VIETNAM NATIONAL UNIVERSITY HO CHI MINH CITY UNIVERSITY OF TECHNOLOGY -------------------- PHAM DUC MINH CHAU AUTHENTICATION PROTOCOL FOR RESOURCE CONSTRAINED DEVICES IN THE INTERNET OF THINGS Majors: Computer Science ID: 60480101 MASTER THESIS Ho Chi Minh City, December 2019 THE WORK IS DONE AT HO CHI MINH CITY UNIVERSITY OF TECHNOLOGY – VNU – HCM Scientific supervisor: Assoc. Dang Tran Khanh. The reviewer 1: Dr. Phan Trong Nhan.
The reviewer 2: Assoc. Nguyen Tuan Dang. This master thesis is defended at Ho Chi Minh City University of Technology – VNU – HCM on 30th December 2019. The master thesis assessment committee includes: 1.
Nguyen Thanh Binh. Le Hong Trang. Phan Trong Nhan. Nguyen Tuan Dang.
Huynh Trung Hieu. Confirmation of the Chairman of the assessment committee and the Head of the specialized management department after the thesis has been corrected (if any). CHAIRMAN OF THE HEAD OF FACULTY OF ASSESSMENT COMMITTEE COMPUTER SCIENCE AND ENGINEERING ii VNU – HO CHI MINH CITY SOCIALIST REPUBLIC OF VIETNAM HO CHI MINH CITY UNIVERSITY Independence – Freedom – Happiness OF TECHNOLOGY MASTER THESIS Student name: PHAM DUC MINH CHAU. Student ID: 1770316 Date of birth: 12-07-1994.
Place of birth: Ho Chi Minh City Major: Computer Science. THESIS TITLE: Authentication Protocol for Resource Constrained Devices in the Internet of Things II. TASKS AND CONTENTS: Proposing an authentication protocol for resource- constrained devices in the Internet of Things which also offers privacy-preserving. DATE OF THE THESIS ASSIGNMENT: 11/02/2019 IV.
DATE OF THE THESIS COMPLETION: 08/12/2019 V. Dang Tran Khanh Ho Chi Minh City, … December 2019 SUPERVISOR HEAD OF DEPARTMENT (Sign and full name) (Sign and full name) DEAN OF FACULTY OF COMPUTER SCIENCE AND ENGINEERING (Sign and full name) iii Acknowledgement I would like to express my gratitude to my supervisor Assoc. Dang Tran Khanh for the continuous support of my Master study and related research. I am thankful for his patience, advice and all the opportunities he has given me during the last two years.
I would like to thank my fellow master students and my co-workers at work for their help, cooperation and our friendships as well, which have encouraged and got me through certain difficult stages. Last but not least, I would like to thank my friends and my families, to my parents and my sister for unconditionally supporting me throughout the course and life in general. Pham Duc Minh Chau iv Abstract By utilizing the potential of the Internet connectivity, the Internet of Things (IoT) is now becoming a popular trend in the technology industry. Its greatest benefit comes from highly heterogeneous interconnected devices and systems, covering every shape, size, and functionality.
Being considered as the future of the Internet, IoT development comes with urgent requirements about the provision of security and privacy as the number of deployed IoT devices rapidly increases. Among those, authenticity is the major requirement for the IoT. On the other hand, one of the most important features required for the IoT is the support for resource-constrained devices. In fact, a large proportion of involved devices in the IoT has low energy power and computational capability.
Therefore, proposed solutions requiring complex computations and high energy consumption cannot be applied to the IoT in practice. In this thesis, I propose a mutual privacy-preserving authentication protocol based on the elliptic curve cryptography (ECC) to achieve efficiency in resource con- sumption and protect the privacy of involved devices. The proposed model is a holistic extension of previously related works, in which distributed network architecture, as well as secure communications between devices, are enabled. The correctness of the proposed scheme is formally proved with BAN-logic.
