Event Details

alidation and implementation of Secure Mutual Authentication framework and Automated Access Control for IoT Smart Home.

Presenter: Mohammed Alshahrani
Supervisor:

Date: Mon, August 20, 2018
Time: 12:30:00 - 14:30:00
Place: EOW 430

ABSTRACT

Abstract

The Internet of Things (IoT), which simply connects both living and non-living things into one ecosystem, is one of the most recent advanced computing paradigms in the twenty-first century. The IoT adds sense to non-living entities, supports their ability to process information, and makes decisions without any intervention from human or living bodies. IoT devices are often resource-constrained and deployed in unmonitored, physically unsecured environments. However, although there is an urgent need to secure IoT infrastructures, this necessity is confronted with the aforementioned resource limitations of the infrastructure underlying platforms and devices. One of the most essential aspects of securing an IoT infrastructure is about the device identity and the mechanisms to authenticate it.  In this seminar, I will evaluate and formally prove the security of our protocol framework that was discussed in the previous seminar. I will first logically analyse, and discuss how our protocol successfully defends and withstands known attacks such as man-in-the-middle (MIM), eavesdropping, and impersonation attacks, among others. Second, I will discuss and prove that our protocol provides secure mutual authentication using the Burrows–Abadi–Needham (BAN) logic, which is used to prove the correctness of mutual authentication and key establishment. Third, I will show the details and results of the simulation of our protocol using the automated validation of Internet security protocols and applications (AVISPA) toolkit which is widely used to validate and assess the security of network protocols. Finally, I will discuss and elaborate the implementation of our protocol using OMNeT++ framework, and then I will show how our protocol can defend against some attack scenarios that we implemented to test our framework.