Suppr超能文献

RESEKRA:使用密封密钥进行远程证明的远程注册。

RESEKRA: Remote Enrollment Using SEaled Keys for Remote Attestation.

机构信息

Infineon Technologies AG, 85579 Neubiberg, Germany.

Departamento Electrónica y Tecnología de Computadores, Universidad de Granada, 18071 Granada, Spain.

出版信息

Sensors (Basel). 2022 Jul 5;22(13):5060. doi: 10.3390/s22135060.

Abstract

This paper presents and implements a novel remote attestation method to ensure the integrity of a device applicable to decentralized infrastructures, such as those found in common edge computing scenarios. Edge computing can be considered as a framework where multiple unsupervised devices communicate with each other with lack of hierarchy, requesting and offering services without a central server to orchestrate them. Because of these characteristics, there are many security threats, and detecting attacks is essential. Many remote attestation systems have been developed to alleviate this problem, but none of them can satisfy the requirements of edge computing: accepting dynamic enrollment and removal of devices to the system, respecting the interrupted activity of devices, and last but not least, providing a decentralized architecture for not trusting in just one Verifier. This security flaw has a negative impact on the development and implementation of edge computing-based technologies because of the impossibility of secure implementation. In this work, we propose a remote attestation system that, through using a Trusted Platform Module (TPM), enables the dynamic enrollment and an efficient and decentralized attestation. We demonstrate and evaluate our work in two use cases, attaining acceptance of intermittent activity by IoT devices, deletion of the dependency of centralized verifiers, and the probation of continuous integrity between unknown devices just by one signature verification.

摘要

本文提出并实现了一种新颖的远程认证方法,以确保适用于去中心化基础设施(如常见边缘计算场景中发现的基础设施)的设备的完整性。边缘计算可以被视为一种框架,其中多个无监督设备相互通信,缺乏层次结构,在没有中央服务器来协调它们的情况下请求和提供服务。由于这些特点,存在许多安全威胁,检测攻击至关重要。已经开发了许多远程认证系统来缓解这个问题,但没有一个系统能够满足边缘计算的要求:接受设备到系统的动态注册和删除,尊重设备的中断活动,最后但并非最不重要的是,为不只是一个验证者提供去中心化架构。由于无法进行安全实现,这个安全缺陷对基于边缘计算的技术的开发和实施产生了负面影响。在这项工作中,我们提出了一种远程认证系统,该系统通过使用可信平台模块(TPM),实现了动态注册和高效、去中心化的认证。我们在两个用例中展示和评估了我们的工作,实现了物联网设备间歇性活动的接受、删除对集中式验证者的依赖以及仅通过一次签名验证即可验证未知设备之间的持续完整性。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/4426/9269829/bcc47d57c7b5/sensors-22-05060-g001.jpg

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验