In addition, I provide an in- formal security analysis in which I will present its resilience to different attacks. A performance analysis is also conducted in the scope of this thesis, which proves the efficiency in resource consumption of the proposed protocols compared to the base related scheme. v Tóm tắt luận văn Bằng việc tận dụng tiềm năng kết nối của các thiết bị thông qua Internet, Mạng lưới vạn vật kết nối (Internet of Things - IoT) đang là một xu thế phát triển phổ biến trong lĩnh vực công nghệ. Lợi ích to lớn của nó đến từ sự kết nối chặt chẽ thiết bị và hệ thống vô cùng đa dạng về mặt chủng loại, hình dáng, kích thước cũng như chức năng.
Được xem như là tương lai của Internet, sự phát triển của IoT đi đôi với những thách thức cũng như yêu cầu cấp bách về khả năng cũng cấp sự bảo mật và riêng tư khi mà số lượng các thiết bị IoT được cài đặt trong thực tế không ngừng tăng lên nhanh chóng. Trong số đó, tính xác thực là một trong những yêu cầu nền tảng cho sự bảo mật trong IoT. Xác thực là một vấn đề không mới và đã có nhiều giải pháp được đề xuất dành cho vấn đề này. Tuy nhiên, chúng ta cần biết rằng một yêu cầu quan trọng đối với các giải pháp dành cho IoT là việc hỗ trợ các thiết bị có nguồn tài nguyên giới hạn.
Trên thực tế, một tỷ lệ lớn các thiết bị trong IoT có nguồn năng lượng cũng như khả năng tính toán thấp. Do đó, các giải pháp đề xuất đòi hỏi tính toán quá phức tạp và tiêu tốn nhiều năng lượng cũng như tài nguyên sẽ không thể áp dụng vào thực tiễn. Trong luận văn này, tôi sẽ đề xuất một cơ chế xác thực lẫn nhau có bảo vệ tính riêng tư dựa trên mã hóa đường cong Elliptic (Elliptic curve cryptography - ECC) để đạt được hiệu quả về mặt tiêu thụ tàì nguyên cũng như đồng thời bảo vệ tính riêng tư của các thiết bị liên quan. Mô hình đề xuất là sự kế thừa và mở rộng từ các công trình liên quan khác, trong đó kiến trúc mạng phân tán cũng như sự giao tiếp an toàn giữa các thiết bị cuối được kích hoạt.
Tính đúng đắn cũng như bảo mật của giao thức đề xuất được chứng minh với BAN-logic. Ngoài ra, luận văn cũng bao gồm phân tích về khả năng chống chọi của giải pháp đối với các loại tấn công bảo mật phổ biến trong thực tế. Phân tích về mặt hiệu năng tiêu thụ tài nguyên của được tiến hành trong phạm vi luận văn để chứng minh sự hiệu quả của giao thức được đề xuất so sánh với mô hình nền tảng trước đó. vi Declaration of authorship I declare that the work presented herein is my own original work and has not been published or submitted elsewhere for any degree programme, diploma or other qual- ifications.
