Suppr超能文献

物联网设备红外通信中的窃听漏洞与对策

Eavesdropping Vulnerability and Countermeasure in Infrared Communication for IoT Devices.

作者信息

Kim Minchul, Suh Taeweon

机构信息

Department of Information Security, Korea University, 145 Anam-ro, Seongbuk-gu, Seoul 02841, Korea.

Department of Computer Science and Engineering, Korea University, 145 Anam-ro, Seongbuk-gu, Seoul 02841, Korea.

出版信息

Sensors (Basel). 2021 Dec 8;21(24):8207. doi: 10.3390/s21248207.

Abstract

Infrared (IR) communication is one of the wireless communication methods mainly used to manipulate consumer electronics devices. Traditional IR devices support only simple operations such as changing TV channels. These days, consumer electronic devices such as smart TV are connected to the internet with the introduction of IoT. Thus, the user's sensitive information such as credit card number and/or personal information could be entered with the IR remote. This situation raises a new problem. Since TV and the set-top box are visual media, these devices can be used to control and/or monitor other IoT devices at home. Therefore, personal information can be exposed to eavesdroppers. In this paper, we experimented with the IR devices' reception sensitivity using remotes. These experiments were performed to measure the IR reception sensitivity in terms of distance and position between the device and the remote. According to our experiments, the transmission distance of the IR remote signal is more than 20 m. The experiments also revealed that curtains do not block infrared rays. Consequently, eavesdropping is possible to steal the user's sensitive information. This paper proposes a simple, practical, and cost-effective countermeasure against eavesdropping, which does not impose any burden on users. Basically, encryption is used to prevent the eavesdropping. The encryption key is created by recycling a timer inside the microcontroller typically integrated in a remote. The key is regenerated whenever the power button on a remote is pressed, providing the limited lifecycle of the key. The evaluation indicates that the XOR-based encryption is practical and effective in terms of the processing time and cost.

摘要

红外(IR)通信是主要用于操控消费电子设备的无线通信方式之一。传统红外设备仅支持诸如更换电视频道等简单操作。如今,随着物联网的引入,智能电视等消费电子设备已接入互联网。因此,用户的敏感信息如信用卡号和/或个人信息可能会通过红外遥控器输入。这种情况引发了一个新问题。由于电视和机顶盒是视觉媒体,这些设备可用于控制和/或监控家中的其他物联网设备。所以,个人信息可能会暴露给窃听者。在本文中,我们使用遥控器对红外设备的接收灵敏度进行了实验。进行这些实验是为了测量设备与遥控器之间距离和位置方面的红外接收灵敏度。根据我们的实验,红外遥控信号的传输距离超过20米。实验还表明窗帘不会阻挡红外线。因此,窃听有可能窃取用户的敏感信息。本文提出了一种简单、实用且经济高效的防窃听对策,不会给用户带来任何负担。基本上,使用加密来防止窃听。加密密钥通过循环利用通常集成在遥控器中的微控制器内部的定时器来创建。每当按下遥控器上的电源按钮时,密钥就会重新生成,从而提供密钥的有限生命周期。评估表明,基于异或的加密在处理时间和成本方面是实用且有效的。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0620/8706134/d70ce364c698/sensors-21-08207-g001.jpg

相似文献

1
Eavesdropping Vulnerability and Countermeasure in Infrared Communication for IoT Devices.
Sensors (Basel). 2021 Dec 8;21(24):8207. doi: 10.3390/s21248207.
3
A secure remote user authentication scheme for 6LoWPAN-based Internet of Things.
PLoS One. 2021 Nov 8;16(11):e0258279. doi: 10.1371/journal.pone.0258279. eCollection 2021.
4
An IoT-Based Anonymous Function for Security and Privacy in Healthcare Sensor Networks.
Sensors (Basel). 2019 Jul 17;19(14):3146. doi: 10.3390/s19143146.
5
Resistance of IoT Sensors against DDoS Attack in Smart Home Environment.
Sensors (Basel). 2020 Sep 16;20(18):5298. doi: 10.3390/s20185298.
7
A secure remote health monitoring model for early disease diagnosis in cloud-based IoT environment.
Pers Ubiquitous Comput. 2023;27(3):697-713. doi: 10.1007/s00779-020-01475-3. Epub 2020 Nov 16.
8
A Framework for Off-Line Operation of Smart and Traditional Devices of IoT Services.
Sensors (Basel). 2020 Oct 23;20(21):6012. doi: 10.3390/s20216012.
9
IoT Privacy Risks Revealed.
Entropy (Basel). 2024 Jun 29;26(7):561. doi: 10.3390/e26070561.
10
Secure transmission for IoT wireless energy-carrying communication systems.
PLoS One. 2023 Aug 3;18(8):e0289251. doi: 10.1371/journal.pone.0289251. eCollection 2023.

引用本文的文献

本文引用的文献

1
2
Ultra-high-capacity wireless communication by means of steered narrow optical beams.
Philos Trans A Math Phys Eng Sci. 2020 Apr 17;378(2169):20190192. doi: 10.1098/rsta.2019.0192. Epub 2020 Mar 2.

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验