Title
Indraj: digital certificate enrollment for battery-powered wireless devices
Abstract
A public key infrastructure (PKI) has been widely deployed and well tested on the Internet. However, this standard practice of delivering scalable security has not yet been extended to the rapidly growing Internet of Things (IoT). Thanks to vendor hardware support and standardization of resource-efficient communication protocols, asymmetric cryptography is no longer unfeasible on small devices. To migrate IoT from poorly scalable, pair-wise symmetric encryption to PKI, a major obstacle remains: how do we certify the public keys of billions of small devices without manual checks or complex logistics? The process of certifying a public key in form of a digital certificate is called enrollment. In this paper, we design an enrollment protocol, called Indraj, to automate enrollment of certificate-based digital identities on resource-constrained IoT devices. Reusing the semantics of the Enrollment over Secure Transport (EST) protocol designed for Internet hosts, Indraj optimizes resource usage by leveraging an IoT stack consisting of Constrained Application Protocol (CoAP), Datagram Transport Layer Security (DTLS) and IPv6 over Low-Power Wireless Personal Area Networks (6LoWPAN). We evaluate our implementation on a low power 32-bit MCU, showing the feasibility of our protocol in terms of latency, power consumption and memory usage. Asymmetric cryptography enabled by automatic certificate enrollment will finally turn IoT devices into well behaved, first-class citizens on the Internet.
Year
DOI
Venue
2019
10.1145/3317549.3323408
Proceedings of the 12th Conference on Security and Privacy in Wireless and Mobile Networks
Keywords
Field
DocType
EST, PKI, contiki OS, digital certificate, enrollment, internet of things, security
Public key infrastructure,IPv6,Computer science,Public key certificate,Computer security,Datagram Transport Layer Security,Computer network,Constrained Application Protocol,Public-key cryptography,Communications protocol,The Internet
Conference
ISBN
Citations 
PageRank 
978-1-4503-6726-4
1
0.37
References 
Authors
0
3
Name
Order
Citations
PageRank
Zhitao He135324.91
Martin Furuhed210.37
Shahid Raza349336.66