IoT technology has been developing rapidly, while at the same time, notorious IoT malware such as Mirai is a severe and inherent threat. We believe it is essential to consider systems that enable us to remotely control infected devices in order to prevent or limit malicious behaviors of infected devices. In this paper, we design a promising candidate for such remote-control systems, called IoT-REX (REmote-Control System for IoT devices). IoT-REX allows a systems manager to designate an arbitrary subset of all IoT devices in the system and every device can confirm whether or not the device itself was designated; if so, the device executes a command given from the systems manager. Towards realizing IoT-REX, we introduce a novel cryptographic primitive called centralized multi-designated verifier signatures (CMDVS). Although CMDVS works under a restricted condition compared to conventional MDVS, it is sufficient for realizing IoT-REX. We provide an efficient CMDVS construction from any approximate membership query structures and digital signatures, yielding compact communication sizes and efficient verification procedures for IoT-REX. We then discuss the feasibility of IoT-REX through cryptographic implementation of the CMDVS construction on a Raspberry Pi. Our promising results demonstrate that the CMDVS construction can compress communication size to about 30% and thus its resulting IoT-REX becomes three times faster than a trivial construction over typical low-power wide area networks with an IoT device. It is expected that IoT-REX can control 12,000 devices within a second.
翻译:IoT技术一直在迅速发展,而与此同时,臭名昭著的IoT恶意软件,如Mirai,是一个严重和固有的威胁。我们认为,必须考虑能够使我们远程控制受感染装置以防止或限制受感染装置的恶意行为的系统,以防止或限制受感染装置的恶意行为。在本文中,我们设计了这种遥控系统的有希望的候选者,称为IoT-REX(IoT装置的遥控系统)。IoT-REX允许系统管理员指定一个系统系统中所有IoT常规装置的任意子集,每个装置都能够确认该装置是否被指定;如果是,该装置将执行系统管理员授予的命令。为了实现IoT-REX,我们引入了一个新的加密原始原始的叫做中央多用途验证签名(CMDVS)。虽然CMDVS的工作条件与常规MVS相比是有限的,但对于实现IOT-REX的第二个条件就足够了。我们从任何接近的会员查询结构和数字签名中提供高效的CMDVS结构,从而产生压缩通信规模和高效的核查程序,从而产生IMX的IX 10 的建造结果。