Suppr超能文献

ZigBee 3.0网络安全挑战的综合分析

A Comprehensive Analysis of Security Challenges in ZigBee 3.0 Networks.

作者信息

Ghobakhlou Akbar, Al-Hamid Duaa Zuhair, Zandi Sara, Cato James

机构信息

Department of Data Science and Artificial Intelligence, Auckland University of Technology (AUT), Auckland 1010, New Zealand.

Department of Computer and Information Sciences, Auckland University of Technology (AUT), Auckland 1010, New Zealand.

出版信息

Sensors (Basel). 2025 Jul 25;25(15):4606. doi: 10.3390/s25154606.

Abstract

ZigBee, a wireless technology standard for the Internet of Things (IoT) devices based on IEEE 802.15.4, faces significant security challenges that threaten the confidentiality, integrity, and availability of its networks. Despite using 128-bit Advanced Encryption Standard (AES) with symmetric keys for node authentication and data confidentiality, ZigBee's design constraints, such as low cost and low power, have allowed security issues to persist. While ZigBee 3.0 introduces enhanced security features such as install codes and trust centre link key updates, there remains a lack of empirical research evaluating their effectiveness in real-world deployments. This research addresses the gap by conducting a comprehensive, hardware-based analysis of ZigBee 3.0 networks using XBee 3 radio modules and ZigBee-compatible devices. We investigate the following three core security issues: (a) the security of symmetric keys, focusing on vulnerabilities that could allow attackers to obtain these keys; (b) the impact of compromised symmetric keys on network confidentiality; and (c) susceptibility to Denial-of-Service (DoS) attacks due to insufficient protection mechanisms. Our experiments simulate realistic attack scenarios under both Centralised and Distributed Security Models to assess the protocol's resilience. The findings reveal that while ZigBee 3.0 improves upon earlier versions, certain vulnerabilities remain exploitable. We also propose practical security controls and best practices to mitigate these attacks and enhance network security. This work contributes novel insights into the operational security of ZigBee 3.0, offering guidance for secure IoT deployments and advancing the understanding of protocol-level defences in constrained environments.

摘要

ZigBee是一种基于IEEE 802.15.4的物联网(IoT)设备无线技术标准,面临着重大的安全挑战,这些挑战威胁到其网络的保密性、完整性和可用性。尽管ZigBee使用128位高级加密标准(AES)和对称密钥进行节点认证和数据保密,但其设计限制,如低成本和低功耗,使得安全问题依然存在。虽然ZigBee 3.0引入了增强的安全功能,如安装代码和信任中心链接密钥更新,但仍缺乏实证研究来评估它们在实际部署中的有效性。本研究通过使用XBee 3无线电模块和ZigBee兼容设备对ZigBee 3.0网络进行全面的基于硬件的分析,解决了这一差距。我们研究了以下三个核心安全问题:(a)对称密钥的安全性,重点关注可能使攻击者获取这些密钥的漏洞;(b)受损对称密钥对网络保密性的影响;(c)由于保护机制不足而容易受到拒绝服务(DoS)攻击的情况。我们的实验在集中式和分布式安全模型下模拟现实的攻击场景,以评估该协议的弹性。研究结果表明,虽然ZigBee 3.0在早期版本的基础上有所改进,但某些漏洞仍然可以被利用。我们还提出了实际的安全控制措施和最佳实践,以减轻这些攻击并增强网络安全性。这项工作为ZigBee 3.0的操作安全性提供了新的见解,为安全的物联网部署提供了指导,并增进了对受限环境中协议级防御的理解。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0cbe/12349651/1ec8f29a4d59/sensors-25-04606-g001.jpg

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验