Evaluating IP security on lightweight hardware

dc.contributorAalto-yliopistofi
dc.contributorAalto Universityen
dc.contributor.advisorGurtov, Andrei
dc.contributor.authorKhurri, Andrey
dc.contributor.departmentTietotekniikan laitosfi
dc.contributor.departmentDepartment of Computer Science and Engineeringen
dc.contributor.schoolPerustieteiden korkeakoulufi
dc.contributor.supervisorYlä-Jääski, Antti
dc.date.accessioned2012-08-29T09:58:50Z
dc.date.available2012-08-29T09:58:50Z
dc.date.issued2011
dc.description.abstractTCP/IP communications stack is being increasingly used to interconnect mobile phones, PDAs, sensor motes and other wireless embedded devices. Although the core functionality of communications protocols has been successfully adopted to lightweight hardware from the traditional Internet and desktop computers, suitability of strong security mechanisms on such devices remains questionable. Insufficient processor, memory and battery resources, as well as constraints of wireless communications limit the applicability of many existing security protocols that involve computationally intensive operations. Varying capabilities of devices and application scenarios with different security and operational requirements complicate the situation further and call for agile and flexible security systems. This study does an empirical evaluation of applicability of selected existing IP security mechanisms to lightweight (resource-constrained) devices. In particular, we evaluate various components of the Host Identity Protocol (HIP), standardized by the Internet Engineering Task Force for achieving authentication, shared key negotiation, secure mobility and multihoming and, if used with IPsec, integrity and confidentiality of user data. Involving a set of cryptographic operations, HIP might easily stress a lightweight client, while affecting performance of applications running on it and shortening battery lifetime of the device. We present a background and related work on network-layer security, as well as a set of measurement results of various security components obtained on devices representing lightweight hardware: embedded Linux PDAs, Symbian-based smartphones, OpenWrt Wi-Fi access routers and wireless sensor platforms. To improve computational and energy efficiency of HIP, we evaluate several lightweight mechanisms that can substitute standard protocol components and provide a good trade-off between security and performance in particular application scenarios. We describe cases where existing HIP security mechanisms (i) can be used unmodified and (ii) should be tailored or replaced to suit resource-constrained environments. The combination of presented security components and empirical results on their applicability can serve as a reference framework for building adaptable and flexible security services for future lightweight communication systems.en
dc.format.extentVerkkokirja (1566 KB, 150 s.)
dc.format.mimetypeapplication/pdf
dc.identifier.isbn978-952-60-4005-9 (PDF)
dc.identifier.isbn978-952-60-4004-2 (printed)#8195;
dc.identifier.issn1799-4942
dc.identifier.urihttps://aaltodoc.aalto.fi/handle/123456789/4915
dc.identifier.urnURN:ISBN:978-952-60-4005-9
dc.language.isoenen
dc.publisherAalto Universityen
dc.relation.ispartofseriesAalto University publication series DOCTORAL DISSERTATIONS , 2/2011en
dc.subject.keywordHost Identity Protocolen
dc.subject.keywordIP securityen
dc.subject.keywordcryptographyen
dc.subject.keywordperformanceen
dc.subject.keywordresource-constrained devicesen
dc.subject.keywordmobile Interneten
dc.subject.otherComputer science
dc.subject.otherTelecommunications engineering
dc.titleEvaluating IP security on lightweight hardwareen
dc.typeG4 Monografiaväitöskirjafi
dc.type.dcmitypetexten
dc.type.ontasotVäitöskirja (monografia)fi
dc.type.ontasotDoctoral dissertation (monograph)en
local.aalto.digiauthask
local.aalto.digifolderAalto_66325

Files

Original bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
isbn9789526040059.pdf
Size:
1.49 MB
Format:
Adobe Portable Document Format