Evaluation of Security Issues on Communication Systems for Internet of Things (IoT)
Date
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
Access Rights
Abstract
In this thesis, taking into consideration of performance-based and security issues, we suggest a set of secure and lightweight AKA methods for LTE network and LTE-enabled IoT applications named Robust Evolved Packet System-Authentication and Key Agreement (REPS-AKA) protocols. Accordingly, we presented five security approaches called REPS-AKA1, REPS-AKA2, REPS-AKA3, REPS-AKA4, and REPS-AKA5. The REPS-AKA1 protocol is presented in chapter 3 to satisfy the security requirements of the LTE system. Then, new handover mitigation named REPS-AKA2 is also suggested in chapter 4 to provide backward and forward key separation and satisfy important security requirements in the X2 handover. In chapter 5, the REPS-AKA3 protocol is presented to settle the security issues in LTE networks. The suggested approach combines the asymmetric and symmetric encryption methods to provide a strong mutual authentication between involved nodes. In chapter 6, we proposed REPS-AKA4 method as a set of safe and fast authentication protocols during the first attachment, nth attachment, and Inter/Intra handover in LTE-WLAN Interworking (LWI) systems. In addition, we suggested a lightweight group-based AKA method for IoT applications called REPS-AKA5 protocol in chapter 7. The proposed method presents a strong mutual authentication between involved nodes and ensures strong identity protection of the IoTDs. The suggested approach also presents considerable confidentiality in the user/control plans using an optimized combination of symmetric/asymmetric keys. We verified the proposed AKA protocols by using the AVISPA, Scyther tools, and BAN logic to check that the REPS-AKA methods are resistant to different known security attacks. Furthermore, we evaluated our method based on performance metrics. The considered results are shown that compared with other AKA methods, the proposed methods provide better performance in terms of computational cost, and signaling overhead. Hence, the REPS-AKA approaches are able to achieve not only defined security requirements but also a considerable improvement in network performance. Keywords: M2M communication, LTE Security, AVISPA tool, BAN logic, Group-based authentication, IoT systems, Subscriber identity, and EPS-AKA protocol, Mobile Communication, Mutual Authentication.
Bu tezde, performansa dayalı ve güvenlik konularını dikkate alarak, LTE ağı ve LTE özellikli IoT uygulamaları için Robust Evolved Packet System-Authentication and Key Agreement (REPS-AKA) adı verilen bir dizi güvenli ve hafif AKA yöntemi öneriyoruz. Buna göre, REPS-AKA1, REPS-AKA2, REPS-AKA3, REPS-AKA4, ve REPS-AKA5 adı verilen beş güvenlik yaklaşımı sunuyoruz. Bölüm 3’te, LTE sisteminin güvenlik gereksinimlerini karşılamak için REPS-AKA1 protokolü sunulmuştur. Daha sonra, yeni geçiş işlemi adı verilen REPS-AKA2, geriye ve ileriye doğru anahtar ayrımı sağlamak ve X2 geçişinde önemli güvenlik gereksinimlerini karşılamak için Bölüm 4’te önerilmiştir. 5. bölümde, REPS-AKA3 protokolü LTE ağlarındaki güvenlik sorunlarını çözmek için sunulmuştur. Önerilen yaklaşım, ilgili cihazlar arasında güçlü bir karşılıklı kimlik doğrulama sağlamak için ortak anahtar ve simetrik anahtar yöntemlerini birleştirir. 6. Bölümde, LTE-WLAN sistemlerinde ilk bağlantı, n’inci bağlantı ve inter/intra aktarım sırasında bir dizi güvenli ve hızlı doğrulama metodu olarak REPS-AKA4 protokolünü önerdik. Önerilen REPS-AKA4 protokolü, yalnızca güvenli bir inter/intra kimlik doğrulaması değil, aynı zamanda AKA prosedürünün performansını arttırabilen LWI sistemi içerisinde etkin bir yeniden doğrulama yaklaşımı sağlar. Ek olarak, 7. bölümde REPS-AKA5 protokolü olarak adlandırılan IoT uygulamaları için hafif grup-tabanlı bir AKA yöntemi önerdik. Önerilen yöntem, ilgili düğümler arasında güçlü bir karşılıklı kimlik doğrulama sunar ve IoT cihazları için güçlü kimlik koruması sağlar. Önerilen yaklaşım aynı zamanda, optimize edilmiş bir simetrik/asimetrik anahtar kombinasyonu kullanan kullanıcı/control planları için önemli ölçüde gizlilik sunar. REPS-AKA yöntemlerinin bilinen farklı güvenlik saldırılarına karşı dirençli olduğunu kontrol etmek için AVISPA, Scyther araçları ve BAN mantığını kullanarak önerilen AKA protokollerini doğruladık. Ayrıca, yöntemimizi performans metriklerine göre değerlendirdik. Ele alınan sonuçlar, diğer AKA yöntemleriyle karşılaştırıldığında, önerilen yöntemlerin hesaplama maliyeti, ve sinyal yükü açısından daha iyi performans sağladığını göstermektedir. Bu nedenle, REPS-AKA yaklaşımları, yalnızca tanımlanmış güvenlik gereksinimlerine ulaşmakla kalmaz, aynı zamanda ağ performansında da önemli bir gelişme sağlar. Anahtar Kelimeler: Makineden Makineye İletişim (M2M), LTE Güvenliği, AVISPA aracı, BAN mantığı, Grup-tabanlı kimlik doğrulama, IoT sistemleri, Abone kimliği, EPS-AKA protokolü, Mobil iletişim, Karşılıklı kimlik doğrulama.










