Transcription of Considerations on Security in ZigBee Networks - …
1 Considerations on Security in ZigBee NetworksGianluca Dini and Marco TilocaDipartimento di Ingegneria dell InformazioneUniversity of PisaPisa, Italy{ , ZigBee outlines a new suite of protocols targetedat low-rate, low-power devices and sensor nodes. ZigBee Spec-ification includes a number of Security provisions and Security model specified in the Smart Energy Profile seemsbound to become the reference Security model for most ofZigBee applications. In this paper we review this Security modeland highlight places where its specification presents concernsand possible inefficiencies in Security management. Specifically,we show that the specification does not adequately address theforward Security requirement so allowing a number of threatsat the routing and application layer. Furthermore, we showinefficiencies in managing both the Network Key and devicescertificates.}
2 Finally, we make some proposals to address ; Security ; key management;I. INTRODUCTIONZigBee is an emerging standard for low-power, low-ratewireless communication which aims at interoperability andencompasses a full range of devices even including low-end battery-powered sensor nodes. ZigBee is built upon thephysical layer and medium access control defined in theIEEE standard (2003 version). ZigBee Specification includes a number of Security provi-sions and options. In particular, ZigBee provides facilities forcarrying out secure communications, protecting establish-ment and transport of cryptographic keys, cyphering framesand controlling devices. ZigBee improves the basic securityframework defined in IEEE , focusing also on keyestablishment and Specification provides two Security models, Stan-dard Security Mode and High Security Mode.
3 While theformer is designed for lower Security residential applications,the latter is intended to be used for high Security commercialapplications. The Security model of the Smart Energy Profileis asserting itself as a reference Security model for ZigBeeapplications, since it constitutes a trade-off between the twostandard this paper we first introduce this Security model andthen we show that it presents two critical issues that havenot been adequately addressed. First of all, the securitymodel does not adequately address theforward securityrequirement [1]. Actually, upon leaving the network (orbeing forced to), a node still remains able to access commu-nication because the onboard keying material is not properlyrevoked. A node may leave the network when it is dismissed,sent to maintenance, lost, compromised, or supposed all these cases, the keys stored on the device may becompromised, and thus, if the they are not properly revoked,an adversary may exploit them to mount severe attacksagainst the network and application , the model comprises a public-key protocol fordevice authentication and key establishment.
4 In order to beopen and interoperable, the model allows many subjects toissue certificates, namely manufacturers, distributors, andeven end users. As a consequence, a device should beequipped with certificates of all potential certification sub-jects. However, this requirement raises a scalability problem,since it conflicts against the limited storage resources ofZigBee end rest of the paper is organized as follows. In Section IIwe provide an overview of ZigBee and IEEE Section III we discuss the Security model and the re-lated key management mechanisms provided by the ZigBeeSmart Energy Profile. In Section IV we present the securityconcerns regarding the forward Security requirement andcertificate management and propose possible approaches forsolutions. Related works are discussed in Section V. Finally,in Section VI we draw our conclusive OVERVIEWZigBee is a specification for a suite of high level commu-nication protocols, intended for devices equipped with smalland low-power digital radios based on the IEEE As reported in [2], ZigBee and IEEE arestandards-based protocols which provide the network infras-tructure required for wireless sensor network depicted in Fig.
5 1, IEEE defines the physicaland MAC layers, while ZigBee defines the network andapplication IEEE MAC layer provides reliable com-munications between a node and its immediate neighbors,addressing collision avoidance and improving efficiency. TheMAC layer also assembles and decomposes data packets andframes, while the physical layer provides the interface to thephysical transmission medium ( radio). ZigBee places itself on top of the IEEE PHY andMAC layers. Basically, it is formed by the application (APL)Figure ZigBee protocol and the network (NWK) layer. Among other things,the application layer specifies frame formats for transportingdata and provides a data service to the applications, whilethe network layer handles network management and routingby invoking actions in the MAC layer. Security is providedin a cross-layered fashion, involving both the application andthe network the rest of this section we present the main features ofIEEE and ZigBee Networks with more IEEE IEEE network can be composed of twotypes of device: Full-Function Devices (FFDs) and Reduced-Function Devices (RFDs) [3].
