scieee AI-readable full text Open interactive document viewer

Multi-Device Authentication using Wearables and IoT

Hajný, Jan; Dzurenda, Petr; Malina, Lukáš

Abstract

The paper presents a novel cryptographic authentication scheme that makes use of the presence of electronic devices around users. The scheme makes authentication more secure by involving devices that are usually worn by users (such as smart-watches, fitness bracelets and smart-cards) or are in their proximity (such as sensors, home appliances, etc.). In our scheme, the user private key is distributed over all personal devices thus cannot be compromised by breaking into only a single device. Furthermore, involving wearables and IoT devices makes it possible to use multiple authentication factors, such as user's position, his behavior and the state of the surrounding environment. We provide the full cryptographic specification of the protocol, its formal security analysis and the implementation results in this paper.

Full text

Multi-device Authentication using Wearables and IoT Jan Hajny, Petr Dzurenda and Lukas Malina Brno University of Technology, Technicka 12, Brno, Czech Republic Keywords: Authentication, Cryptography, Constrained Devices, Wearables, Internet of Things. Abstract: The paper presents a novel cryptographic authentication scheme that makes use of the presence of electronic devices around users. The scheme makes authentication more secure by involving devices that are usually worn by users (such as smart-watches, fitness bracelets and smart-cards) or are in their proximity (such as sensors, home appliances, etc.). In our scheme, the user private key is distributed over all personal devices thus cannot be compromised by breaking into only a single device. Furthermore, involving wearables and IoT devices makes it possible to use multiple authentication factors, such as user’s position, his behavior and the state of the surrounding environment. We provide the full cryptographic specification of the protocol, its formal security analysis and the implementation results in this paper. 1 INTRODUCTION In modern society, people are surrounded by a huge amount of so-called smart devices, such as smartphones, tablets, smart-cards, smart-watches, etc. Furthermore, the amount of various sensors, smartmeters and smart-home appliances increases significantly. The current trend is to interconnect all these devices into a single network, called the Internet of Things (IoT). Although the aforementioned devices have only small computational and memory resources, they are programmable and can communicate with one another. Despite there are so many electronic devices around us, we usually use only a single device to access electronic services, either a PC, a tablet or a smart-phone. However, if such a device gets compromised by attackers, the security is gone and attackers can access user’s assets. For example, if user’s smart-phone gets stolen and the password for electronic banking is revealed (or stored in memory), the attacker might get access to the user’s account. We resolve this weakness by involving multiple personal devices in the authentication process. These devices can provide additional authentication data. For example, if a user owns a smart-watch, it would be natural to check its presence during the authentication. Or, it would be useful to check the presence of a wireless home router in some applications where we want to allow the access only from users from a home location. For very sensitive applications, it would make sense to check for multiple factors, such as the password knowledge, the presence of a smartcard and the presence of a Bluetooth Low Energy (BLE) beacon device that certifies position. In this paper, we provide the description of a cryptographic protocol that allows such an involvement of many constrained devices in the authentication process. We propose a provably secure protocol that distributes the user’s private key among multiple devices. To get authenticated, the user must prove the knowledge of all parts of his private key that corresponds to his personal public key. Our protocol is provably secure and easily implementable on all programmable constrained devices, such as smart-cards, smart-watches, sensors and wearables in general. 