Decentralized Public Key Infrastructure for Internet-of-Things

In many envisioned IoT applications, security is crucial. However, designing and/or deploying existing security techniques in IoT systems is not straightforward due to the inherent heterogeneity of IoT devices as well as their huge number. A critical security building block is represented by the Pub...

Full description

Saved in:
Bibliographic Details
Published inMILCOM 2018 - 2018 IEEE Military Communications Conference (MILCOM) pp. 907 - 913
Main Authors Won, Jongho, Singla, Ankush, Bertino, Elisa, Bollella, Greg
Format Conference Proceeding
LanguageEnglish
Published IEEE 01.10.2018
Online AccessGet full text

Cover

Loading…
Abstract In many envisioned IoT applications, security is crucial. However, designing and/or deploying existing security techniques in IoT systems is not straightforward due to the inherent heterogeneity of IoT devices as well as their huge number. A critical security building block is represented by the Public Key Infrastructure (PKI) relying on Certificate Authorities (CAs). However, even a single-point-of-failure in a PKI may affect entire IoT systems due to its centralized nature. Failures have far reaching effects as the number of IoT devices increases. Furthermore, it is difficult for the owners of IoT devices to manage the certificates for their IoT devices since there are no standard protocols for retrieving, installing and updating the certificates. As a result, IoT device manufacturers often install certificates on the devices on behalf of the owners of the devices, which introduces the risk that the private keys of the devices are leaked by the manufacturers. In this paper, we propose a decentralized PKI for IoT, called IoT-PKI, which utilizes distributed nodes in a blockchain network instead of CAs, and thus addresses scalability. IoT-PKI protects against key leakages at device manufacturers since it allows the owners of IoT devices to manage the certificates of their IoT devices. Finally, we show the feasibility and efficiency of IoT-PKI through our prototype implementation and experiments.
AbstractList In many envisioned IoT applications, security is crucial. However, designing and/or deploying existing security techniques in IoT systems is not straightforward due to the inherent heterogeneity of IoT devices as well as their huge number. A critical security building block is represented by the Public Key Infrastructure (PKI) relying on Certificate Authorities (CAs). However, even a single-point-of-failure in a PKI may affect entire IoT systems due to its centralized nature. Failures have far reaching effects as the number of IoT devices increases. Furthermore, it is difficult for the owners of IoT devices to manage the certificates for their IoT devices since there are no standard protocols for retrieving, installing and updating the certificates. As a result, IoT device manufacturers often install certificates on the devices on behalf of the owners of the devices, which introduces the risk that the private keys of the devices are leaked by the manufacturers. In this paper, we propose a decentralized PKI for IoT, called IoT-PKI, which utilizes distributed nodes in a blockchain network instead of CAs, and thus addresses scalability. IoT-PKI protects against key leakages at device manufacturers since it allows the owners of IoT devices to manage the certificates of their IoT devices. Finally, we show the feasibility and efficiency of IoT-PKI through our prototype implementation and experiments.
Author Bollella, Greg
Singla, Ankush
Bertino, Elisa
Won, Jongho
Author_xml – sequence: 1
  givenname: Jongho
  surname: Won
  fullname: Won, Jongho
  organization: Department of Computer Science, Purdue University, West Lafayette, IN, USA
– sequence: 2
  givenname: Ankush
  surname: Singla
  fullname: Singla, Ankush
  organization: Department of Computer Science, Purdue University, West Lafayette, IN, USA
– sequence: 3
  givenname: Elisa
  surname: Bertino
  fullname: Bertino, Elisa
  organization: Department of Computer Science, Purdue University, West Lafayette, IN, USA
– sequence: 4
  givenname: Greg
  surname: Bollella
  fullname: Bollella, Greg
