首页> 外文期刊>Computers & Security >PKI4IoT: Towards public key infrastructure for the Internet of Things
【24h】

PKI4IoT: Towards public key infrastructure for the Internet of Things

机译:PKI4IoT:迈向物联网的公钥基础设施

获取原文
获取原文并翻译 | 示例
           

摘要

Public Key Infrastructure is the state-of-the-art credential management solution on the Internet. However, the millions of constrained devices that make of the Internet of Things currently lack a centralized, scalable system for managing keys and identities. Modern PK1 is built on a set of protocols which were not designed for constrained environments, and as a result many small, battery-powered IoT devices lack the required computing resources. In this paper, we develop an automated certificate enrollment protocol light enough for highly constrained devices, which provides end-to-end security between certificate authorities (CA) and the recipient IoT devices. We also design a lightweight profile for X.509 digital certificates with CBOR encoding, called XIOT. Existing CAs can now issue traditional X.509 to IoT devices. These are converted to and from the XIOT format by edge devices on constrained networks. This procedure preserves the integrity of the original CA signature, so the edge device performing certificate conversion need not be trusted. We implement these protocols within the Contiki embedded operating system and evaluate their performance on an ARM Cortex-M3 platform. Our evaluation demonstrates reductions in energy expenditure and communication latency. The RAM and ROM required to implement these protocols are on par with the other lightweight protocols in Contiki's network stack.
机译:公钥基础结构是Internet上最先进的凭据管理解决方案。但是,数百万受物联网约束的设备目前缺少用于管理密钥和身份的集中式,可扩展的系统。现代PK1建立在一组协议的基础上,这些协议不是为受约束的环境而设计的,因此,许多由电池供电的小型IoT设备缺少所需的计算资源。在本文中,我们开发了一种轻量级的自动证书注册协议,该协议对于高度受限的设备足够轻巧,它在证书颁发机构(CA)与接收方IoT设备之间提供了端到端的安全性。我们还为带有CBOR编码的X.509数字证书设计了一个轻量级配置文件,称为XIOT。现有的CA现在可以向物联网设备发布传统的X.509。这些由受限网络上的边缘设备与XIOT格式进行相互转换。此过程保留了原始CA签名的完整性,因此不需要信任执行证书转换的边缘设备。我们在Contiki嵌入式操作系统中实现这些协议,并在ARM Cortex-M3平台上评估它们的性能。我们的评估表明,减少了能源消耗和通信延迟。实施这些协议所需的RAM和ROM与Contiki网络堆栈中的其他轻量级协议相当。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号