1.1 Related Work and Contribution The design of cryptographic protocols for user authentication is the topic of countless scientific papers, starting with the proposals of traditional authentication protocols (Neuman and Ts’ O, 1994; Lashkari et al., 2009), provably secure authentication protocols based on zero-knowledge proofs (Schnorr, 1991; Guillou and Quisquater, 1988), to privacy-enhanced authentication protocols (Camenisch and et Al., 2012; Paquin, 2011) and light-weight protocols (Chien and Huang, 2007). Since personal and wearable smart devices have started to appear only very recently, Hajny, J., Dzurenda, P. and Malina, L. Multi-Device Authentication using Wearables and IoT. DOI: 10.5220/0006000004830488 In Proceedings of the 13th International Joint Conference on e-Business and Telecommunications (ICETE 2016) - Volume 4: SECRYPT, pages 483-488 ISBN: 978-989-758-196-0 Copyright c 2016 by SCITEPRESS – Science and Technology Publications, Lda. All rights reserved 483 not many papers focusing on using the combination of many devices, i.e. the multi-device authentication, exist. Xu (Xu, 2015) focuses on biometric authentication using wearables, namely on face recognition using smart-glass and gait recognition using smart-watch. Cha et al. (Cha et al., 2015) present a simple model for two device authentication for micro-payment systems using a mobile and wearable devices. Nevertheless, their approach lacks more details and concrete cryptographic functions. To some extent, the concepts of continuous authentication (Shepherd, 1995) and progressive authentication (Riva et al., 2012) are close to our approach as they are also based on combining multiple sources of authentication data. However, the schemes are using mainly biometric authentication factors. The most related work from 2015 (Gonzalez-Manzano et al., 2015) presents an access control mechanism for cloud-based storage service access by using a set of devices. However, their scheme is based on symmetric cryptography, thus does not provide nonrepudiation. Furthermore, there is no formal security analysis provided in the paper. Based on the current state analysis, to our best knowledge, we present the first cryptographic scheme that 1) allows strong multi-device authentication, 2) is provably secure, 3) provides non-repudiation and allows private keys to never leave the user device, 4) is easily implementable on personal and wearable devices and 5) allows simple registration and deregistration of personal devices. Using this authentication scheme, the practical access control mechanisms can get much more secure without any negative influence on usability and user friendliness. 1.2 Paper Outline We provide the preliminaries in Sec. 2, the security model and description of protocols in Sec. 3, the security proof in Sec. 4 and the implementation results in Sec. 5. 2 PRELIMINARIES 2.1 Notation We describe Proof of Knowledge protocols (PK) using the efficient notation introduced by Camenisch and Stadler (Camenisch and Stadler, 1997a). The protocol for proving the knowledge of a discrete logarithm of an element cwith respect to a generator gis denoted as PK{α:c=gα}. The symbol “:” means “such that”, “|” means “divides”, “|x|” is the bitlength of xand “x∈R{0,1}l” is a randomly chosen bitstring of maximum length l. 2.2 Used Primitives Our scheme is based on Schnorr’s identification scheme (Schnorr, 1991). That, in turn, makes use of the protocols for the interactive proof of knowledge of a discrete logarithm (Camenisch and Stadler, 1997b). Using the cryptographic proofs of knowledge, it is possible to prove the knowledge of a private value of a discrete logarithm wwith respect to public values c,g,psuch that c≡gw(mod p)holds in modular multiplicative group Z∗ pwhere pis a large prime and gis a group generator. The protocol can be denoted as PK{w:c=gw}. We use the modification of this protocol called the proof of representation, denoted as PK{w0,w1,...,wi:c=gw0 0gw1 1. . . gwi i}. Furthermore, we use a signature scheme that can be obtained by hashing the protocol challenge ewith the message using the Fiat-Shamir heuristics (Fiat and Shamir, 1987). The signature on message mis then denoted as SPK{w0,w1,...,wi:c=gw0 0gw1 1. . . gwi i}(m). 