论文标题

通过商业物联网设备进行安全固件更新和测试的分散方法

A decentralized approach towards secure firmware updates and testing over commercial IoT Devices

论文作者

Gupta, Projjal

论文摘要

互联网技术在计算和数据科学领域发生了范式转变,而定义变化的一种范式就是物联网或物联网。如今,成千上万的家用电器使用集成的智能设备,这些设备允许远程监视和控制,还允许使用诸如高端AI综合智能安全系统等密集的计算工作,并为用户提供持续的警报。这些物联网设备的更新过程通常缺乏检查集中式服务器安全性的能力,这些服务器可能会受到损害并托管恶意固件文件,因为假定服务器在部署过程中是安全的。可以使用分散的数据库来解决此问题的解决方案,以持有哈希和固件。本文讨论了用于托管商业物联网产品的固件的不安全服务器的可能含义,并旨在提供基于区块链的分散解决方案,以托管固件文件,具有不可变性的属性,并控制了对固件上传功能的控制访问,以便停止未经授权的使用。该论文对可能的硬件实现以及在此类安全的体系结构模型中使用密码安全组件的使用阐明了灯光。

Internet technologies have made a paradigm shift in the fields of computing and data science and one such paradigm defining change is the Internet of Things or IoT. Nowadays, thousands of household appliances use integrated smart devices which allow remote monitoring and control and also allow intensive computational work such as high end AI-integrated smart security systems with sustained alerts for the user. The update process of these IoT devices usually lack the ability of checking the security of centralized servers, which may be compromised and host malicious firmware files as it is presumed that the servers are secure during deployment. The solution for this problem can be solved using a decentralized database to hold the hashes and the firmware. This paper discusses the possible implications of insecure servers used to host the firmwares of commercial IoT products, and aims to provide a blockchain based decentralized solution to host firmware files with the property of immutability, and controlled access to the firmware upload functions so as to stop unauthorized use. The paper sheds light over possible hardware implementations and the use of cryptographically secure components in such secure architecture models.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源