This article develops a shared-secret free wireless security infrastructure that provides confidentiality, identity authentication, message authentication, integrity, sender nonrepudiation, receiver nonrepudiation, and anonymity. Our infrastructure is based on two physical primitives, namely collaborative jamming and spatial signature enforcement, and a zero knowledge alternative for bootstrapping trust. Notably, it eschews the use of shared secrets, while providing a cryptosystem that is no less secure than conventional cryptosystems.
Link asymmetry is one of the unique challenges that wireless sensor networks pose in the design of network protocols. We observe, based on testbed experiments, that a substantial percentage of links are asymmetric, many are even unidirectional. We also find that the reliability of synchronous acknowledgments is considerably higher than that of asynchronous messages. Thus the norm of estimating link quality bidirectionally via asynchronous beacons underestimates the link reliability of asymmetric links. This leads us to investigate how to exploit asymmetric links in order to improve network functions such as convergecast routing in sensor networks via one-way link estimation. We propose a new one-way link metric ETF (for the expected number of transmissions over forward links) and present a local procedure for its estimation. We use ETF to identify reliable forward links, and we use dynamic retransmission thresholding for error control. Via experiments on testbeds of CC1000 radios and CC2420 radios (an IEEE 802.15.4-compliant radio), we quantify the performance improvement in ETF as compared with ETX. We also study the performance improvement of ETF over ETX when no special mechanism is employed to discover asymmetric links or to control retransmissions.
Cooperative jamming enables secure communication between two radios without using shared secrets. We design an efficient randomized coding scheme that uses cooperative jamming within the context of conventional modulation-demodulation schemes to achieve concurrent two-way secure communication.
A sensor network typically refers to a collection of sensor nodes equipped with sensing, communication and processing capabilities. It brings an opportunity to solve many difficult problems including real time monitoring, tracking, and controlling. While the applications of sensor networking become many and varied, security has always been one of the major concerns in real deployments. In this dissertation, we design physical primitives for secure communication in wireless sensor networks, and develop a wireless security framework to provide conventional security services. We investigate the feasibility of achieving perfect secrecy and information authenticity without shared secrets via two physical primitives: (i) cooperative jamming primitive, where we introduce a secure coding problem in which not only the sender but also the receiver participates in the coding. In essence, the receiver’s role is to selectively jam the sender’s transmission at the level of bits, bytes, or packets. We then design a class of secure codes, called “dialog codes”, for diverse channel models and receiver models. (ii) spatial verification primitive, where we exploit the spatial signature induced by the radio communications of a node on its neighboring nodes, and design a spatial primitive that robustly and efficiently validates the authenticity of the source of messages. To address trust initialization, we propose a zero knowledge proof alternative that allows bootstrapping trust among individuals in a distributed way.
Link estimation is a basic element of routing in low-power wireless networks, and data-driven link estimation using unicast MAC feedback has been shown to outperform broadcast-beacon-based link estimation. Nonetheless, little is known about how different data-driven link estimation methods affect routing behaviors. To address this issue, we classify existing data-driven link estimation methods into two broad categories: L-NT that uses aggregate information about unicast and L-ETX that uses information about the individual unicast-physical-transmissions. Through mathematical analysis and experimental measurement in a testbed of 98 XSM motes (an enhanced version of MICA2 motes), we examine the accuracy and stability of L-NT and L-ETX in estimating the ETX routing metric. We also experimentally study the routing performance of L-NT and L-ETX. We discover that these two representative, seemingly similar methods of data-driven link estimation differ significantly in routing behaviors: L-ETX is much more accurate and stable than L-NT in estimating the ETX metric, and accordingly, L-ETX achieves a higher data delivery reliability and energy efficiency than L-NT (for instance, by 25.18 percent and a factor of 3.75, respectively, in our testbed). These findings provide new insight into the subtle design issues in data-driven link estimation that significantly impact the reliability, stability, and efficiency of wireless routing, thus shedding light on how to design link estimation methods for mission-critical wireless networks which pose stringent requirements on reliability and predictability.
In this paper, motivated by the goal of modeling the fine-grain capabilities of jammers for the context of security in low-power wireless networks, we experimentally characterize jamming in networks of CC2420 radio motes and CC1000 radio motes. Our findings include that it is easy to locate J (relative to S and R) and choose its power level so that J can corrupt S's messages with high probability as well as corrupt individual S's bits with nontrivial probability. Internal jammers are however limited in at least two ways: One, it is hard for them to prevent R from detecting that it has received an uncorrupted message from S. And two, the outcome of their corruptions are not only not deterministic, even the probabilities of corrupted outcomes are time-varying. We therefore conclude that it is hard to predict the value resulting from colliding S's messages (bits) with J's messages (bits) and, conversely, to deduce the value sent by S's or J's from the corrupted value received by R.