  organization: VMWare, Palo Alto, CA, USA
BookMark eNotj7FOwzAURQ0CiVLyBV3yAw5-duw8L0goUIhIVYbsVRKewSgkyHGH8vUU0elKZzg695pdjNNIjK1AZADC3m6qutxuMikAM9TWFiDOWGILBK3QFIDanLOFBK15odFcsWSeP4UQINFICwt290A9jTG0g_-ht_R13w2-T1_okFajC-0cw76P-0Cpm8IRRQojRT453nz48X2-YZeuHWZKTrtkzfqxKZ95vX2qyvuaeysi186AAAINPeZSqhY704PsOiOFU9jlSuoi15I0mdxoPPZKh4IUuL9OpZZs9a_1RLT7Dv6rDYfd6bD6BdvKSgY
ContentType Conference Proceeding
DBID 6IE
6IH
CBEJK
RIE
RIO
DOI 10.1109/MILCOM.2018.8599710
DatabaseName IEEE Electronic Library (IEL) Conference Proceedings
IEEE Proceedings Order Plan (POP) 1998-present by volume
IEEE Xplore All Conference Proceedings
IEEE Electronic Library Online
IEEE Proceedings Order Plans (POP) 1998-present
DatabaseTitleList
Database_xml – sequence: 1
  dbid: RIE
  name: IEEE Electronic Library Online
  url: https://proxy.k.utb.cz/login?url=https://ieeexplore.ieee.org/
  sourceTypes: Publisher
DeliveryMethod fulltext_linktorsrc
Discipline Military & Naval Science
Engineering
EISBN 9781538671856
1538671859
EISSN 2155-7586
EndPage 913
ExternalDocumentID 8599710
Genre orig-research
GroupedDBID 6IE
6IF
6IG
6IH
6IL
6IN
AAJGR
ABLEC
ABQGA
ALMA_UNASSIGNED_HOLDINGS
BEFXN
BFFAM
BGNUA
BKEBE
BPEOZ
CBEJK
IEGSK
IJVOP
OCL
RIE
RIL
RIO
ID FETCH-LOGICAL-i90t-5f6101e151c84223a8b6c12bb620f38b43257452e5e646582152f80e31f286233
IEDL.DBID RIE
IngestDate Wed Jun 26 19:28:18 EDT 2024
IsPeerReviewed false
IsScholarly true
Language English
LinkModel DirectLink
MergedId FETCHMERGED-LOGICAL-i90t-5f6101e151c84223a8b6c12bb620f38b43257452e5e646582152f80e31f286233
PageCount 7
ParticipantIDs ieee_primary_8599710
PublicationCentury 2000
PublicationDate 2018-Oct.
PublicationDateYYYYMMDD 2018-10-01
PublicationDate_xml – month: 10
  year: 2018
  text: 2018-Oct.
PublicationDecade 2010
PublicationTitle MILCOM 2018 - 2018 IEEE Military Communications Conference (MILCOM)
PublicationTitleAbbrev MILCOM
PublicationYear 2018
Publisher IEEE
Publisher_xml – name: IEEE
SSID ssj0001286291
ssj0002683877
Score 2.2877913
Snippet In many envisioned IoT applications, security is crucial. However, designing and/or deploying existing security techniques in IoT systems is not...
SourceID ieee
SourceType Publisher
StartPage 907
Title Decentralized Public Key Infrastructure for Internet-of-Things
URI https://ieeexplore.ieee.org/document/8599710
hasFullText 1
inHoldings 1
isFullTextHit
isPrint
link http://utb.summon.serialssolutions.com/2.0.0/link/0/eLvHCXMwjV09T8MwELVKJ1iAtqh8ygNiwmm-7NgLS6FqgRSGInWr4vgsVUgpqtKh_fXYcSgFMbAlkRw551jvdH7vHULXIgLhQ5YQzUARyyMkQomIKG7glSqtKLMC53TMhm_x45ROG-h2q4UBgIp8Bp69rM7y1SJf2VJZj1MhEqun2kuEcFqtnXqKyc1r3xd7HzIe8SSpjYYCX_TS0XP_JbVsLu7Vb_rRUqVClMEhSr_m4ogk796qlF6--WXT-N_JHqHOt3YPv25R6Rg1oGihgx3bwRbqppU193KNb_A4M78arnd4G93dQ03XnG9AYVfUw0-wxqNCLzPnNrtaAja5LnbVRCjJQhPX_7ODJoOHSX9I6hYLZC78klBtsqcADOrnPDaJQsYly4NQShb6OuIyjsyOjmkIFFjMrKaWhpr7EAXahjuKTlCzWBTQRdgPQSb2lE2AiHMlpBlKE8VEDFqGUp2ito3R7MOZaMzq8Jz9_fgc7dt1cqy5C9Q0XweXBv1LeVUt-ycB2avu
link.rule.ids 310,311,783,787,792,793,799,27937,55086
linkProvider IEEE
linkToHtml http://utb.summon.serialssolutions.com/2.0.0/link/0/eLvHCXMwjV3PT8IwFG4IHtSLChj83YPxZMd-tWsvXlACwtADJtzIur4mxGQYMg7w19tuE9F48LYt2dK9tnlfXr_vewjdigCEC0lENANFLI-QCCUCorhJr1RpRZkVOMdj1n8Ln6d0WkP3Wy0MABTkM3DsZXGWrxbpypbKOpwKEVk91Z7B1ZyVaq2diopB55Xzi733GQ94FFVWQ54rOvFg1H2JLZ-LO9W3fjRVKXJK7wjFX6MpqSTvziqXTrr5ZdT43-Eeo9a3eg-_bvPSCapB1kCHO8aDDdSOC3Pu5Rrf4XFiFhuu9ngTPTxCRdicb0DhsqyHh7DGg0wvk9JvdrUEbNAuLuuJkJOFJmUH0Baa9J4m3T6pmiyQuXBzQrXBTx6YvJ_y0ECFhEuWer6UzHd1wGUYmD0dUh8osJBZVS31NXch8LQNdxCconq2yKCNsOuDjOw5mwARpkpI8yqNFBMhaOlLdYaaNkazj9JGY1aF5_zvxzdovz-JR7PRYDy8QAd2zkoO3SWqmz-FK4MFcnldLIFPMeavOQ
openUrl ctx_ver=Z39.88-2004&ctx_enc=info%3Aofi%2Fenc%3AUTF-8&rfr_id=info%3Asid%2Fsummon.serialssolutions.com&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Abook&rft.genre=proceeding&rft.title=MILCOM+2018+-+2018+IEEE+Military+Communications+Conference+%28MILCOM%29&rft.atitle=Decentralized+Public+Key+Infrastructure+for+Internet-of-Things&rft.au=Won%2C+Jongho&rft.au=Singla%2C+Ankush&rft.au=Bertino%2C+Elisa&rft.au=Bollella%2C+Greg&rft.date=2018-10-01&rft.pub=IEEE&rft.eissn=2155-7586&rft.spage=907&rft.epage=913&rft_id=info:doi/10.1109%2FMILCOM.2018.8599710&rft.externalDocID=8599710