Re: Access control for IoT

Tony Arcieri <[email protected]> Sat, 16 Jan 2016 10:26:17 -0800
Newsgroups gmane.comp.capabilities.general
Message-ID <CAHOTMV+_hStN7T5WqN1XzyA8Joo-7fRqDkbMcrAPZFKGkDMaBg@mail.gmail.com>
--===============6933855516228539550==
Content-Type: multipart/alternative; boundary=047d7bd756e801cff8052977a9fe

--047d7bd756e801cff8052977a9fe
Content-Type: text/plain; charset=UTF-8

On Sat, Jan 16, 2016 at 9:59 AM, Alan Karp <[email protected]> wrote:

> I think one reason for lack of interoperability is the desire for lock-in
> by the vendors.  Another is lack of standards.
>
> As far as privacy versus functionality, I believe 99+% of people will
> choose the latter without blinking an eye.
>

IoT is in a tough spot. Devices are constrained, so implementers often seek
to cut corners on the systems they use in order to boost performance and/or
reduce power usage.

At the same time, these devices require lots of functionality out of the
cryptosystems they use for secure operation and access control.

These two constraints don't play well together, and the result is often
quite broken.

I was just at RealWorldCrypto where a speaker from Microsoft was talking
about a transport encryption protocol designed for non-IP-based transports
used by IoT devices. He threw up a slide with a protocol description and
someone in the audience broke it on the spot (identity misbinding attack).

SecureRF is pushing their "Algebraic Eraser" public key algorithm, which
they claim has performance which scales linearly to the key size as opposed
to quadratically like ECC or RSA:

https://twitter.com/kennyog/status/688409890914717700

But it was already broken once, and apparently a new paper is coming out
next week breaking their "fix".

I have seen plenty of IoT frameworks from real cryptographers which look
rather interesting, but these are all research projects which are
half-baked and don't have a suitable implementation for use on real
hardware.

All that said, as far as I can tell there really isn't anything to
recommend so far that remotely resembles a real option in this space. The
best I can recommend are half-baked research projects.

-- 
Tony Arcieri

--047d7bd756e801cff8052977a9fe
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_extra"><div class=3D"gmail_quote">On S=
at, Jan 16, 2016 at 9:59 AM, Alan Karp <span dir=3D"ltr">&lt;<a href=3D"mai=
lto:[email protected]" target=3D"_blank">[email protected]</a>&gt;</spa=
n> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px =
0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-=
style:solid;padding-left:1ex"><div dir=3D"ltr">I think one reason for lack =
of interoperability is the desire for lock-in by the vendors.=C2=A0 Another=
 is lack of standards.<div><br></div><div>As far as privacy versus function=
ality, I believe 99+% of people will choose the latter without blinking an =
eye.</div></div></blockquote><div><br></div><div>IoT is in a tough spot. De=
vices are constrained, so implementers often seek to cut corners on the sys=
tems they use in order to boost performance and/or reduce power usage.</div=
><div><br></div><div>At the same time, these devices require lots of functi=
onality out of the cryptosystems they use for secure operation and access c=
ontrol.</div><div><br></div><div>These two constraints don&#39;t play well =
together, and the result is often quite broken.</div><div><br></div><div>I =
was just at RealWorldCrypto where a speaker from Microsoft was talking abou=
t a transport encryption protocol designed for non-IP-based transports used=
 by IoT devices. He threw up a slide with a protocol description and someon=
e in the audience broke it on the spot (identity misbinding attack).</div><=
div><br></div><div>SecureRF is pushing their &quot;Algebraic Eraser&quot; p=
ublic key algorithm, which they claim has performance which scales linearly=
 to the key size as opposed to quadratically like ECC or RSA:</div><div><br=
></div><div><a href=3D"https://twitter.com/kennyog/status/68840989091471770=
0">https://twitter.com/kennyog/status/688409890914717700</a><br></div><div>=
<br></div><div>But it was already broken once, and apparently a new paper i=
s coming out next week breaking their &quot;fix&quot;.</div><div><br></div>=
<div>I have seen plenty of IoT frameworks from real cryptographers which lo=
ok rather interesting, but these are all research projects which are half-b=
aked and don&#39;t have a suitable implementation for use on real hardware.=
</div><div><br></div><div>All that said, as far as I can tell there really =
isn&#39;t anything to recommend so far that remotely resembles a real optio=
n in this space. The best I can recommend are half-baked research projects.=
</div><div><br></div></div>-- <br><div class=3D"gmail_signature">Tony Arcie=
ri<br></div>
</div></div>

--047d7bd756e801cff8052977a9fe--

--===============6933855516228539550==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk

--===============6933855516228539550==--