|
ABSTRACT
We introduce TinySec, the first fully-implemented link layer security architecture for wireless sensor networks. In our design, we leverage recent lessons learned from design vulnerabilities in security protocols for other wireless networks such as 802.11b and GSM. Conventional security protocols tend to be conservative in their security guarantees, typically adding 16--32 bytes of overhead. With small memories, weak processors, limited energy, and 30 byte packets, sensor networks cannot afford this luxury. TinySec addresses these extreme resource constraints with careful design; we explore the tradeoffs among different cryptographic primitives and use the inherent sensor network limitations to our advantage when choosing parameters to find a sweet spot for security, packet overhead, and resource requirements. TinySec is portable to a variety of hardware and radio platforms. Our experimental results on a 36 node distributed sensor network application clearly demonstrate that software based link layer protocols are feasible and efficient, adding less than 10% energy, latency, and bandwidth overhead.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
Crossbow technology inc. http://www.xbow.com.
|
| |
2
|
Moteiv. http://www.moteiv.com/.
|
| |
3
|
OpenSSL. http://www.openssl.org.
|
| |
4
|
Security architecture for the Internet Protocol. RFC 2401, November 1998.
|
| |
5
|
Smart buildings admit their faults. Lab Notes: Research from the College of Engineering, UC Berkeley, http://www.coe.berkeley.edu/labnotes/1101smartbuildings.html, November 2001.
|
| |
6
|
Wireless medium access control and physical layer specifications for low-rate wireless personal area networks. IEEE Standard, 802.15.4-2003, May 2003. ISBN 0-7381-3677-5.
|
| |
7
|
Elad Barkan, Eli Biham, and Nathan Keller. Instant ciphertext-only cryptanalysis of GSMencrypted communication. In Advances in Cryptology -- CRYPTO 2003, volume 2729 of Lecture Notes in Computer Science, 2003.
|
| |
8
|
|
| |
9
|
|
| |
10
|
Steven M. Bellovin. Problem areas for the IP security protocols. In Proceedings of the Sixth USENIX Security Symposium, 1996.
|
| |
11
|
Steven M. Bellovin and Matt Blaze. Cryptographic modes of operation for the internet. In Second NIST Workshop on Modes of Operation, August 2001.
|
 |
12
|
|
 |
13
|
|
| |
14
|
|
| |
15
|
E. Dawson and L. Nielsen. Automated cryptanalysis of XOR plaintext strings. Cryptologia, (2):165--181, April 1996.
|
 |
16
|
|
| |
17
|
G.L. Duckworth, D.C. Gilbert, and J.E. Barger. Acoustic counter-sniper system. In SPIE International Symposium on Enabling Technologies for Law Enforcement and Security, 1996.
|
| |
18
|
Bruno Dutertre, Steven Cheung, and Joshua Levy. Lightweight key management in wireless sensor networks by leveraging initial trust. Technical Report SRI-SDL-04-02, SRI International, April 2004.
|
 |
19
|
|
| |
20
|
|
 |
21
|
David Gay , Philip Levis , Robert von Behren , Matt Welsh , Eric Brewer , David Culler, The nesC language: A holistic approach to networked embedded systems, Proceedings of the ACM SIGPLAN 2003 conference on Programming language design and implementation, June 09-11, 2003, San Diego, California, USA
|
| |
22
|
|
 |
23
|
Jason Hill , Robert Szewczyk , Alec Woo , Seth Hollar , David Culler , Kristofer Pister, System architecture directions for networked sensors, Proceedings of the ninth international conference on Architectural support for programming languages and operating systems, p.93-104, November 2000, Cambridge, Massachusetts, United States
|
| |
24
|
Chris Hurley. The worldwide wardrive: The myths, the misconceptions, the truth, the future. In Defcon 11, August 2003.
|
| |
25
|
|
| |
26
|
Chris Karlof, Yaping Li, and Joe Polastre. ARRIVE: Algorithm for robust routing in volatile environments. Technical Report UCB/CSD-03-1233, University of California at Berkeley, May 2002.
|
| |
27
|
|
 |
28
|
|
 |
29
|
|
| |
30
|
|
 |
31
|
Alan Mainwaring , David Culler , Joseph Polastre , Robert Szewczyk , John Anderson, Wireless sensor networks for habitat monitoring, Proceedings of the 1st ACM international workshop on Wireless sensor networks and applications, September 28-28, 2002, Atlanta, Georgia, USA
[doi> 10.1145/570738.570751]
|
| |
32
|
David Malan, Matt Welsh, and Michael D. Smith. A public-key infrastructure for key distribution in TinyOS based on elliptic curve cryptography. In First IEEE International Conference on Sensor and Ad Hoc Communications and Networks, October 2004.
|
 |
33
|
Adrian Perrig , Robert Szewczyk , Victor Wen , David Culler , J. D. Tygar, SPINS: security protocols for sensor netowrks, Proceedings of the 7th annual international conference on Mobile computing and networking, p.189-199, July 2001, Rome, Italy
[doi> 10.1145/381677.381696]
|
 |
34
|
|
| |
35
|
Bruce Schneier. Applied Cryptography, Second Edition. John Wiley & Sons, 1996.
