论文标题

确保智能家居边缘设备免受损坏的云服务器

Securing Smart Home Edge Devices against Compromised Cloud Servers

论文作者

Trimananda, Rahmadi, Younis, Ali, Kwa, Thomas, Demsky, Brian, Xu, Harry

论文摘要

智能家用物联网系统通常依靠基于云的服务器进行组件之间的通信。尽管在物联网安全方面存在大量工作,但其中大多数都集中在确保客户(即物联网设备)上。但是,云服务器也可能会受到损害。现有的方法通常不会保护智能家庭系统免受受损的云服务器的影响。 本文介绍了Fidelius:一个运行时系统,即使在存在受损的服务器的情况下,也用于安全的基于云的存储和通信。 Fidelius的设计是针对具有间歇性互联网访问的智能家庭系统量身定制的。特别是,如果丢失了与云的通信,它支持对智能家居设备的本地控制,并使用交易来提供一致性模型来减轻由于网络分区而可能出现的不一致之处。我们已经实施了Fidelius,开发了使用Fidelius的智能家居基准,并测量了Fidelius的性能和功耗。我们的实验表明,与商业粒子框架相比,Fidelius缩短了数据通信时间的50%以上,并将电池寿命提高了2倍。与Pyoram相比,替代性(基于Oram)的遗产实现的实现,Fidelius的访问时间更快4-7倍,数据传输的数据减少了25-43倍。

Smart home IoT systems often rely on cloud-based servers for communication between components. Although there exists a body of work on IoT security, most of it focuses on securing clients (i.e., IoT devices). However, cloud servers can also be compromised. Existing approaches do not typically protect smart home systems against compromised cloud servers. This paper presents FIDELIUS: a runtime system for secure cloud-based storage and communication even in the presence of compromised servers. FIDELIUS's design is tailored for smart home systems that have intermittent Internet access. In particular, it supports local control of smart home devices in the event that communication with the cloud is lost, and provides a consistency model using transactions to mitigate inconsistencies that can arise due to network partitions. We have implemented FIDELIUS, developed a smart home benchmark that uses FIDELIUS, and measured FIDELIUS's performance and power consumption. Our experiments show that compared to the commercial Particle.io framework, FIDELIUS reduces more than 50% of the data communication time and increases battery life by 2X. Compared to PyORAM, an alternative (ORAM-based) oblivious storage implementation, FIDELIUS has 4-7X faster access times with 25-43X less data transferred.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源