• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

rTLS:面向物联网的安全高效 TLS 会话恢复。

rTLS: Secure and Efficient TLS Session Resumption for the Internet of Things.

机构信息

DTU Compute, Department of Applied Mathematics and Computer Science, Technical University of Denmark, Richard Petersens Plads, 2800 Kongens Lyngby, Denmark.

出版信息

Sensors (Basel). 2021 Sep 29;21(19):6524. doi: 10.3390/s21196524.

DOI:10.3390/s21196524
PMID:34640844
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC8512771/
Abstract

In recent years, the Transport Layer Security (TLS) protocol has enjoyed rapid growth as a security protocol for the Internet of Things (IoT). In its newest iteration, TLS 1.3, the Internet Engineering Task Force (IETF) has standardized a zero round-trip time (0-RTT) session resumption sub-protocol, allowing clients to already transmit application data in their first message to the server, provided they have shared session resumption details in a previous handshake. Since it is common for IoT devices to transmit periodic messages to a server, this 0-RTT protocol can help in reducing bandwidth overhead. Unfortunately, the sub-protocol has been designed for the Web and is susceptible to replay attacks. In our previous work, we adapted the 0-RTT protocol to strengthen it against replay attacks, while also reducing bandwidth overhead, thus making it more suitable for IoT applications. However, we did not include a formal security analysis of the protocol. In this work, we address this and provide a formal security analysis using OFMC. Further, we have included more accurate estimates on its performance, as well as making minor adjustments to the protocol itself to reduce implementation ambiguity and improve resilience.

摘要

近年来,传输层安全 (TLS) 协议作为物联网 (IoT) 的安全协议得到了快速发展。在其最新版本 TLS 1.3 中,互联网工程任务组 (IETF) 标准化了一个零往返时间 (0-RTT) 会话恢复子协议,允许客户端在向服务器发送的第一条消息中已经传输应用数据,前提是它们在以前的握手中共享了会话恢复详细信息。由于物联网设备通常向服务器发送周期性消息,因此此 0-RTT 协议有助于减少带宽开销。不幸的是,该子协议是为 Web 设计的,容易受到重播攻击。在我们之前的工作中,我们改编了 0-RTT 协议以加强其对重播攻击的防御能力,同时还减少了带宽开销,从而使其更适合物联网应用。但是,我们没有对协议进行正式的安全性分析。在这项工作中,我们解决了这个问题,并使用 OFMC 进行了正式的安全分析。此外,我们还对其性能进行了更准确的估计,并对协议本身进行了微小调整,以减少实现的模糊性并提高弹性。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8c85/8512771/a50b396435b4/sensors-21-06524-g004.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8c85/8512771/3af706d72bd8/sensors-21-06524-g001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8c85/8512771/9810ba7847ec/sensors-21-06524-g002.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8c85/8512771/71ff3447672a/sensors-21-06524-g003.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8c85/8512771/a50b396435b4/sensors-21-06524-g004.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8c85/8512771/3af706d72bd8/sensors-21-06524-g001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8c85/8512771/9810ba7847ec/sensors-21-06524-g002.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8c85/8512771/71ff3447672a/sensors-21-06524-g003.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/8c85/8512771/a50b396435b4/sensors-21-06524-g004.jpg

相似文献

1
rTLS: Secure and Efficient TLS Session Resumption for the Internet of Things.rTLS:面向物联网的安全高效 TLS 会话恢复。
Sensors (Basel). 2021 Sep 29;21(19):6524. doi: 10.3390/s21196524.
2
Secure Three-Factor Authentication Protocol for Multi-Gateway IoT Environments.用于多网关物联网环境的安全三因素认证协议
Sensors (Basel). 2019 May 22;19(10):2358. doi: 10.3390/s19102358.
3
Internet of Medical Things-Based Secure and Energy-Efficient Framework for Health Care.基于医疗物联网的医疗保健安全高效节能框架
Big Data. 2022 Feb;10(1):18-33. doi: 10.1089/big.2021.0202. Epub 2021 Dec 24.
4
Performance of the Transport Layer Security Handshake Over 6TiSCH.6TiSCH 上传输层安全握手的性能
Sensors (Basel). 2021 Mar 21;21(6):2192. doi: 10.3390/s21062192.
5
MARAS: Mutual Authentication and Role-Based Authorization Scheme for Lightweight Internet of Things Applications.MARAS:用于轻量级物联网应用的相互认证和基于角色的授权方案
Sensors (Basel). 2023 Jun 17;23(12):5674. doi: 10.3390/s23125674.
6
LR-AKAP: A Lightweight and Robust Security Protocol for Smart Home Environments.LR-AKAP:智能家居环境中的轻量级健壮安全协议。
Sensors (Basel). 2022 Sep 13;22(18):6902. doi: 10.3390/s22186902.
7
A review: a new authentication protocol for real-time healthcare monitoring system.综述:实时医疗监测系统的新型认证协议。
Ir J Med Sci. 2021 Aug;190(3):927-932. doi: 10.1007/s11845-020-02425-x. Epub 2020 Nov 3.
8
A Performance Analysis of Security Protocols for Distributed Measurement Systems Based on Internet of Things with Constrained Hardware and Open Source Infrastructures.基于具有受限硬件和开源基础设施的物联网的分布式测量系统安全协议性能分析
Sensors (Basel). 2024 Apr 26;24(9):2781. doi: 10.3390/s24092781.
9
Certificateless Hybrid Signcryption by a Novel Protocol Applied to Internet of Things.无证书混合签密协议在物联网中的应用
Comput Intell Neurosci. 2022 Feb 26;2022:3687332. doi: 10.1155/2022/3687332. eCollection 2022.
10
Formal modeling and analysis of security schemes of RPL protocol using colored Petri nets.使用着色 Petri 网对 RPL 协议安全方案进行形式化建模与分析。
PLoS One. 2023 Aug 17;18(8):e0285700. doi: 10.1371/journal.pone.0285700. eCollection 2023.