HomeShield: A Credential-Less Authentication Framework for Smart Home Systems

21Citations
Citations of this article
41Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Smart home systems have become more and more prevailent in recent years. On the one hand, they make our everyday life more convenient; on the other hand, they suffer from the two notorious security problems, namely, the open-port problem and the overprivilege problem, making their security situations extremely worrying and uncheerful. In this article, we proposed HomeShield, a novel credential-less authentication framework to shield smart home systems by effectively defending against the attacks resulted from these two security problems without the need for sensitive credentials. We further detailed an implementation of HomeShield based on the side channels that are publicly available in Android smartphones serving as controllers of smart home systems and presented its workflow in protecting against various attacks caused by the open-port and overprivilege problems. Finally, we tested our HomeShield implementation on a real-world smart home system and considered four threat models that cover basically all practical attacks, including Mirai and its variants. We also considered the effectiveness of our HomeShield implementation on the SmartApps of the Samsung SmartThings platform, which also suffers from the open-port and overprivilege problems, even though its overprivilege issue has been extensively studied by the recently proposed works, such as ContexIoT and SmartAuth. The evaluation results indicate that our HomeShield realization can successfully defend against over 90% attack trials with an average latency of less than 1 s.

Cite

CITATION STYLE

APA

Xiao, Y., Jia, Y., Liu, C., Alrawais, A., Rekik, M., & Shan, Z. (2020). HomeShield: A Credential-Less Authentication Framework for Smart Home Systems. IEEE Internet of Things Journal, 7(9), 7903–7918. https://doi.org/10.1109/JIOT.2020.3003621

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free