Shattered Chain of Trust: Understanding Security Risks in Cross-Cloud IoT Access Delegation
Bin Yuan, Yan Jia, Luyi Xing, Dongfang Zhao, XiaoFeng Wang, Deqing Zou, Hai Jin, Yuqing Zhang
摘要
IoT clouds facilitate the communication between IoT devices and users, and authorize users' access to their devices. In this paradigm, an IoT device is usually managed under a particular IoT cloud designated by the device vendor, e.g., Philips bulbs are managed under Philips Hue cloud. Today's mainstream IoT clouds also support device access delegation across different vendors (e.g., Philips Hue, LIFX, etc.) and cloud providers (e.g., Google, IFTTT, etc.): for example, Philips Hue and SmartThings clouds support to delegate device access to another cloud such as Google Home, so a user can manage multiple devices from different vendors all through Google Home. Serving this purpose are the IoT delegation mechanisms developed and utilized by IoT clouds, which we found are heterogeneous and ad-hoc in the wild, in the absence of a standardized delegation protocol suited for IoT environments. In this paper, we report the first systematic study on real-world IoT access delegation, based upon a semi-automatic verification tool we developed. Our study brought to light the pervasiveness of security risks in these delegation mechanisms, allowing the adversary (e.g., Airbnb tenants, former employees) to gain unauthorized access to the victim's devices (e.g., smart locks) or impersonate the devices to trigger other devices. We confirmed the presence of critical security flaws in these mechanisms through end-to-end exploits on them, and further conducted a measurement study. Our research demonstrates the serious consequences of these exploits and the security implications of the practice today for building these mechanisms. We reported our findings to related parties, which acknowledged the problems. We further propose principles for developing more secure cross-cloud IoT delegation services, before a standardized solution can be widely deployed.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper10
- Who's In Control? On Security Risks of Disjointed IoT Device Management ChannelsYan Jia, Bin Yuan, Luyi Xing, Dongfang Zhao 等CCS 2021 · 被引用 22 次
- P-Verifier: Understanding and Mitigating Security Risks in Cloud-based IoT Access PoliciesZe Jin, Luyi Xing, Yiwei Fang, Yan Jia 等CCS 2022 · 被引用 19 次
- Ruledger: Ensuring Execution Integrity in Trigger-Action IoT PlatformsJingwen Fan, Yi He, Bo Tang, Qi Li 等INFOCOM 2021 · 被引用 17 次
- Securing Graph Neural Networks in MLaaS: A Comprehensive Realization of Query-based Integrity VerificationBang Wu, Xingliang Yuan, Shuo Wang, Qi Li 等S&P 2024 · 被引用 13 次
- Perils and Mitigation of Security Risks of Cooperation in Mobile-as-a-Gateway IoTXin'an Zhou, Jiale Guan, Luyi Xing, Zhiyun QianCCS 2022 · 被引用 9 次
它引用的顶会 Paper14
- Security Analysis of Emerging Smart Home ApplicationsEarlence Fernandes, Jaeyeon Jung, Atul PrakashS&P 2016 · 被引用 684 次
- ContexloT: Towards Providing Contextual Integrity to Appified IoT PlatformsYunhan Jack Jia, Qi Alfred Chen, Shiqi Wang, Amir Rahmati 等NDSS 2017 · 被引用 325 次
- FlowFence: Practical Data Protection for Emerging IoT Application FrameworksEarlence Fernandes, Justin Paupore, Amir Rahmati, Daniel Simionato 等USENIX Security 2016 · 被引用 296 次
- IoTGuard: Dynamic Enforcement of Security and Safety Policy in Commodity IoTZ. Berkay Celik, Gang Tan, Patrick D. McDanielNDSS 2019 · 被引用 254 次
- Sensitive Information Tracking in Commodity IoTZ. Berkay Celik, Leonardo Babun, Amit Kumar Sikder, Hidayet Aksu 等USENIX Security 2018 · 被引用 236 次
相关 Paper
- Burglars' IoT Paradise: Understanding and Mitigating Security Risks of General Messaging Protocols on IoT CloudsYan Jia, Luyi Xing, Yuhang Mao, Dongfang Zhao 等S&P 2020 · 被引用 64 次
- Protected or Porous: A Comparative Analysis of Threat Detection Capability of IoT SafeguardsAnna Maria Mandalari, Hamed Haddadi, Daniel J. Dubois, David R. ChoffnesS&P 2023
- Discovering and Understanding the Security Hazards in the Interactions between IoT Devices, Mobile Apps, and Clouds on Smart Home PlatformsWei Zhou, Yan Jia, Yao Yao, Lipeng Zhu 等USENIX Security 2019 · 被引用 160 次
- Fear and Logging in the Internet of ThingsQi Wang, Wajih Ul Hassan, Adam Bates, Carl A. GunterNDSS 2018 · 被引用 205 次
- Smart Home Beyond the Home: A Case for Community-Based Access ControlMadiha Tabassum, Jess Kropczynski, Pamela J. Wisniewski, Heather Richter LipfordCHI 2020 · 被引用 45 次
