Smart home IoT systems rely on authentication mechanisms to ensure that only authorized entities can control devices and access sensitive functionality. In practice, these mechanisms must balance security with usability, often favoring persistent connectivity and minimal user interaction. This paper presents an empirical analysis of authentication enforcement in deployed smart home IoT devices, focusing on how authentication state is established, reused, and validated during normal operation and under routine network conditions. A set of widely deployed consumer devices, including smart plugs, lighting devices, cameras, and a hub based ecosystem, was evaluated in a controlled residential environment using passive network measurement and controlled interaction through official mobile applications. Authentication behavior was examined during initial pairing, over extended periods of operation, after common network changes, and under replay attempts from a different local network host. The results show that authentication state established during pairing is consistently reused across control actions, persists for extended periods without explicit expiration, and remains valid after network events such as reconnection, address reassignment, and router reboot. Replay experiments demonstrate that previously observed authentication artifacts can often be reused to issue control commands from another host on the same local network with high success rates. These behaviors were observed across multiple device categories and ecosystems. The findings indicate that current smart home IoT authentication mechanisms rely on long lived trust relationships with limited binding to session freshness, network context, or controller identity.
翻译:智能家居物联网系统依赖认证机制确保只有授权实体能够控制设备并访问敏感功能。在实际应用中,这些机制必须在安全性与可用性之间取得平衡,通常倾向于维持持久连接并最小化用户交互。本文对已部署智能家居物联网设备的认证执行情况进行了实证分析,重点关注认证状态在正常运行和常规网络条件下如何建立、重用和验证。研究通过在受控住宅环境中使用被动网络测量和官方移动应用程序的受控交互,对一组广泛部署的消费级设备(包括智能插座、照明设备、摄像头和基于中枢的生态系统)进行了评估。认证行为在初始配对阶段、长期运行期间、常见网络变更后以及来自不同本地网络主机的重放尝试场景下均被检验。结果表明:配对期间建立的认证状态在控制操作中被持续重用;在没有明确过期机制的情况下长期保持有效;并在重新连接、地址重分配和路由器重启等网络事件后依然有效。重放实验证明,先前观测到的认证凭证通常可被同一本地网络中另一主机重用,并以高成功率发出控制指令。这些行为在多个设备类别和生态系统中均被观察到。研究结果表明,当前智能家居物联网认证机制依赖于长期存续的信任关系,其与会话新鲜度、网络上下文或控制器身份的绑定程度有限。