The IPv6 over Low-powered Wireless Personal Area Network (6LoWPAN) protocol was introduced to allow the transmission of Internet Protocol version 6 (IPv6) packets using the smaller-size frames of the IEEE 802.15.4 standard, which is used in many Internet of Things (IoT) networks. The primary duty of the 6LoWPAN protocol is packet fragmentation and reassembly. However, the protocol standard currently does not include any security measures, not even authenticating the fragments immediate sender. This lack of immediate-sender authentication opens the door for adversaries to launch several attacks on the fragmentation process, such as the buffer-reservation attacks that lead to a Denial of Service (DoS) attack and resource exhaustion of the victim nodes. This paper proposes a security integration between 6LoWPAN and the Routing Protocol for Low Power and Lossy Networks (RPL) through the Chained Secure Mode (CSM) framework as a possible solution. Since the CSM framework provides a mean of immediate-sender trust, through the use of Network Coding (NC), and an integration interface for the other protocols (or mechanisms) to use this trust to build security decisions, 6LoWPAN can use this integration to build a chain-of-trust along the fragments routing path. A proof-of-concept implementation was done in Contiki Operating System (OS), and its security and performance were evaluated against an external adversary launching a buffer-reservation attack. The results from the evaluation showed significant mitigation of the attack with almost no increase in power consumption, which presents the great potential for such integration to secure the forwarding process at the 6LoWPAN Adaptation Layer
翻译:低功率无线个人区域网(6LoWPAN)的IPv6号协议(6LOWPAN)被采用,以便利用互联网协议第6版(IPv6)的小型框架传输互联网协议包件,该软件在许多Times(IoT)网络互联网上使用。6LoWPAN协议的主要职责是包装碎裂和重新组装。但协议标准目前并不包括任何安全措施,甚至不认证直接发送的碎片。这种缺乏缓冲文件认证为对手启动对破碎进程的几次攻击打开了大门,例如缓冲保留攻击导致拒绝服务(DoS)攻击和资源耗竭的受害者节点。本文建议,6LoWPAN与低功率和损失网络规则(RPL)之间的安全整合是可能的解决方案。由于CSM框架提供了即时速发送者信任,通过使用网络编码(NCNC),以及从缓冲保留攻击过程的整合到其他协议(ODROVI)的整合连接,在启动系统上几乎使用内部安全规则(OLVI)的交付决定的外部评估,从而建立这一信任。