轻量级安全的基于软件的执行环境

IF 6 3区 计算机科学 Q1 COMPUTER SCIENCE, INFORMATION SYSTEMS
José Cecílio , Alan Oliveira de Sá , Georg Jäger , André Souto , António Casimiro
{"title":"轻量级安全的基于软件的执行环境","authors":"José Cecílio ,&nbsp;Alan Oliveira de Sá ,&nbsp;Georg Jäger ,&nbsp;André Souto ,&nbsp;António Casimiro","doi":"10.1016/j.iot.2025.101513","DOIUrl":null,"url":null,"abstract":"<div><div>The Internet of Things (IoT) has become increasingly prevalent and used to handle sensitive and critical data. This demands mechanisms to ensure data security, protect privacy, and promote the general safety of IoT-based systems. Currently, hardware-based trusted execution environments (TEEs) are used to provide data protection, but they are not suitable for low-cost devices lacking hardware-assisted security features. To address this issue, this paper proposes a Lightweight Secured Software-based Execution Environment (LWSEE) for embedded devices. LWSEE is designed to be supported by low-cost, low-end devices without specific hardware requirements. It consists of a lightweight distributed solution that offers protection against hardware attacks, provides a comprehensive security check mechanism, enables secure application execution, and supports secure application updates to ensure the continued security of IoT devices. LWSEE comprises a secure architecture and communication protocol specially tailored to devices with constrained resources. Our experimental evaluation underlines the minimal overhead introduced by LWSEE while showing its performance in terms of execution time, CPU time, and memory usage. We examine the flexibility and adaptability of LWSEE by demonstrating that it can be configured to achieve minimal overhead (<em>e.g.</em>, <span><math><mrow><mn>39</mn><mo>.</mo><mn>8</mn></mrow></math></span> ms per message for the general integrity verification of a node). This approach enables IoT devices to remain secure without dedicated hardware, allowing for the widespread adoption of IoT technology while maintaining data safety.</div></div>","PeriodicalId":29968,"journal":{"name":"Internet of Things","volume":"30 ","pages":"Article 101513"},"PeriodicalIF":6.0000,"publicationDate":"2025-01-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"LWSEE: Lightweight Secured Software-Based Execution Environment\",\"authors\":\"José Cecílio ,&nbsp;Alan Oliveira de Sá ,&nbsp;Georg Jäger ,&nbsp;André Souto ,&nbsp;António Casimiro\",\"doi\":\"10.1016/j.iot.2025.101513\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><div>The Internet of Things (IoT) has become increasingly prevalent and used to handle sensitive and critical data. This demands mechanisms to ensure data security, protect privacy, and promote the general safety of IoT-based systems. Currently, hardware-based trusted execution environments (TEEs) are used to provide data protection, but they are not suitable for low-cost devices lacking hardware-assisted security features. To address this issue, this paper proposes a Lightweight Secured Software-based Execution Environment (LWSEE) for embedded devices. LWSEE is designed to be supported by low-cost, low-end devices without specific hardware requirements. It consists of a lightweight distributed solution that offers protection against hardware attacks, provides a comprehensive security check mechanism, enables secure application execution, and supports secure application updates to ensure the continued security of IoT devices. LWSEE comprises a secure architecture and communication protocol specially tailored to devices with constrained resources. Our experimental evaluation underlines the minimal overhead introduced by LWSEE while showing its performance in terms of execution time, CPU time, and memory usage. We examine the flexibility and adaptability of LWSEE by demonstrating that it can be configured to achieve minimal overhead (<em>e.g.</em>, <span><math><mrow><mn>39</mn><mo>.</mo><mn>8</mn></mrow></math></span> ms per message for the general integrity verification of a node). This approach enables IoT devices to remain secure without dedicated hardware, allowing for the widespread adoption of IoT technology while maintaining data safety.</div></div>\",\"PeriodicalId\":29968,\"journal\":{\"name\":\"Internet of Things\",\"volume\":\"30 \",\"pages\":\"Article 101513\"},\"PeriodicalIF\":6.0000,\"publicationDate\":\"2025-01-31\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Internet of Things\",\"FirstCategoryId\":\"94\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S2542660525000265\",\"RegionNum\":3,\"RegionCategory\":\"计算机科学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q1\",\"JCRName\":\"COMPUTER SCIENCE, INFORMATION SYSTEMS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Internet of Things","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2542660525000265","RegionNum":3,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0

摘要

物联网(IoT)已变得越来越普遍,并用于处理敏感和关键数据。这就需要建立保障数据安全、保护隐私、提升物联网系统整体安全的机制。目前,基于硬件的可信执行环境(tee)用于提供数据保护,但它们不适合缺乏硬件辅助安全特性的低成本设备。为了解决这个问题,本文提出了一种基于嵌入式设备的轻量级安全软件执行环境(LWSEE)。LWSEE被设计成支持低成本的低端设备,没有特定的硬件要求。它由一个轻量级的分布式解决方案组成,提供针对硬件攻击的保护,提供全面的安全检查机制,支持安全的应用程序执行,并支持安全的应用程序更新,以确保物联网设备的持续安全。LWSEE包括一个安全架构和通信协议,专门为资源受限的设备量身定制。我们的实验评估强调了LWSEE引入的最小开销,同时显示了其在执行时间、CPU时间和内存使用方面的性能。我们通过演示LWSEE可以配置为实现最小的开销(例如,对于节点的一般完整性验证,每条消息39.8 ms)来检查LWSEE的灵活性和适应性。这种方法使物联网设备在没有专用硬件的情况下保持安全,允许广泛采用物联网技术,同时保持数据安全。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
LWSEE: Lightweight Secured Software-Based Execution Environment
The Internet of Things (IoT) has become increasingly prevalent and used to handle sensitive and critical data. This demands mechanisms to ensure data security, protect privacy, and promote the general safety of IoT-based systems. Currently, hardware-based trusted execution environments (TEEs) are used to provide data protection, but they are not suitable for low-cost devices lacking hardware-assisted security features. To address this issue, this paper proposes a Lightweight Secured Software-based Execution Environment (LWSEE) for embedded devices. LWSEE is designed to be supported by low-cost, low-end devices without specific hardware requirements. It consists of a lightweight distributed solution that offers protection against hardware attacks, provides a comprehensive security check mechanism, enables secure application execution, and supports secure application updates to ensure the continued security of IoT devices. LWSEE comprises a secure architecture and communication protocol specially tailored to devices with constrained resources. Our experimental evaluation underlines the minimal overhead introduced by LWSEE while showing its performance in terms of execution time, CPU time, and memory usage. We examine the flexibility and adaptability of LWSEE by demonstrating that it can be configured to achieve minimal overhead (e.g., 39.8 ms per message for the general integrity verification of a node). This approach enables IoT devices to remain secure without dedicated hardware, allowing for the widespread adoption of IoT technology while maintaining data safety.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
Internet of Things
Internet of Things Multiple-
CiteScore
3.60
自引率
5.10%
发文量
115
审稿时长
37 days
期刊介绍: Internet of Things; Engineering Cyber Physical Human Systems is a comprehensive journal encouraging cross collaboration between researchers, engineers and practitioners in the field of IoT & Cyber Physical Human Systems. The journal offers a unique platform to exchange scientific information on the entire breadth of technology, science, and societal applications of the IoT. The journal will place a high priority on timely publication, and provide a home for high quality. Furthermore, IOT is interested in publishing topical Special Issues on any aspect of IOT.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信