Significant worldwide growth is witnessed in development and deployment of huge numbers of heterogeneous sensor networks. These all brings the issue of state-of-the-art federations or collaborations among such networks. Query Processing operation in such collaborative systems has major challenges: fast and scalable query processing, QoS support for query, flexible and robust collaborative system design etc. To our knowledge there has not been much work done on designing scalable and efficient query processing among the huge collaboration of sensor networks. The work EE-QPS designed a pipelined query optimization problem based on energy efficiency. But with varying demands (energy, delay, reliability etc.) of different queries, the Quality of Service (QoS) support becomes very important. Also, entirely sequential or entirely parallel query processing have problems with latency and scalability. Then a hybrid query processing scheme can have flexibility to deliver better performance for all kinds of collaborative systems. Considering all these aspects, we have proposed QoS-QPS, a QoS supported clustered Query Processing System. We have designed a flexible model for querying cost of sensor networks. The cost model is inexpensive to compute and general enough to apply. Then we propose clustered query processing technique, that utilizes a constrained graph partitioning algorithm. This whole QoS aware query processing technique delivers balanced and efficient clustering of sensor networks based on implication relationship. Comprehensive simulations study shows that our proposed scheme is better than existing techniques in compromising among different system requirements. The results also validate the efficiency, scalability and applicability of QoS-QPS. Further we have analyzed potential architectural issues and possible solutions.
The wireless network community has become increasingly aware of the benefits of data-driven link estimation and routing as compared with beacon-based approaches, but the issue of Biased Link Sampling (BLS) estimation has not been well studied even though it affects routing convergence in the presence of network and environment dynamics. Focusing on traffic-induced dynamics, we examine the open, unexplored question of how serious the BLS issue is and how to effectively address it when the routing metric ETX is used. For a wide range of traffic patterns and network topologies and using both node-oriented and network-wide analysis and experimentation, we discover that the optimal routing structure remains quite stable even though the properties of individual links and routes vary significantly as traffic pattern changes. In cases where the optimal routing structure does change, data-driven link estimation and routing is either guaranteed to converge to the optimal structure or empirically shown to converge to a close-to-optimal structure. These findings provide the foundation for addressing the BLS issue in the presence of traffic-induced dynamics and suggest approaches other than existing ones. These findings also demonstrate that it is possible to maintain an optimal, stable routing structure despite the fact that the properties of individual links and paths vary in response to network dynamics.
We investigate the feasibility of achieving perfect secrecy in wireless network communications without shared secrets. We introduce a secure coding problem in which not only the sender but also the receiver participates in the coding. In essence, the receiver's role is to selectively jam the sender's transmission at the level of bits, bytes, or packets. We then design a class of secure codes, which we call dialog codes, for diverse channel models and receiver models. Our codes are simple and efficient, with only O(1) complexity in both the encoding and the decoding process, and achieve optimal coding rate in some channel models. This, along with their potential for augmenting security and/or simplifying security bootstrapping, makes them worthy of consideration for resource-constrained wireless sensor network devices. By way of experimental validation, we study the channel jamming characteristics of extant mote radios — specifically, CC2420 (IEEE 802.15.4) and CC1000— in experiments, observe their time-varying channel behavior, and demonstrate the correctness and robustness of implementations of our dialog codes at the byte-level and at the packet-level in the presence of dynamic channel fluctuations.
Message authentication is a critical task in wireless sensor applications not only because it is a basic building block to ensure the authenticity of information but also a prerequisite for bootstrapping cryptographic secrets. Authentication has been explored extensively in the literature, however, the insecure environment within a fabric where multiple users and applications coexist, and limitations in the hardware pose new challenge for this problem. In this paper, we define a new zero knowledge proof problem in which (1) no memory of neighboring certificates is required; and (2) there is no central verification. We then discuss the properties of any potential solution, and propose a practical scheme that allows zero knowledge proof of the identity of each individual node. A notable merit of this scheme is that even if some nodes are compromised, the rest of the system remains secure. We believe this scheme can satisfy the security requirements in many emerging sensor network applications with proper parameter selection.
This paper develops a framework for wireless security that provides confidentiality, identity authentication, message authentication, integrity, sender non-repudiation, receiver non-repudiation and anonymity. Our framework is based on two physical primitives: collaborative jamming and spatial signature enforcement. Notably, it eschews the use of shared secrets, while providing a cryptosystem that is no less secure than conventional cryptosystems.
