2013/12/03 by Heiner Perrey, Perrey, Heiner, Martin Landsmann +7 · 1 citation
Computer Science · #C.2.2 #C.2.6 #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Networking and Internet Architecture (cs.NI) #cs.CR #cs.NI
paper · pdf · doi:10.48550/arxiv.1312.0984
arxiv created 2015/12/15 · arxiv updated 2016/08/08
The IPv6 Routing Protocol for Low-Power and Lossy Networks (RPL) was recently introduced as the new routing standard for the Internet of Things. Although RPL defines basic security modes, it remains vulnerable to topological attacks which facilitate blackholing, interception, and resource exhaustion. We are concerned with analyzing the corresponding threats and protecting future RPL deployments from such attacks. Our contributions are twofold. First, we analyze the state of the art, in particular the protective scheme VeRA and present two new rank order attacks as well as extensions to mitigate them. Second, we derive and evaluate TRAIL, a generic scheme for topology authentication in RPL. TRAIL solely relies on the basic assumptions of RPL that (1) the root node serves as a trust anchor and (2) each node interconnects to the root as part of a hierarchy. Using proper reachability tests, TRAIL scalably and reliably identifies any topological attacker without strong cryptographic efforts.