3 MULTI-DEVICE AUTHENTICATION In multi-device authentication, there are three types of entities (or roles) in the system: •Verifiers: usually service providers that need to verify the identity of their users. •Users: customers that are represented by their master devices (PCs, laptops, smart-phones, tablets, . . . ). Users need to prove their identity. •Devices: constrained personal devices (smartcards, smart-watches, sensors, RFID tags, . . . ), that are involved in the authentication process to strengthen security. These entities engage in the following protocols: •(spar,(sk0,...,ski),pkU)←Setup(k,d)protocol: the protocol is run by a Verifier and a User to generate and share initial parameters. It inputs the security parameter k, the maximum of user devices dand outputs the system parameters spar and User’s initial keypair (sk0,...,ski),pkU. •(Accept/Reject)←Authenticate(spar,(sk0,..., ski),pkU)protocol: the protocol is run jointly by a User, his devices and a Verifier to prove the knowledge of User’s private keys. It inputs the system parameters spar, the User’s public key pkU, all corresponding private keys (sk0,...,ski) SECRYPT 2016 - International Conference on Security and Cryptography 484 and outputs Accept if the proof is valid and Reject otherwise. •(pkU)←Register(spar,(sk0,...,ski),pkU,ski+1) protocol: the protocol is run jointly by a User, his devices and a Verifier to register a new device in the system. It inputs the system parameters spar, new (i+1)’th device’s private key ski+1, the User’s keypair (sk0,...,ski),pkUand outputs an updated User’s public key pkUthat corresponds to ski+1and all previous private keys of the user. •(pkU)←Deregister(spar,(sk0,...,ski),pkU, ski+1)protocol: the protocol is run jointly by a User and the Verifier to deregister the public key of his device, in case the device needs to be revoked (due to loss, damage, theft, etc.). It inputs the system parameters spar, existing (i+1)’th device’s private key ski+1, the User’s keypair (sk0,...,ski),pkUand outputs an updated User’s public key pkUthat corresponds to all previous private keys of the user except ski+1. In classical authentication, the Authenticate protocol only proves User’s knowledge of a password and keys stored in his master device to a Verifier. In multi-device authentication, each device has its private cryptographic key that corresponds to a general public key stored by a Verifier. The Authenticate protocol proves the knowledge of all private keys to a Verifier without revealing them. Thus, authentication is successful only if the whole group of preselected devices participate in the protocol. However, this group can be changed jointly by Users and Verifiers, using the Register and Deregister protocols. 3.1 Security Model We use and prove properties for authentication protocol completeness, soundness and zero-knowledge (Quisquater et al., 1989). The completeness property states that honest Users are almost always accepted by Verifiers, the soundness property states that dishonest Users are almost always rejected by Verifiers and the zero-knowledge property states that the protocol leaks no information about Users’ private keys, using the simulation paradigm (i.e., all the public protocol values can be efficiently generated without the knowledge of private keys). Definition 1. Authentication completeness. An honest Verifier rejects an honest User (i.e., the one using private keys that correspond to the public key) with probability negligible in the length of the security parameter k. Definition 2. Authentication soundness. An honest Verifier accepts a dishonest User (i.e., the one using private keys that do not correspond to the public key) with probability negligible in the length of the security parameter k. Definition 3. Authentication zero-knowledge. There exist a simulator Sthat is able to efficiently generate a protocol transcript indistinguishable from a real protocol transcript without the knowledge of private keys. 3.2 Scheme Instantiation In this section, we provide the concrete instantiation of the protocols used in our scheme. All operations are computed in Z∗ p. 3.2.1 Setup Protocol On the input of the security parameter kand device number parameter d, a Verifier randomly selects a group G=hgiof prime order