CFRV: A Decentralized Control-Flow Attestation Schema Using Mutual Secret Sharing.

Sensors (Basel)

School of Cyber Science and Engineering, Zhengzhou University, Zhengzhou 450001, China.

Published: August 2022

AI Article Synopsis

Article Abstract

Control-flow attestation (CFA) is a mechanism that securely logs software execution paths running on remote devices. It can detect whether a device is being control-flow hijacked by launching a challenge-response process. In the growing landscape of the Internet of Things, more and more peer devices need to communicate to share sensed data and conduct inter-operations without the involvement of a trusted center. Toward the scalability of CFA mechanisms and mitigating the single-point failure, it is important to design a decentralized CFA schema. This paper proposed a decentralized schema (CFRV) to verify the control flow on remote devices. Moreover, it introduces a token (asymmetric secret slices) into peer devices to make the attestation process mutual. In this case, CFRV can mitigate a particular kind of man-in-the-middle attack called . We built our prototype toolbox on Raspberry-Pi to formulate our proof of concept. In our evaluation, CFRV protects the verification process from malicious verifiers and the man-in-the-middle attack. The proposed mechanism can also limit the PKI (Public Key Infrastructure) usage to a single stage to save the peer devices' computational cost. Compared to related decentralized schemes, the cryptographic operation's duration is reduced by 40%.

Download full-text PDF

Source
http://www.ncbi.nlm.nih.gov/pmc/articles/PMC9415934PMC
http://dx.doi.org/10.3390/s22166044DOI Listing

Publication Analysis

Top Keywords

control-flow attestation
8
remote devices
8
peer devices
8
man-in-the-middle attack
8
cfrv
4
cfrv decentralized
4
decentralized control-flow
4
attestation schema
4
schema mutual
4
mutual secret
4

Similar Publications

Want AI Summaries of new PubMed Abstracts delivered to your In-box?

Enter search terms and have AI summaries delivered each week - change queries or unsubscribe any time!