VIETNAM NATIONAL UNIVERSITY HO CHI MINH CITY UNIVERSITY OF TECHNOLOGY -------------------- NGUYEN LE PHUONG THAO AUTHENTICATION PROTOCOL FOR INTERNET OF THINGS DEVICES USING BLUETOOTH LOW ENERGY Majors: Computer Science ID: 60480101 MASTER THESIS Ho Chi Minh City, January 2021 i THE WORK IS DONE AT HO CHI MINH CITY UNIVERSITY OF TECHNOLOGY – VNU – HCM Scientific supervisor: Assoc. Dang Tran Khanh. The reviewer 1: Assoc. Tran Trung Hieu.
The reviewer 2: Assoc. Nguyen Tuan Dang. This master thesis is defended at Ho Chi Minh City University of Technology – VNU – HCM on 22nd January 2021. The master thesis assessment committee includes: 1.
Tran Minh Quang. Phan Trong Nhan. Huynh Trung Hieu. Nguyen Tuan Dang.
Dang Tran Khanh. Confirmation of the Chairman of the assessment committee and the Head of the specialized management department after the thesis has been corrected (if any). CHAIRMAN OF THE HEAD OF FACULTY OF ASSESSMENT COMMITTEE COMPUTER SCIENCE AND ENGINEERING ii VNU –HO CHI MINH CITY SOCIALIST REPUBLIC OF VIETNAM HO CHI MINH CITY UNIVERSITY Independence –Freedom –Happiness OFTECHNOLOGY MASTER THESIS Student name: NGUYEN LE PHUONG THAO. Date of birth: Dec 30th, 1991.
Place of birth: Ho Chi Minh City. Major: Computer Science. THESIS TITLE: Authentication Protocol for Internet of Things Devices using Bluetooth low energy II. TASKS AND CONTENTS: Proposing an authentication protocol for Internet of Things Devices using Bluetooth low energy, which is lightweight and secure.
DATE OF THE THESIS ASSIGNMENT: Feb 24th, 2020. DATE OF THE THESIS COMPLETION: Dec 20th, 2020. Dang Tran Khanh Ho Chi Minh City,……. Jan 2021 SUPERVISOR HEAD OF DEPARTMENT (Sign and full name) (Sign and full name) DEAN OF FACULTY OF COMPUTER SCIENCE AND ENGINEERING (Sign and full name) ii Acknowledgement I would like to express my gratitude to my supervisor Assoc.
Dang Tran Khanh for the continuous support of my Master study and related research. I am thankful for his patience, advice and all the opportunities he has given me during the last two years. I would like to thank my fellow master students and my co-workers at work for their help, cooperation and our friendships as well, which have encouraged and got me through certain difficult stages. Last but not least, I would like to thank my friends and my families, to my parents and my sister for unconditionally supporting me throughout the course and life in general.
Nguyen Le Phuong Thao iii Abstract More than twenty years have passed since the day the term "Internet of Things" (IoTs) first appeared, now IoTs systems are so familiar in our daily life. The greatest benefit of IoTs comes from highly heterogeneous interconnected devices and systems, cover- ing every shape, size, and functionality. Being considered as the future of the Internet, IoT development comes with urgent requirements about the provision of security and privacy as the number of deployed IoT devices rapidly increases every year. Among those, authenticity is the main requirement for the IoT.
Device to Device connection is also a crucial part of IoTs. One of the most popular standards for Device to Device connection is Bluetooth. Bluetooth Low Energy (BLE) is increasing in popularity, especially now many scientists are proposing it as a technique for contact tracing to combat COVID-19. Additionally, BLE is being used in applications involving trans- ferring sensitive information such as home security systems.
Therefore, a secure au- thentication protocol for IoTs based on BLE framework will be necessary due to the lightweight and popularity of BLE. In this thesis, I propose a new authentication solution for BLE with enhanced privacy, but minimal impact on energy consumption. I also provided a framework to demonstrate our protocol can be implemented on real devices, which support BLE modules. The correctness of the proposed scheme is formally proved with BAN logic.
