. We achieve this based on the internal randomness of each device that is unpredictable to attackers. Any modification to RF signals will be detected with high probabilities. Extensive security analysis and experimentation on the USRP platform demonstrate the effectiveness of our design under various attack strategies.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Secure Device Bootstrapping Without Secrets Resistant to Signal Manipulation AttacksNirnimesh Ghose, Loukas Lazos, Ming LiS&P 2018 · 被引用 11 次
- HELP: Helper-Enabled In-Band Device Pairing Resistant Against Signal CancellationNirnimesh Ghose, Loukas Lazos, Ming LiUSENIX Security 2017 · 被引用 13 次
- AEROKEY: Using Ambient Electromagnetic Radiation for Secure and Usable Wireless Device AuthenticationKyuin Lee, Yucheng Yang, Omkar Prabhune, Aishwarya Lekshmi Chithra 等UbiComp 2022 · 被引用 11 次
- Practical Obfuscation of BLE Physical-Layer Fingerprints on Mobile DevicesHadi Givehchian, Nishant Bhaskar, Alexander Redding, Han Zhao 等S&P 2024 · 被引用 16 次
- RF-Rock: An Intermodulation-based RFID Unauthorized Identification Attack without Tag ActivationChen Gong, Bo Liang, Purui Wang, Xiaoyu Ji 等MobiCom 2025 · 被引用 1 次
