AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
Article Link
Collect
Submit Manuscript
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline
Regular Paper

A Secure IoT Firmware Update Scheme Against SCPA and DoS Attacks

School of Cyber Science and Technology, Shandong University, Qingdao 266237, China
Key Laboratory of Cryptologic Technology and Information Security (Shandong University), Ministry of Education, Qingdao 266237, China
Show Author Information

Abstract

In the IEEE S&P 2017, Ronen et al. exploited side-channel power analysis (SCPA) and approximately 5 000 power traces to recover the global AES-CCM key that Philip Hue lamps use to decrypt and authenticate new firmware. Based on the recovered key, the attacker could create a malicious firmware update and load it to Philip Hue lamps to cause Internet of Things (IoT) security issues. Inspired by the work of Ronen et al., we propose an AES-CCM-based firmware update scheme against SCPA and denial of service (DoS) attacks. The proposed scheme applied in IoT terminal devices includes two aspects of design (i.e., bootloader and application layer). Firstly, in the bootloader, the number of updates per unit time is limited to prevent the attacker from acquiring a sufficient number of useful traces in a short time, which can effectively counter an SCPA attack. Secondly, in the application layer, using the proposed handshake protocol, the IoT device can access the IoT server to regain update permission, which can defend against DoS attacks. Moreover, on the STM32F405+M25P40 hardware platform, we implement Philips’ and the proposed modified schemes. Experimental results show that compared with the firmware update scheme of Philips Hue smart lamps, the proposed scheme additionally requires only 2.35 KB of Flash memory and a maximum of 0.32 s update time to effectively enhance the security of the AES-CCM-based firmware update process.

Electronic Supplementary Material

Download File(s)
jcst-36-2-419-Highlights.pdf (349.6 KB)
jcst-36-2-419_ESM.pdf (491 KB)

References

【1】
【1】
 
 
Journal of Computer Science and Technology
Pages 419-433

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
Fan Y-H, Wang M-Q, Li Y-B, et al. A Secure IoT Firmware Update Scheme Against SCPA and DoS Attacks. Journal of Computer Science and Technology, 2021, 36(2): 419-433. https://doi.org/10.1007/s11390-020-9831-8

1252

Views

6

Crossref

5

Web of Science

6

Scopus

0

CSCD

Received: 09 July 2019
Accepted: 24 February 2020
Published: 05 March 2021
©Institute of Computing Technology, Chinese Academy of Sciences 2021