Questioning the security and efficiency of the ESIoT approach

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

ESIoT is a secure access control and authentication protocol introduced for Internet of Things (IoT) applications. The core primitive of ESIoT is an identity-based broadcast encryption scheme called Secure Identity-Based Broadcast Encryption (SIBBE). SIBBE is designed to provide secure key distribution among a group of devices in IoT networks, and enable devices in each group to perform mutual authentication. The scheme is also designed to hide the structure of the group from nodes outside of the group. We identify multiple efficiency and security issues in this primitive that prove SIBBE unsuitable for IoT applications. First, we show that contrary to what was claimed, the size of the ciphertexts generated by the encryption function is not constant but in fact linear in the number of devices in the group. Additionally, we demonstrate that the encryption and decryption costs are also linear in the number of nodes in the group, implying scalability issues thus inefficiency for IoT applications. In terms of security, we prove that SIBBE does not achieve the desired property of anonymity and allows an attacker to gain information on the structure of any given group. Finally, we demonstrate how SIBBE does not achieve the claimed chosen-ciphertext security. We however prove its security for a weaker security notion (namely selective-ID indistinguishability against chosen-plaintext attacks) under a variant of the GDDHE assumption.

Original languageEnglish
Title of host publicationWiSec 2018 - Proceedings of the 11th ACM Conference on Security and Privacy in Wireless and Mobile Networks
PublisherAssociation for Computing Machinery, Inc
Pages202-207
Number of pages6
ISBN (Electronic)9781450357319
DOIs
Publication statusPublished - 18 Jun 2018
Event11th ACM Conference on Security and Privacy in Wireless and Mobile Networks, WiSec 2018 - Stockholm, Sweden
Duration: 18 Jun 201820 Jun 2018

Publication series

NameWiSec 2018 - Proceedings of the 11th ACM Conference on Security and Privacy in Wireless and Mobile Networks

Conference

Conference11th ACM Conference on Security and Privacy in Wireless and Mobile Networks, WiSec 2018
Country/TerritorySweden
CityStockholm
Period18/06/1820/06/18

Fingerprint

Dive into the research topics of 'Questioning the security and efficiency of the ESIoT approach'. Together they form a unique fingerprint.

Cite this