Security, reliability and interoperability are indispensable in today's distributed heterogeneous information infrastructure. For government and military applications, it is crucial to conduct effective and efficient testing of security properties for newly developed systems, which are to be integrated into existing information system. Yet little progress has been made in the technology advancement of rigorous and automated security testing. In this contribution we present virtual cyber security testing capability (VCSTC) - a DoD funded project-for developing an automated testing capability that can assess the operational functions and security impact of a target system without physically integrating it into an intended network infrastructure. VCSTC first synthesizes a model to emulate the real network infrastructure; then it automatically generates and executes test cases with guaranteed coverage of the features and security properties under test. This report presents the architecture of VCSTC, its key techniques and experimental results on real systems.
Wireless sensor networks have a variety of applications, such as environment monitoring, structural monitoring, remote exploration, condition-based maintenance, commercial surveillance, and national asset protection. These applications require the network to monitor a certain type of non-local spatiotemporal phenomenon, collaboratively process gathered information, and respond to external events or report results. There are different types of phenomenon that can be observed by a network of sensors. For some phenomena such as fire, gas leak, chemical attack and biological attack, it is critical to track the boundary of the affected area.
Network security devices are becoming more sophisticated and so are the testing processes. Traditional network testbeds face challenges in terms of fidelity, scalability and complexity of security features. In this paper we propose a new methodology of testing security devices using network virtualization techniques, and present an integrated solution, including network emulation, test case specification and automated test execution. Our hybrid network emulation scheme provides high fidelity by host virtualization and scalability by lightweight protocol stack emulation. We also develop an intermediate level test case description language that is suitable for security tests at various network protocol layers and that can be executed automatically on the emulated network. The methodology presented in this paper has been implemented and integrated into a security infrastructure testing system for US Department of Defense and we report the experimental results.
Link estimation is a basic element of routing in low-power wireless networks, and several approaches using broadcast beacons and/or unicast MAC feedback have been proposed in the past years. No netheless, there has been no systematic study on the inherent draw backs of beacon-based link estimation and the subtleties of data-dr iven link estimation. Using a testbed of 98 XSM motes (an enhanced version o f MICA2 motes), we characterize the inherent errors in predicting unicast properties via broadcast beacons, and we show that data-driven lin k estimation and routing achieves higher event reliability (e.g., by up t o 18.75%) and energy efficiency (e.g., by up to a factor of 1.96) than beacon -based approaches. Through mathematical and experimental analysis , we examine the accuracies of different data-driven link estimation methods and their impacts on routing performance. We discover, counterintui tively, that two representative, seemingly similar methods of data-dri ven link estimation differ significantly in performance: in our testbed, for instance, data delivery reliability differs by 25.18%, and energy efficiency differs by a factor of 3.75. These findings provide new insight into the su btle design decisions in link estimation that significantly impact routing performance in low-power wireless networks. Keywords—Low-power wireless networks, sensor networks, link estimation and routing, data-driven, beacon-based
We answer the following questions for routing in wireless sensor networks: 1) should broadcast beacon or data serve as the basis of link estimation? 2) how to use MAC feedback in data-driven link estimation and routing? 3) how to address the issue of biased link sampling in data-driven link estimation and routing.
The wireless network community has become increasingly aware of the benefits of data-driven link estimation and routing as compared with beacon-based approaches, but the issue of biased link sampling (BLS) has not been well studied even though it affects routing convergence in the presence of network and environment dynamics. Focusing on traffic-induced dynamics, we examine the open, unexplored question of how serious the BLS issue is and how to effectively address it when the routing metric ETX is used. For a wide range of traffic patterns and network topologies and using both node-oriented and network-wide analysis and experimentation, we discover that the optimal routing structure remains quite stable even though the properties of individual links and routes vary significantly as traffic pattern changes. In cases where the optimal routing structure does change, data-driven link estimation and routing is either guaranteed to converge to the optimal structure or empirically shown to converge to a close-to-optimal structure. These findings provide the foundation for addressing the BLS issue in the presence of traffic-induced dynamics and suggest approaches other than existing ones. These findings also demonstrate that it is possible to maintain an optimal, stable routing structure despite the fact that the properties of individual links and paths vary in response to network dynamics.
This paper experimentally investigates the feasibility, of crypto-free communications in resource-constrained wireless sensor networks. We exploit the spatial signature induced by the radio communications of a node on its neighboring nodes. We design a primitive that robustly and efficiently realizes this concept, even at the level of individual packets and when the network is relatively sparse. Using this primitive, we design a protocol that robustly and efficiently validates the authenticity of the source of messages: authentic messages incur no communication overhead whereas masqueraded communications are detected cooperatively by the neighboring nodes. The protocol enables lightweight collusion-resistant methods for broadcast authentication, unicast authentication, non-repudiation and integrity of communication. We have implemented our primitive and protocol, and quantified the high-level of accuracy of the protocol via testbed experiments with CC1000 radio-enabled motes.