|
| |
36
|
Peter Shipley. Open WLANs: the early results of wardriving, 2001.
|
| |
37
|
Peter Shipley, 2003. personal communication.
|
| |
38
|
Adam Stubblefield, John Ioannidis, and Aviel D. Rubin. Using the fluhrer, mantin, and shamir attack to break WEP. In Network and Distributed Systems Security Symposium (NDSS), 2002.
|
| |
39
|
Robert Szewczyk, Joseph Polastre, Alan Mainwaring, and David Culler. Lessons from a sensor network expedition. In First European Workshop on Wireless Sensor Networks (EWSN '04), January 2004.
|
 |
40
|
|
 |
41
|
Ramnath Venugopalan , Prasanth Ganesan , Pushkin Peddabachagari , Alexander Dean , Frank Mueller , Mihail Sichitiu, Encryption overhead in embedded systems and sensor network nodes: modeling and analysis, Proceedings of the 2003 international conference on Compilers, architecture and synthesis for embedded systems, October 30-November 01, 2003, San Jose, California, USA
[doi> 10.1145/951710.951737]
|
| |
42
|
Jessie Walker. Unsafe at any key size; an analysis of the WEP encapsulation. http://grouper.ieee.org/groups/802/11/Documents/DocumentHolder/0-362.zip.
|
| |
43
|
Ron Watro, Derrick Kong, Sue fen Cuti, Jen Mulligan, Charlie Gardiner, and Dan Coffin. TinyPK. http://www.is.bbn.com/projects/lws-nest/.
|
| |
44
|
Matt Welsh, Dan Myung, Mark Gaynor, and Steve Moulton. Resuscitation monitoring with a wireless sensor network. Supplement to Circulation: Journal of the American Heart Association, October 2003.
|
| |
45
|
WiGLE. Wireless geographic logging engine---general stats, December 2003.
|
| |
46
|
Qi Xue and Aura Ganz. Runtime security composition for sensor networks (SecureSense). In IEEE Vehicular Technology Conference (VTC Fall 2003), October 2003.
|
| |
47
|
T. Ylonen. SSH - secure login connections over the Internet. In Proceedings of the Sixth USENIX Security Symposium, 1996.
|
CITED BY 90
|
|
|
|
|
|
|
|
Ronald Watro , Derrick Kong , Sue-fen Cuti , Charles Gardiner , Charles Lynn , Peter Kruus, TinyPK: securing sensor networks with public key technology, Proceedings of the 2nd ACM workshop on Security of ad hoc and sensor networks, October 25-25, 2004, Washington DC, USA
|
|
|
|
|
|
|
|
|
|
|
|
Arno Wacker , Mirko Knoll , Timo Heiber , Kurt Rothermel, A new approach for establishing pairwise keys for securing wireless sensor networks, Proceedings of the 3rd international conference on Embedded networked sensor systems, November 02-04, 2005, San Diego, California, USA
|
|
|
Yee Wei Law , Lodewijk van Hoesel , Jeroen Doumen , Pieter Hartel , Paul Havinga, Energy-efficient link-layer jamming attacks against wireless sensor network MAC protocols, Proceedings of the 3rd ACM workshop on Security of ad hoc and sensor networks, November 07-07, 2005, Alexandria, VA, USA
|
|
|
|
|
|
Hamdy S. Soliman , Mohammed Omari, Application of synchronous dynamic encryption system (SDES) in wireless sensor networks, Proceedings of the 2nd ACM international workshop on Performance evaluation of wireless ad hoc, sensor, and ubiquitous networks, October 10-13, 2005, Montreal, Quebec, Canada
|
|
|
|
|
|
Ana Paula R. da Silva , Marcelo H. T. Martins , Bruno P. S. Rocha , Antonio A. F. Loureiro , Linnyer B. Ruiz , Hao Chi Wong, Decentralized intrusion detection in wireless sensor networks, Proceedings of the 1st ACM international workshop on Quality of service & security in wireless and mobile networks, October 13-13, 2005, Montreal, Quebec, Canada
|
|
|
|
|
|
|
|
|
|
|
|
Raghu K. Ganti , Praveen Jayachandran , Tarek F. Abdelzaher , John A. Stankovic, SATIRE: a software architecture for smart AtTIRE, Proceedings of the 4th international conference on Mobile systems, applications and services, June 19-22, 2006, Uppsala, Sweden
|
|
|
Anthony D. Wood , Lei Fang , John A. Stankovic , Tian He, SIGF: a family of configurable, secure routing protocols for wireless sensor networks, Proceedings of the fourth ACM workshop on Security of ad hoc and sensor networks, October 30-30, 2006, Alexandria, Virginia, USA
|
|
|
|
|
|
|
|
|
Eric Sabbah , Adnan Majeed , Kyoung-Don Kang , Ke Liu , Nael Abu-Ghazaleh, An application-driven perspective on wireless sensor network security, Proceedings of the 2nd ACM international workshop on Quality of service & security for wireless and mobile networks, October 02-02, 2006, Terromolinos, Spain
|
|
|
Muneeb Ali , Umar Saif , Adam Dunkels , Thiemo Voigt , Kay Römer , Koen Langendoen , Joseph Polastre , Zartash Afzal Uzmi, Medium access control issues in sensor networks, ACM SIGCOMM Computer Communication Review, v.36 n.2, April 2006
