Secure pairing is essential for trustworthy deployment and operation of Internet of Things (IoT) devices. However, traditional pairing methods are unsuitable due to the lack of user interfaces such as keyboards. Proximity-based approaches are usable but vulnerable to nearby attackers, while methods relying on physical operations (e.g., shaking) offer higher security but require inertial sensors that most IoT devices lack. We introduceUniversal Operation Sensing, which enables IoT devices to detect user operations without inertial sensors. With this technique, users can complete pairing within seconds through simple actions, such as pressing a button or twisting a knob, using either a smartphone or a smartwatch. We further identify an accuracy issue caused by information loss in the commonly used fuzzy-commitment protocol. To address this issue, we propose TimeWall, an accurate pairing protocol that avoids fuzzy commitment and incurs zero information loss. A comprehensive evaluation shows that it is secure, usable, and efficient.
翻译:安全配对对于物联网设备的可信部署与运行至关重要。然而,由于缺乏键盘等用户界面,传统配对方法并不适用。基于邻近性的方案虽具可用性,但易受邻近攻击者威胁;而依赖物理操作的方法虽能提供更高安全性,却需要大多数物联网设备所不具备的惯性传感器。本文提出通用操作感知技术,使物联网设备无需惯性传感器即可检测用户操作。通过该技术,用户可使用智能手机或智能手表,在数秒内通过按压按钮或旋转旋钮等简单动作完成配对。我们进一步发现常用模糊承诺协议中存在因信息损失导致的准确性问题。为解决该问题,我们提出TimeWall协议——一种避免模糊承诺且实现零信息损失的精确配对协议。综合评估表明,该协议具备安全性、可用性与高效性。