Detail publikačního výsledku

Testbed for LoRaWAN Security: Design and Validation through Man-in-the-Middle Attacks Study

POSPÍŠIL, O.; FUJDIAK, R.; MIKHAYLOV, K.; RUOTSALAINEN, H.; MIŠUREC, J.

Originální název

Testbed for LoRaWAN Security: Design and Validation through Man-in-the-Middle Attacks Study

Anglický název

Testbed for LoRaWAN Security: Design and Validation through Man-in-the-Middle Attacks Study

Druh

Článek WoS

Originální abstrakt

The low-power wide-area (LPWA) technologies, which enable cost and energy-efficient wireless connectivity for massive deployments of autonomous machines, have enabled and boosted the development of many new Internet of things (IoT) applications; however, the security of LPWA technologies in general, and specifically those operating in the license-free frequency bands, have received somewhat limited attention so far. This paper focuses specifically on the security and privacy aspects of one of the most popular license-free-band LPWA technologies, which is named LoRaWAN. The paper's key contributions are the details of the design and experimental validation of a security-focused testbed, based on the combination of software-defined radio (SDR) and GNU Radio software with a standalone LoRaWAN transceiver. By implementing the two practical man-in-the-middle attacks (i.e., the replay and bit-flipping attacks through intercepting the over-the-air activation procedure by an external to the network attacker device), we demonstrate that the developed testbed enables practical experiments for on-air security in real-life conditions. This makes the designed testbed perspective for validating the novel security solutions and approaches and draws attention to some of the relevant security challenges extant in LoRaWAN.

Anglický abstrakt

The low-power wide-area (LPWA) technologies, which enable cost and energy-efficient wireless connectivity for massive deployments of autonomous machines, have enabled and boosted the development of many new Internet of things (IoT) applications; however, the security of LPWA technologies in general, and specifically those operating in the license-free frequency bands, have received somewhat limited attention so far. This paper focuses specifically on the security and privacy aspects of one of the most popular license-free-band LPWA technologies, which is named LoRaWAN. The paper's key contributions are the details of the design and experimental validation of a security-focused testbed, based on the combination of software-defined radio (SDR) and GNU Radio software with a standalone LoRaWAN transceiver. By implementing the two practical man-in-the-middle attacks (i.e., the replay and bit-flipping attacks through intercepting the over-the-air activation procedure by an external to the network attacker device), we demonstrate that the developed testbed enables practical experiments for on-air security in real-life conditions. This makes the designed testbed perspective for validating the novel security solutions and approaches and draws attention to some of the relevant security challenges extant in LoRaWAN.

Klíčová slova

LoRa; LoRaWAN; security; encryption; testbed; SDR; IoT; LPWAN

Klíčová slova v angličtině

LoRa; LoRaWAN; security; encryption; testbed; SDR; IoT; LPWAN

Autoři

POSPÍŠIL, O.; FUJDIAK, R.; MIKHAYLOV, K.; RUOTSALAINEN, H.; MIŠUREC, J.

Rok RIV

2022

Vydáno

20.08.2021

Nakladatel

MDPI

Místo

BASEL

ISSN

2076-3417

Periodikum

Applied Sciences-Basel

Svazek

11

Číslo

16

Stát

Švýcarská konfederace

Strany od

1

Strany do

17

Strany počet

17

URL

Plný text v Digitální knihovně

BibTex

@article{BUT172314,
  author="Ondřej {Pospíšil} and Radek {Fujdiak} and Konstantin {Mikhaylov} and Henri {Ruotsalainen} and Jiří {Mišurec}",
  title="Testbed for LoRaWAN Security: Design and Validation through Man-in-the-Middle Attacks Study",
  journal="Applied Sciences-Basel",
  year="2021",
  volume="11",
  number="16",
  pages="1--17",
  doi="10.3390/app11167642",
  url="https://www.mdpi.com/2076-3417/11/16/7642/htm"
}

Dokumenty