Securing intra-communication in 6LoWPAN: A PKI integrated scheme

S. Goswami, S. Misra, Chaynika Taneja, Anandarup Mukherjee
{"title":"Securing intra-communication in 6LoWPAN: A PKI integrated scheme","authors":"S. Goswami, S. Misra, Chaynika Taneja, Anandarup Mukherjee","doi":"10.1109/ANTS.2014.7057265","DOIUrl":null,"url":null,"abstract":"6LoWPAN standard enables efficient integration of low power wireless networks with IPv6. However the security requirements of 6LoWPANs are high due to undefined deployment scenarios and constrained capabilities of sensor nodes. A number of schemes have been devised for secure communication over the Internet, PKI being the most widely used of them. It provides authentication, non-repudiation, confidentiality and integrity. PKI does not qualify for use in 6LoWPAN as it is not streamlined for these networks and creates a communication and processing overhead which cannot be borne by a simple wireless sensor node. We provide a scheme to integrate PKI and 6LoWPAN by essentially delegating a major portion of key management activity to the edge routers (gateway) of the LoWPAN and limiting the involvement of the end nodes to minimum communication with the edge router. The edge router maintains a Local Key Database (LKDB) by remaining in constant contact with the certification authority (CA) server and oversees all related keying functions in the LoWPAN. A request packet format and algorithm to acquire keys of the destination from edge router is proposed. Performance evaluation of the proposed scheme using a protocol analyzer indicated a time and increased packet count tradeoff for the enhanced level of security. An increase in packet payload during evaluation led to a significant increase in transmitted message count. The proposed scheme did not alter the nature of the packets transmitted and performed well at scalable loads.","PeriodicalId":333503,"journal":{"name":"2014 IEEE International Conference on Advanced Networks and Telecommuncations Systems (ANTS)","volume":"64 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2014 IEEE International Conference on Advanced Networks and Telecommuncations Systems (ANTS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ANTS.2014.7057265","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7

Abstract

6LoWPAN standard enables efficient integration of low power wireless networks with IPv6. However the security requirements of 6LoWPANs are high due to undefined deployment scenarios and constrained capabilities of sensor nodes. A number of schemes have been devised for secure communication over the Internet, PKI being the most widely used of them. It provides authentication, non-repudiation, confidentiality and integrity. PKI does not qualify for use in 6LoWPAN as it is not streamlined for these networks and creates a communication and processing overhead which cannot be borne by a simple wireless sensor node. We provide a scheme to integrate PKI and 6LoWPAN by essentially delegating a major portion of key management activity to the edge routers (gateway) of the LoWPAN and limiting the involvement of the end nodes to minimum communication with the edge router. The edge router maintains a Local Key Database (LKDB) by remaining in constant contact with the certification authority (CA) server and oversees all related keying functions in the LoWPAN. A request packet format and algorithm to acquire keys of the destination from edge router is proposed. Performance evaluation of the proposed scheme using a protocol analyzer indicated a time and increased packet count tradeoff for the enhanced level of security. An increase in packet payload during evaluation led to a significant increase in transmitted message count. The proposed scheme did not alter the nature of the packets transmitted and performed well at scalable loads.
6LoWPAN内部通信安全:一种PKI集成方案
6LoWPAN标准实现了低功耗无线网络与IPv6的高效集成。然而,由于部署场景不明确和传感器节点能力受限,6lowpan的安全性要求很高。为了在互联网上进行安全通信,已经设计了许多方案,PKI是其中使用最广泛的。它提供身份验证、不可否认性、保密性和完整性。PKI不适合在6LoWPAN中使用,因为它不适合这些网络,并且创建了一个简单的无线传感器节点无法承担的通信和处理开销。通过将密钥管理活动的主要部分委派给LoWPAN的边缘路由器(网关),并将终端节点的参与限制为与边缘路由器的最小通信,我们提供了一种集成PKI和6LoWPAN的方案。边缘路由器通过与证书颁发机构(CA)服务器保持持续联系来维护本地密钥数据库(LKDB),并监督LoWPAN中所有相关的密钥功能。提出了一种从边缘路由器获取目的地密钥的请求报文格式和算法。使用协议分析器对所提出的方案进行性能评估,指出了为提高安全级别所需的时间和增加的数据包数权衡。在评估期间数据包有效负载的增加导致传输消息计数的显著增加。该方案不改变传输数据包的性质,在可扩展负载下表现良好。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信