Any literature data or work done by others and cited within this thesis has been completely listed in the reference section. Pham Duc Minh Chau vii Contents Acknowledgement iv Abstract v Tóm tắt luận văn vi Declaration of authorship vii List of acronyms xiii 1 Introduction 1 1.2 Major purposes of the thesis .1 Internet of Things overview .2 Cloud computing with the IoT .3 Fog computing with the IoT .2 Public key cryptography .1 Public-key encryption .2 Public-key digital signature .3 Elliptic curve cryptography .1 BAN-logic overview .3 Typical protocol goals .4 Protocol analysis with BAN-logic .1 Authentication protocol taxonomy .1 Symmetric key schemes .2 Asymmetric key schemes .2 Authentication using ECC .2 Security and privacy requirements .2 Subnetwork joining phase .1 Subnetwork joining authentication .2 Resilience to attacks .1 Computational energy cost. 58 7 Conclusions 60 References 61 Autobiography xiv List of published articles xv Appendix xvi x List of Figures 1.1 The global market of IoT devices estimations by years.2 The network architecure considered in the scope of this thesis.1 Different application domains of the Internet of Things [10].2 A two layered architecture in which End/IoT devices strongly depend- ing on the Cloud .3 Three-Layer Architecture of Fog Computing [15].4 Encryption/Decryption in Public-key cryptosystems.5 Using a Digital Signature to Validate Data Integrity .1 The network architecture for the proposed authentication protocol.2 The registration phase between a device and the trusted server through a secure channel of the proposed scheme.3 The authentication process when a device joins a subnetwork with the verification from the trusted server of the proposed scheme.4 The D2D authentication phase between two device with the verifica- tion of their gateway of the proposed scheme. 36 xi List of Tables 2.1 RSA and EC key sizes for equivalent security levels and correspond- ing bitlengths for EC parameter n and RSA modulus n [21] .1 Descriptions of the notations used in this thesis.1 Comparisons with previous schemes .1 Computational cost comparison between the proposed scheme and the base-scheme.2 Summary of energy consumption per operation.3 Data length of values used in both the proposed scheme and the base- scheme.4 Energy consumption comparisons.5 Processing time of devices in seconds.6 Transmission length of each entity in the proposed protocol and in the base scheme in the joining phase.
59 xii List of acronyms Acronym Meaning IoT Internet of Things ECC Elliptic Curve Cryptography TLS Transport Layer Security DTLS Data Transport Layer Security UDP User Datagram Protocol TCP Transmission Control Protocol TPM Trusted Platform Module ECDH Elliptic-curve Diffie–Hellman ECDHP Elliptic-curve Diffie–Hellman Problem ECDLP Elliptic Curve Discrete Logarithm Problem ECDDHP Elliptic-curve Decision Diffie–Hellman Problem EC Elliptic Curve D2D Device-to-Device xiii Chapter 1 Introduction 1.1 Overview The Internet of Things (IoT), which was first introduced by Kevin Ashton [3] in 1999, has opened new opportunities for the research community to study its wide variety of aspects in the area of wireless communications and networking in the past few years. By utilizing the potential of Internet connectivity, the IoT is now becoming a popular trend in the technology industry. Its greatest benefit comes from highly heteroge- neous interconnected devices and systems, covering every shape, size, and function- ality. As shown in Figure 1.1, it is forecasted that around 75.4 billions of devices will be connected to the Internet by 2025 [1].
These objects in the IoT have capabilities of communicating and interacting with each other to exchange their data, providing monitoring of the environment around to enable and giving responses to changes in the system’s environment. Such capabilities are promising in totally changing human lifestyle, making it safer, more convenient and comfortable. This motivation has at- tracted and encouraged many researchers to participate in designing and inventing novel solutions and applications for the IoT. IoT development also comes with urgent requirements about the provision of security and privacy as the number of deployed IoT devices rapidly increases.
Gartner reports that 20% of organizations suffer at least one IoT security attack in the last three years [2]. Prior technology trends, e., cloud computing and big data, seem to have quite similar security requirements with the IoT. Nonetheless, the IoT unique nature introduces new challenges to security requirements, which are much different from 1 Figure 1.1: The global market of IoT devices estimations by years. previous technology trends.
For example, big data solutions are not required to deal with an uncontrolled environment and constrained resources, while cloud computing hardly deals with the mobility of devices and physical accessibility of sensors [3]. The security requirements for IoT systems depend on their domains of appli- cations. They include the needs of confidentiality, integrity, and authenticity. Among those, authenticity is the major requirement for the IoT [4], which provides the proof that a connection is established with an authenticated entity.
Authentication is an im- portant factor in which each connected object’s identity is required to be verified be- fore they can securely communicate as well as access various IoT resources. Besides, privacy is considered to be one of the most dominant challenges in the IoT [5]. Highly interconnected objects in the IoT produce a huge amount of transmitted data.