|
|
|
Prabal K. Dutta , Jonathan W. Hui , David C. Chu , David E. Culler, Securing the deluge Network programming system, Proceedings of the fifth international conference on Information processing in sensor networks, April 19-21, 2006, Nashville, Tennessee, USA
|
|
|
Patrick Traynor , Raju Kumar , Hussain Bin Saad , Guohong Cao , Thomas La Porta, LIGER: implementing efficient hybrid security mechanisms for heterogeneous sensor networks, Proceedings of the 4th international conference on Mobile systems, applications and services, June 19-22, 2006, Uppsala, Sweden
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Paolo Baronti , Prashant Pillai , Vince W. C. Chook , Stefano Chessa , Alberto Gotta , Y. Fun Hu, Wireless sensor networks: A survey on the state of the art and the 802.15.4 and ZigBee standards, Computer Communications, v.30 n.7, p.1655-1695, May, 2007
|
|
|
|
|
|
|
|
|
Andrew T. Campbell , Shane B. Eisenman , Nicholas D. Lane , Emiliano Miluzzo , Ronald A. Peterson, People-centric urban sensing, Proceedings of the 2nd annual international workshop on Wireless internet, p.18-es, August 02-05, 2006, Boston, Massachusetts
|
|
|
Mark Luk , Ghita Mezzour , Adrian Perrig , Virgil Gligor, MiniSec: a secure sensor network communication architecture, Proceedings of the 6th international conference on Information processing in sensor networks, April 25-27, 2007, Cambridge, Massachusetts, USA
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Yee Wei Law , Marimuthu Palaniswami , Lodewijk Van Hoesel , Jeroen Doumen , Pieter Hartel , Paul Havinga, Energy-efficient link-layer jamming attacks against wireless sensor network MAC protocols, ACM Transactions on Sensor Networks (TOSN), v.5 n.1, p.1-38, February 2009
|
|
|
|
|
|
|
|
|
Dennis K. Nilsson , Tanya Roosta , Ulf Lindqvist , Alfonso Valdes, Key management and secure software updates in wireless process control environments, Proceedings of the first ACM conference on Wireless network security, March 31-April 02, 2008, Alexandria, VA, USA
|
|
|
Hailun Tan , Sanjay Jha , Diet Ostry , John Zic , Vijay Sivaraman, Secure multi-hop network programming with multiple one-way key chains, Proceedings of the first ACM conference on Wireless network security, March 31-April 02, 2008, Alexandria, VA, USA
|
|
|
Yang Xiao , Venkata Krishna Rayi , Bo Sun , Xiaojiang Du , Fei Hu , Michael Galloway, A survey of key management schemes in wireless sensor networks, Computer Communications, v.30 n.11-12, p.2314-2341, September, 2007
|
|
|
S. B. Eisenman , E. Miluzzo , N. D. Lane , R. A. Peterson , G-S. Ahn , A. T. Campbell, The BikeNet mobile sensing system for cyclist experience mapping, Proceedings of the 5th international conference on Embedded networked sensor systems, November 06-09, 2007, Sydney, Australia
|
|
|
Chiu C. Tan , Haodong Wang , Sheng Zhong , Qun Li, Body sensor network security: an identity-based cryptography approach, Proceedings of the first ACM conference on Wireless network security, March 31-April 02, 2008, Alexandria, VA, USA
|
|
|
|
|
|
|
|
|
Leonardo B. Oliveira , Adrian Ferreira , Marco A. Vilaça , Hao Chi Wong , Marshall Bern , Ricardo Dahab , Antonio A. F. Loureiro, SecLEACH-On the security of clustered sensor networks, Signal Processing, v.87 n.12, p.2882-2895, December, 2007
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Tammara Massey , Philip Brisk , Foad Dabiri , Majid Sarrafzadeh, Delay aware, reconfigurable security for embedded systems, Proceedings of the ICST 2nd international conference on Body area networks, p.1-5, June 11-13, 2007, Florence, Italy
|
|
|
|
|
|
Bo Sun , Yang Xiao , Chung Chih Li , Hsiao-Hwa Chen , T. Andrew Yang, Security co-existence of wireless sensor networks and RFID for pervasive computing, Computer Communications, v.31 n.18, p.4294-4303, December, 2008
|
|
|
|
|
|
Idris M. Atakli , Hongbing Hu , Yu Chen , Wei Shinn Ku , Zhou Su, Malicious node detection in wireless sensor networks using weighted trust evaluation, Proceedings of the 2008 Spring simulation multiconference, April 14-17, 2008, Ottawa, Canada
|
|
|
Kun Sun , An Liu , Roger Xu , Peng Ning , Douglas Maughan, Securing network access in wireless sensor networks, Proceedings of the second ACM conference on Wireless network security, March 16-19, 2009, Zurich, Switzerland
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|