6 FFDs can talk with both otherFFDs and RFDs, whereas RFDs can talk only with an , an RFD is intended for very simple applicationsand features minimal resources, in terms of storage, mem-ory and processing capability. An IEEE networkcomprises at least oneCoordinator, an FFD capableof relaying messages from other devices. Furthermore, oneCoordinator is elected asPAN Coordinatorand is respon-sible for network and Security management. An RFD isassociated to a single FFD at a time. In an IEEE two topologies are the Star topology each RFD talks directly to the PANC oordinator, while in the Peer-to-peer topology each devicecan communicate with any other FFD in its range, in orderto define more complex network provides Security services on incomingand outgoing frames, when requested by the higher standard supports the following Security services ona per-frame basis: data confidentiality, data authenticity,and replay protection.
7 Such services are provided at theMAC level by means of (i) anauxiliary Security subheader(carrying useful information for Security processing, includ-ing how the frame is actually protected and which keyingmaterial is used); (ii) a collection ofsecurity MAC layerattributes(in order to configure Security procedures in aflexible way and determine how to provide Security ), and,finally, (iii)Frame Security procedures( operations tosecure/unsecure frames or retrieve cryptographic keys). Animportant point to consider is that IEEE does notconsider at all key establishment and device MAC layer entrusts such services to the higher layers( ZigBee ), and solely provides communication securityat the MAC level. Thus, IEEE assumes that whena frame is transmitted (received) and it needs to be secured(unsecured), all the needed Security material ( crypto-graphic keys) is available and already established at boththe sender and the recipient side.
8 However, IEEE to use the 128-bit AES encryption scheme [4].B. ZigBeeThe ZigBee Alliance has developed a two-way wirelesscommunications standard, which turns out to be low-costand low-power consumption. Solutions adopting the ZigBeestandard will be embedded in consumer electronics, homeand building automation, industrial controls, PC peripherals,medical sensor applications, toys and to the Specification [5], a ZigBee networkmay comprise three types of devices:Coordinator,Router,andend device. With reference to the device types inan IEEE network, the ZigBee Coordinator corre-sponds to the PAN Coordinator, a Router corresponds toa Coordinator and an end device corresponds to an RFDor an FFD which is neither a Coordinator nor the PANC oordinator. In the rest of this document we will use theZigBee terminology to indicate ZigBee network layer (NWK) supportsStar,Tree,andMeshtopologies.
9 In the Star topology, the networkis controlled by the Coordinator, which is responsible forinitiating and maintaining the devices on the network, whilethe end devices directly communicate with the Mesh and Tree topologies, the Coordinator is responsiblefor starting the network and for choosing certain key networkparameters, but the network may also be extended throughthe use of ZigBee Routers, while routes are established bymeans of a routing protocol similar to the Ad hoc On-demand Distance Vector (AODV) protocol. In Tree net-works, Routers move data and control messages through thenetwork using a hierarchical routing regard to Security issues, ZigBee fits very well withthe services provided by IEEE and uses symmetrickey encryption for end-to-end communications. In partic-ular, a ZigBee network must comprise aTrust Center, anode, typically the ZigBee Coordinator, which provides keymanagement and other Security offers someapplication profileswhich specifyboth a possible collection of devices and a set of messagesused by devices to communicate with one another.
10 Eachapplication profile describes also someclusters, sets ofparameters and commands (some mandatory) the deviceshave to use in order to interoperate within the , the most important and promising ZigBee appli-cation profiles seem to beHome Automation[6] andSmartEnergy[7]. In the rest of this document we will focus onthe latter, since it considers Security as a major issue andincludes precise mechanisms for secure communications aswell as a properKey Establishment Cluster[7].III. Security INSMARTENERGYPROFILES mart Energy Profile(SEP) provides device descrip-tions and standard practices for demand-response and loadmanagement applications, tailored for residential or lightcommercial environment. Possible scenarios include singlehomes or even an entire apartment complex. Currently,key application domains are metering, pricing and demandresponse and load control applications.