Document Type

Article

Publication Date

3-29-2022

Publication Title

Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies(IMWUT)

Volume

6

Issue

1

Pages

1-29

Publisher Name

Association for Computing Machinery

Publisher Location

New York, USA

Abstract

Wireless connectivity is becoming common in increasingly diverse personal devices, enabling various interoperation- and Internet-based applications and services. More and more interconnected devices are simultaneously operated by a single user with short-lived connections, making usable device authentication methods imperative to ensure both high security and seamless user experience. Unfortunately, current authentication methods that heavily require human involvement, in addition to form factor and mobility constraints, make this balance hard to achieve, often forcing users to choose between security and convenience. In this work, we present a novel over-the-air device authentication scheme named AEROKEY that achieves both high security and high usability. With virtually no hardware overhead, AEROKEY leverages ubiquitously observable ambient electromagnetic radiation to autonomously generate spatiotemporally unique secret that can be derived only by devices that are closely located to each other. Devices can make use of this unique secret to form the basis of a symmetric key, making the authentication procedure more practical, secure and usable with no active human involvement. We propose and implement essential techniques to overcome challenges in realizing AEROKEY on low-cost microcontroller units, such as poor time synchronization, lack of precision analog front-end, and inconsistent sampling rates. Our real-world experiments demonstrate reliable authentication as well as its robustness against various realistic adversaries with low equal-error rates of 3.4% or less and usable authentication time of as low as 24 s.

Comments

Author Posting ©️ ACM, 2022. This article is posted here by permission of ACM for personal use. This article was published in the Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies(IMWUT), VOL.6,ISS.1 (March 29, 2022), https://doi.org/10.1145/3517254

Creative Commons License

Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 License
This work is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 License.

Share

COinS