Volume 9 - Issue 4
Device Identification and Personal Data Attestation in Networks
- Clementine Gritti
NTNU, Norway
clementine.gritti@ntnu.no
- Melek Onen
Eurecom, France
melek.onen@eurecom.fr
- Refik Molva
Eurecom, France
refik.molva@eurecom.fr
- Willy Susilo
University of Wollongong, Australia
wsusilo@uow.edu.au
- Thomas Plantard
University of Wollongong, Australia
thomaspl@uow.edu.au
Keywords: Internet of Things, Identity-Based Cryptography, Aggregate Signature
Abstract
A powerful world connecting digital and physical environments is promised through the Internet
of Things (IoT). However, because of the heterogeneous nature of devices and of the diversity of
their provenance, security and privacy vulnerabilities threaten IoT-based implementations. Moreover,
constrained resources from devices bring technical challenges, compelling protocols to be as
lightweight Similarly to Gritti et al.’s approach, a secure bootstrap is first processed to enable a reliable
authentication of devices in a local network, and then, a message attestation phase is executed to
allow authentication of personal messages of devices. While devices are limited to pre-determined
common messages in Gritti et al.’s solution, they can authenticate their own personal messages in
our paper. We ensure that our solution is suitable in IoT settings by proving it secure and privacypreserving
as well as satisfying operational requirements. In addition, we provide benchmarking
results on both the scheme from Gritti et al.’s scheme and our scheme.