COOB: Hybrid secure device pairing scheme in a hostile environment

  • Sameh Khalfaoui
  • , Jean Leneutre
  • , Arthur Villard
  • , Jingxuan Ma
  • , Pascal Urien

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Due to the scalability limitations, the secure device pairing of Internet of Things objects cannot be efficiently conducted based on traditional cryptographic techniques using a pre-shared security knowledge. The use of Out-of-Band (OoB) channels has been proposed as a way to authenticate the key establishment process but they require a relatively long time and an extensive user involvement to transfer the authentication bits. However, the context-based schemes exploit the randomness of the ambient environment to extract a common secret without an extensive user intervention under the requirement of having a secure perimeter during the extraction phase, which is considered as a strong security assumption. In this paper, we introduce a novel hybrid scheme, called COOB, that efficiently combines a state-of-the-art fast context-based encoder with our Out-of-Band based scheme. This protocol exploits a nonce exponentiation to achieve the temporary secrecy goal needed for the authentication. Our method provides security against an attacker that can violate the secure perimeter requirement, which is not supported by the existing contextual schemes. This security improvement has been formally validated in the symbolic model using the TAMARIN prover. Based on our implementation of the Out-of-Band channel, COOB enhances the usability by reducing the pairing time up to 39 % for an 80-bit OoB exchange while keeping an optimal protocol cost.

Original languageEnglish
Title of host publicationSecurity and Privacy in Communication Networks - 16th EAI International Conference, SecureComm 2020, Proceedings
EditorsNoseong Park, Kun Sun, Sara Foresti, Kevin Butler, Nitesh Saxena
PublisherSpringer Science and Business Media Deutschland GmbH
Pages419-438
Number of pages20
ISBN (Print)9783030630942
DOIs
Publication statusPublished - 1 Jan 2020
Event16th International Conference on Security and Privacy in Communication Networks, SecureComm 2020 - Washington, United States
Duration: 21 Oct 202023 Oct 2020

Publication series

NameLecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, LNICST
Volume336
ISSN (Print)1867-8211

Conference

Conference16th International Conference on Security and Privacy in Communication Networks, SecureComm 2020
Country/TerritoryUnited States
CityWashington
Period21/10/2023/10/20

Keywords

  • Context-based pairing
  • Formal methods
  • Internet of Things
  • Out-of-band channel
  • Secure device pairing
  • Security

Fingerprint

Dive into the research topics of 'COOB: Hybrid secure device pairing scheme in a hostile environment'. Together they form a unique fingerprint.

Cite this