q:|q|=kwhere DL assumption holds, chooses d+1 random elements (α0,α1,...,αd)∈RZq, computes gl=gαlfor all 0 ≤ l≤dand outputs (G,(g0,...,gd)) as public system parameters spar to all Users and devices over a secure channel1. A User selects his private key at random, i.e., computes sk0∈RZqand computes his public key as pk0=gsk0 0. If some additional device is already present, it also generates its private key, i.e. computes sk1∈RZq, and computes its public key as pk1=gsk1 1. The same applies if more devices are present. We note that the device private key never leaves the device, only the public key is revealed. Finally, the User (represented by his master user device) computes the user public key as pkU=∏l i=0pkifor all lavailable devices and distributes this public key to the Verifier over a secure channel. 3.2.2 Authenticate Protocol In the Authenticate protocol, the User must prove that he knows all private keys sko,...,skithat were used to construct the public key pkU. This can be realized by the proof of discrete logarithm representation, a protocol denoted as PK{(sk0,...,ski):pkU= gsk0 0. . . gski i}. Since the User’s master device does not know the private keys, except sk0, the proving protocol must be distributed among all devices, as depicted in Fig. 1 in CS notation and in Fig. 2 in full notation. 3.2.3 Register Protocol The Register protocol is used when a new device needs to be added to the set of user devices. In that 1These values can be pre-shared in software. Multi-Device Authentication using Wearables and IoT 485 Master Device Verifier PK{(sk0,...,ski):pkU=gsk0 0. . . gski i} ←−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−− PK{(sk0):pk0=gsk0 0} Device 1 PK{(sk1):pk1=gsk1 1} ←−−−−−−−−−−−−−−−−−−−−−−−→ . . Device i PK{(ski):pki=gski i} ←−−−−−−−−−−−−−−−−−−−−−−→ PK{(sk0,...,ski):pkU=gsk0 0. . . gski i} −−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−→ Verify PK Accept/Reject ←−−−−−−−−−−−−−−−−−−−−−−−−−− Figure 1: Authenticate protocol in CS notation. Device 1 Master Device Verifier sk1sk0pkU r1∈RZq ¯c1=gr1 1mod p ¯c1 −−−−−−−−−−−−−−−−−−−−−→ r0∈RZq ¯c=¯c1gr0 0mod p ¯c −−−−−−−−−−−−−−−−−−−−→ e∈RZq e ←−−−−−−−−−−−−−−−−−−−− z0=r0−esk0 e ←−−−−−−−−−−−−−−−−−−−− z1=r1−esk1 z1 −−−−−−−−−−−−−−−−−−−−−→ z0,z1 −−−−−−−−−−−−−−−−−−−−→ ¯c? =pke Ugz0 0gz1 1 Accept/Reject ←−−−−−−−−−−−−−−−−− Figure 2: Authenticate protocol for 1 master device and 1 additional device in full notation. case, the new device generates its private key, i.e., computes ski+1∈RZq, and computes its public key as pki+1=gski+1 i+1. The new public key must be delivered to the master device using a secure channel. Then, the master device may authenticate itself to the Verifier (using the Authenticate protocol) and provide the new public key pki+1. The Verifier then updates the main User’s public key pkU=pkU∗pki+1. After this update, the new (i+1)’th device must be always used in the Authentication protocol. The Register protocol is depicted in Fig. 3. 3.2.4 Deregister Protocol In case some of devices gets lost, stolen or stops working, a User can use the Deregister protocol to remove it from the set of registered devices. The User first sends the public key of the invalid device, e.g. pki+1, to the Verifier. The Verifier temporarily Device i+1 Master Device Verifier ski+1∈RZq pki+1=gski+1 i+1pki+1 −−−−−−−−−−−−→ SPK{(sk0,...,ski):pkU=gsk0 0. . . gski i}(pki+1) ←−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−→ Verify SPK Accept/Reject ←−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−− pkU=pkU∗pki+1pkU=pkU∗pki+1 Figure 3: Register protocol. Master Device Verifier pki+1 −−−−−−−−−−−−−−−−−−−−−−−−−−−−−→ Check that pki+1is a valid key. pktemp =pkU∗pk−1 i+1 SPK{(sk0,...,ski):pktemp =gsk0 0. . . gski i}(pki+1) ←−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−− SPK{(sk0):pk0=gsk0 0}(pki+1) Device 1 SPK{(sk1):pk1=gsk1 1}(pki+1) ←−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−→ . . Device i SPK{(ski):pki=gski i}(pki+1) ←−−−−−−−−−−−−−−−−−−−−−−−−−−−−−→ SPK{(sk0,...,ski):pktemp =gsk0 0. . . gski i}(pki+1) −−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−→ Verify SPK pkU=pktemp Accept/Reject ←−−−−−−−−−−−−−−−−−−−−−−−−−− pkU=pktemp Figure 4: Deregister protocol. removes the device and computes the temporal public key pktemp =pkU∗pk−1 i+1. Then, the Verifier asks the User to authenticate with respect to the pktemp. If the User is able to successfully finish the authentication protocol, the Verifier sets the temporal public key as permanent, i.e. sets pkU=pktemp. The protocol is depicted in Fig. 4. 