IoT technology has been developing rapidly, while at the same time, it raises cybersecurity concerns. Mirai, a notorious IoT malware, is one of the representative threats; it infects many IoT devices and turns them into botnets, and the botnets rapidly spread infection over IoT networks. It seems hard to eliminate the chance of devices being infected with malware completely. Therefore, we believe it is essential to consider systems that enable us to remotely stop (or control) infected devices as soon as possible to prevent or limit malicious behaviors of infected devices. In this paper, we design a promising candidate for such remote-control systems, called IoT-REX (REemote-Control System for IoT devices). IoT-REX allows a systems manager to designate an arbitrary subset of all IoT devices in the system and generate authenticated information that contains any command the system manager wants. Every device can confirm whether or not the device itself was designated; if so, the device executes the command. Towards realizing IoT-REX, we introduce a novel cryptographic primitive called centralized multi-designated verifier signatures (CMDVS). Although CMDVS works under a restricted condition compared to conventional MDVS, it is sufficient for realizing IoT-REX. We provide an efficient CMDVS construction from any approximate membership query structures and digital signatures, yielding compact communication sizes and efficient verification procedures for IoT-REX.
翻译:IPT技术在迅速发展的同时,也引起了网络安全方面的担忧。Mirai是一个臭名昭著的IOT恶意软件,是具有代表性的威胁之一;它感染了许多IOT装置,将其变成肉麻,而肉网在IOT网络上迅速传播。似乎很难消除装置被恶意软件完全感染的机会。因此,我们认为,必须考虑能够使我们尽快远程停止(或控制)感染装置的系统,以防止或限制受感染装置的恶意行为。在本文中,我们设计了一个有前途的远程控制系统候选人,称为IOT-REX(IOT-REX(IOT装置的remote-控制系统),将它们变成肉网,而肉网在IOT网络上迅速传播。IOT-REnets让系统管理员可以任意指定该系统所有IOT装置的一组,并生成包含系统管理者所想要的任何指令的经认证的信息。每个装置都能够确认装置是否被指定;如果如此,该装置执行命令。为了实现 IOT-REX,我们从一个名为中央级的加密智能智能智能智能智能化的多校验测试程序。