Sanchez-Gomez Jesus, Garcia-Carrillo Dan, Marin-Perez Rafael, Skarmeta Antonio F
Department of Information and Communications Engineering, Faculty of Computer Science, University of Murcia, 30100 Murcia, Spain.
Odin Solutions SL, 30820 Murcia, Spain.
Sensors (Basel). 2020 Feb 7;20(3):882. doi: 10.3390/s20030882.
Security is critical in the deployment and maintenance of novel IoT and 5G networks. The process of bootstrapping is required to establish a secure data exchange between IoT devices and data-driven platforms. It entails, among other steps, authentication, authorization, and credential management. Nevertheless, there are few efforts dedicated to providing service access authentication in the area of constrained IoT devices connected to recent wireless networks such as narrowband IoT (NB-IoT) and 5G. Therefore, this paper presents the adaptation of bootstrapping protocols to be compliant with the 3GPP specifications in order to enable the 5G feature of secondary authentication for constrained IoT devices. To allow the secondary authentication and key establishment in NB-IoT and 4G/5G environments, we have adapted two Extensible Authentication Protocol (EAP) lower layers, i.e., PANATIKI and LO-CoAP-EAP. In fact, this approach presents the evaluation of both aforementioned EAP lower layers, showing the contrast between a current EAP lower layer standard, i.e., PANA, and one specifically designed with the constraints of IoT, thus providing high flexibility and scalability in the bootstrapping process in 5G networks. The proposed solution is evaluated to prove its efficiency and feasibility, being one of the first efforts to support secure service authentication and key establishment for constrained IoT devices in 5G environments.
安全性在新型物联网和5G网络的部署与维护中至关重要。引导过程是在物联网设备和数据驱动平台之间建立安全数据交换所必需的。这一过程除其他步骤外,还涉及认证、授权和凭证管理。然而,在连接到诸如窄带物联网(NB-IoT)和5G等最新无线网络的受限物联网设备领域,致力于提供服务访问认证的工作却很少。因此,本文提出了对引导协议进行调整,使其符合3GPP规范,以便为受限物联网设备启用二次认证的5G功能。为了在NB-IoT和4G/5G环境中实现二次认证和密钥建立,我们对两个可扩展认证协议(EAP)下层进行了调整,即PANATIKI和LO-CoAP-EAP。实际上,这种方法对上述两个EAP下层进行了评估,展示了当前EAP下层标准(即PANA)与专门针对物联网约束设计的标准之间的对比,从而在5G网络的引导过程中提供了高度的灵活性和可扩展性。对所提出的解决方案进行了评估,以证明其效率和可行性,这是为5G环境中受限物联网设备支持安全服务认证和密钥建立所做的首批努力之一。