4 SECURITY PROOF We prove the completeness, soundness and zeroknowledge in this section. Theorem 1. Authentication protocol is complete as defined in Def. 1. Proof. We prove the authentication protocol’s completeness using the verification equation used in the authentication protocol depicted in Fig. 2. SECRYPT 2016 - International Conference on Security and Cryptography 486 Table 1: Performance results for 1280 bit keys (|p|=1280,|q|=160). Type Product ModExp RNG ModMul Sub Total [ms] Smart-watch Sony SmartWatch 3 SWR50 2.3 1.4 <0.1<0.01 3.7 Smart-phone Nexus 5 LG 1.9 7.4 <0.1<0.01 9.3 Micro-computer Raspberry Pi 1 model B 59.3 0.8 <0.6<0.160.1 Smart-card MULTOS ML4-P17 227 49 188 48 512 Smart-card MULTOS ML3-80KR1 403 45 195 44 687 Smart-card MULTOS MC4-P16 333 68 255 56 712 Smart-card SmartCafe 4.x 356 47 1159 79 1641 Smart-card SmartCafe 3.2 59 31 1737 94 1921 Smart-card J3A081 75 31 2510 179 2795 Secure element CertGate microSD 78 34 2694 168 2974 Table 2: Performance results for 2048 bit keys (|p|=2048,|q|=256). Type Product ModExp RNG ModMul Sub Total [ms] Smart-watch Sony SmartWatch 3 SWR50 7.5 2 <0.1<0.01 9.5 Smart-phone Nexus 5 LG 5.2 9.2 <0.1<0.01 14.4 Micro-computer Raspberry Pi 1 model B 216.2 1.2 <0.7<0.1217.4 Smart-card MULTOS ML4-P17 346 62 190 48 646 Smart-card MULTOS ML3-80KR1 530 56 194 44 824 Smart-card MULTOS MC4-P16 484 84 256 56 880 Smart-card SmartCafe 4.x 617 47 1536 79 2279 Smart-card SmartCafe 3.2 188 31 2532 94 2845 Smart-card J3A081 258 47 3962 179 4446 Secure element CertGate microSD 263 48 4153 168 4632 ¯c=pke Ugz0 0gz1 1= (gsk0 0gsk1 1)egr0−esk0 0gr1−esk1 1=gr0 0gr1 1=¯c Theorem 2. Authentication protocol is sound as defined in Def. 2. Proof. Suppose that a user does not know the private keys and is ready to correctly respond to at least two Verifier’s challenges (denoted as e,e0) by sending (z0,z1)and (z0 0,z0 1). Then, the following equations must hold for the User to be accepted. ¯c=pke Ugz0 0gz1 1 ¯c=pke0 Ugz0 0 0gz0 1 1 By dividing we get: 1=pke−e0 Ugz0−z0 0 0gz1−z0 1 1 And finally we get: pkU=g z0−z0 0 e0−e 0g z1−z0 1 e0−e 1 And we reached the contradiction because the user knows the private keys sk0=z0−z0 0 e0−eand sk1=z1−z0 1 e0−e. Theorem 3. Authentication protocol is zeroknowledge as defined in Def. 3. Proof. We prove the zero-knowledge property by constructing the zero-knowledge simulator S. The simulator works in the following steps. 1. Randomly selects the responses ˆz0,ˆz1∈RZq. 2. Randomly selects the challenge ˆe∈RZq. 3. Computes the commitment ˆ ¯c=pkˆe Ugˆz0 0gˆz1 1. The simulator’s output is computationally indistinguishable from the real protocol transcript, i.e. (ˆ ¯c,ˆe,(ˆz0,ˆz1)) ∼ =c(¯c,e,(z0,z1)), because all pairs are selected randomly and uniformly from the same sets. 5 IMPLEMENTATION ASPECTS In this section, we prove that our scheme is efficient and easy to implement even on constrained devices. We implemented all required operations of the authentication protocol2on a set of devices that have very limited resources. We used devices that can be expected around modern users, namely a smart-watch, smart-cards, a smart-phone, a secure element with tamper-resistant hardware and a microcomputer. The results for individual operations and 2ModExp - modular exponentiation, RNG - random number generation, ModMul - modular multiplication and Sub - subtraction. Multi-Device Authentication using Wearables and IoT 487 the total time of the authentication protocol are shown in Tab. 1 for 1280-bit keysize and in Tab. 2 for 2048bit keysize. Based on the implementation results, we state that the authentication protocol can be easily implemented on smart-phones and smart-watches with running times around 10 ms, on micro-computers with running times under 100 ms for the standard variant and around 200 ms for the more secure variant. The protocol can be also implemented on programmable smart-cards using the Multos smart-card platform with running times under 1 s for all variants. The worst results were obtained using a microSD secure element, a device that is used for storing sensitive cryptographic information on mobile phones. Using this device, the authentication protocol would take around 3 seconds. 