Additionally, I provided an information security analysis to prove my protocol can withstand typical types of cyberattacks. Last but not least, I measured the execution time and power consumption when applying my protocol on the top of BLE frame- work. I also attach three publicized articles regarding to my research during master study. iv Tóm tắt luận văn Hơn hai mươi năm đã trôi qua kể từ ngày thuật ngữ “Internet of Things” (IoTs) lần đầu tiên xuất hiện, giờ đây các hệ thống IoTs đã quá quen thuộc trong cuộc sống hàng ngày của chúng ta.
Lợi ích to lớn của nó đến từ sự kết nối chặt chẽ thiết bị và hệ thốngvô cùng đa dạng về mặt chủng loại, hình dáng, kích thước cũng như chức năng. Được xem là tương lai của Internet, sự phát triển của IoT đi kèm với các yêu cầu cấp thiết về việc cung cấp bảo mật và quyền riêng tư khi số lượng thiết bị IoT được triển khai tăng nhanh hàng năm. Trong số đó, khả năng xác thực là yêu cầu quan trọng đối với IoT. Kết nối thiết bị với thiết bị cũng là một phần thiết yếu của IoT.
Một trong những tiêu chuẩn phổ biến nhất cho kết nối Thiết bị với Thiết bị là Bluetooth. Bluetooth Low Energy (BLE) đang ngày càng phổ biến, đặc biệt là khi hiện nay nhiều nhà khoa học đang đề xuất nó như một kỹ thuật truy tìm liên lạc để chống lại COVID-19. Ngoài ra, BLE đang được sử dụng trong các ứng dụng liên quan đến việc chuyển thông tin nhạy cảm như hệ thống an ninh gia đình. Do đó, một giao thức xác thực an toàn cho IoTs dựa trên nền tảng BLE sẽ là cần thiết do tính hiệu quả và phổ biến của BLE.
Trong luận văn này, tôi sẽ đề xuất một giải pháp xác thực mới cho IoTs trên nền tảng BLE với tính riêng tư được nâng cao nhưng tiêu thụ năng lượng một cách tối thiểu. Tôi cũng đã cung cấp một khuôn khổ để chứng minh giao thức của chúng tôi có thể được triển khai trên các thiết bị thực hỗ trợ các phần cứng BLE. Tính đúng đắn của giao thức đề xuất được chứng minh với logic BAN. Ngoài ra, luận văn cũng cung cấp phân tích bảo mật thông tin để chứng minh giao thức được đề xuất có thể chống lại các loại tấn công mạng điển hình.
Cuối cùng, tôi đã thực hiện các đo đạc cần thiết để đảm bảo tính tiết kiệm năng lượng cuả giao thức. v Declaration of authorship I declare that the work presented herein is my own original work and has not been published or submitted elsewhere for any degree programme, diploma or other qual- ifications. Any literature data or work done by others and cited within this thesis has been completely listed in the reference section. Nguyen Le Phuong Thao vi Contents Acknowledgement iii Abstract iv Tóm tắt luận văn v Declaration of authorship vi List of acronyms xiii 1 Introduction 1 1.2 Major purposes of the thesis .1 Internet of Things overview .2 Public key cryptography .1 Public-key encryption .2 Public-key digital signature .3 Bluetooth Low Energy .1 BAN-logic overview .3 Typical protocol goals .4 Protocol analysis with BAN-logic .1 Criteria of Authentication schemes .2 Existing authentication frameworks.
27 5 System implementation and proposed framework 33 5.2 Authentication Message Calculation. 49 8 Conclusion and Future Work 51 List of published articles 53 Appendix 54 References 108 Autobiography xiv ix List of Figures 1.1 The global market of IoT devices estimations by years.2 The network architecure considered in the scope of this thesis.1 Different application domains of the Internet of Things [16].2 Encryption/Decryption in Public-key cryptosystems.3 Using a Digital Signature to Validate Data Integrity .4 BLE network topology .2 Three entities authentication protocol [36] .1 Detailed proposed authentication protocol .2 Party-Crasher protocol .3 Party-Crasher protocol overview .4 Detailded proposed authentication protocol .5 Same link key in PC and PP .1 Raspberry Pi boards set up .1 Execution time PC .2 Execution time PP. 50 xi List of Tables 7.1 Power consumption and duration of each phase of BLE.2 consumption and duration of each phase of Zigbee.3 The energy used by two devices for their mutual authentication. 49 xii List of acronyms Acronym Meaning IoT Internet of Things D2D Device-to-Device BLE Bluetooth Low Energy ECC Elliptic Curve Cryptography TLS Transport Layer Security DTLS Data Transport Layer Security UDP User Datagram Protocol TCP Transmission Control Protocol TPM Trusted Platform Module ECDH Elliptic-curve Diffie–Hellman ECDHP Elliptic-curve Diffie–Hellman Problem ECDLP Elliptic Curve Discrete Logarithm Problem ECDDHP Elliptic-curve Decision Diffie–Hellman Problem EC Elliptic Curve PC Party-Crasher PO Party-Owner PP Party-Participant LTK Long term key IRK Identity Resolving Key CSRK Connection Signature Resolving Key API Application Programming Interface xiii Chapter 1 Introduction 1.1 Overview In 1999, the term "Internet of Things" (IoTs) first appeared in a presentation of Kevin Ashton [1].
Also within this year, Neil Gershenfeld was speaking about similar defi- nition from the MIT Media Lab in his book "When Things Start to Think" [2]. 1999 can be considered as a big year for IoTs. Nearly twenty years have passed, now IoTs systems are so familiar in our daily life. The number of IoTs devices increases rapidly every year and is forecast to grow to almost 31 billion worldwide in 2020 [3].
The appearance of IoTs changes the ways in which individuals and organizations interact with the physical world and communicate among themselves. For example, the inter- action with home equipment, automotive, mobile devices and industrial machines will be not the same as before. In all aspects of modern life, i. learning, traffic, health care, working ., applying IoT technology helps to improve the quality of services and increase satisfaction of users.
Its greatest benefit comes from highly heterogeneous in- terconnected devices and systems, covering every shape, size, and functionality. As shown in Figure 1.1, researcher estimated that around 75.4 billions of devices will be connected to the Internet by 2025 [4]. These objects in the IoT have capabilities of communicating and interacting with each other to exchange their data, providing monitoring of the environment around to enable and giving responses to changes in the system’s environment. Such capabilities are promising in totally changing human lifestyle, making it safer, more convenient and comfortable.
This motivation has at- tracted and encouraged many researchers to participate in designing and inventing 1 novel solutions and applications for the IoT.1: The global market of IoT devices estimations by years. With this growth of IoTs, security becomes a survival problem. In fact, Gartner ’s 2016 IoT Backbone Survey showed that 32% of Information Technology leaders cited security as a top barrier to IoT success [5]. In order to keep the IoT the system safe, the authentication process between IoT devices must be well-controlled.
How- ever, IoTs environment also has its own constraints which make it different from other systems: the uncontrolled environment, the heterogeneity, the need for scalability, as well as the constrained resource [6]. As a result, the authentication protocol in IoT must be lightweight and flexible. Gartner reports that 20% of organizations suffer at least one IoT security attack in the last three years [7]. Prior technology trends, e., cloud computing and big data, seem to have quite similar security requirements with the IoT.
Nonetheless, the IoT unique nature introduces new challenges to security re- quirements, which are much different from previous technology trends. For example, big data solutions are not required to deal with an uncontrolled environment and con- strained resources, while cloud computing hardly deals with the mobility of devices and physical accessibility of sensors [8]. The security requirements for IoT systems depend on their domains of appli- cations. They include the needs of confidentiality, integrity, and authenticity.
Among those, authenticity is the major requirement for the IoT [9], which provides the proof that a connection is established with an authenticated entity.