6 CONCLUSION In this paper, we proposed a novel multi-device authentication scheme. By using the inputs from personal and wearable devices, the authentication process gets more secure and reliable as it is possible to verify not only user’s knowledge of a password, but the presence of his wearables, tags and smart-devices at his location. The scheme does not require any additional actions from a user, allows easy registration of new personal devices and deregistration of invalid devices. The full security analysis is provided and implementation aspects are described in this paper. As the next step, we focus on adding privacy-enhancing features to this scheme. ACKNOWLEDGMENT Research was sponsored by the Czech Science Foundation project nr. 14-25298P Research into cryptographic primitives for secure authentication and digital identity protection”, the Technology Agency of the Czech Republic project TA04010476 ”Secure Systems for Electronic Services User Verification” and the National Sustainability Program LO1401. For the research, infrastructure of the SIX Center was used. REFERENCES Camenisch, J. and et Al. (2012). Specification of the identity mixer cryptographic library. Technical report, IBM Research - Zurich. Camenisch, J. and Stadler, M. (1997a). Efficient group signature schemes for large groups. In Advances in Cryptology - CRYPTO ’97, volume 1294 of LNCS, pages 410–424. Springer Berlin / Heidelberg. Camenisch, J. and Stadler, M. (1997b). Proof systems for general statements about discrete logarithms. Technical report, IBM. Cha, B.-R., Lee, S.-H., Park, S.-B., and Ji, G.-K. L. Y.-K. (2015). Design of micro-payment to strengthen security by 2 factor authentication with mobile & wearable devices. Chien, H.-Y. and Huang, C.-W. (2007). Security of ultralightweight rfid authentication protocols and its improvements. SIGOPS Oper. Syst. Rev., 41(4):83–86. Fiat, A. and Shamir, A. (1987). How to prove yourself: Practical solutions to identification and signature problems. In Advances in Cryptology - CRYPTO 86, volume 263 of LNCS, pages 186–194. Springer Berlin / Heidelberg. Gonzalez-Manzano, L., de Fuentes, J., and Orfila, A. (2015). Access control for the cloud based on multidevice authentication. In Trustcom/BigDataSE/ISPA, 2015 IEEE, volume 1, pages 856–863. IEEE. Guillou, L. C. and Quisquater, J.-J. (1988). EUROCRYPT ’88: Workshop on the Theory and Application of Cryptographic Techniques, chapter A Practical Zero-Knowledge Protocol Fitted to Security Microprocessor Minimizing Both Transmission and Memory, pages 123–128. Springer Berlin Heidelberg, Berlin, Heidelberg. Lashkari, A. H., Danesh, M. M. S., and Samadi, B. (2009). A survey on wireless security protocols (wep, wpa and wpa2/802.11 i). In Computer Science and Information Technology, 2009. ICCSIT 2009. 2nd IEEE International Conference on, pages 48–52. IEEE. Neuman, B. C. and Ts’ O, T. (1994). Kerberos: An authentication service for computer networks. Communications Magazine, IEEE, 32(9):33–38. Paquin, C. (2011). U-prove cryptographic specification v1.1. Technical report, Microsoft Corporation. Quisquater, J.-J., Guillou, L., Annick, M., and Berson, T. (1989). How to explain zero-knowledge protocols to your children. In Proceedings on Advances in cryptology, CRYPTO ’89, pages 628–631, New York, NY, USA. Springer-Verlag New York, Inc. Riva, O., Qin, C., Strauss, K., and Lymberopoulos, D. (2012). Progressive authentication: Deciding when to authenticate on mobile phones. In Presented as part of the 21st USENIX Security Symposium (USENIX Security 12), pages 301–316, Bellevue, WA. USENIX. Schnorr, C. P. (1991). Efficient signature generation by smart cards. Journal of Cryptology, 4:161–174. Shepherd, S. J. (1995). Continuous authentication by analysis of keyboard typing characteristics. In Security and Detection, pages 111–114. Xu, W. (2015). Mobile applications based on smart wearable devices. In Proceedings of the 13th ACM Conference on Embedded Networked Sensor Systems, pages 505–506. ACM. SECRYPT 2016 - International Conference on Security and Cryptography 488