Caveat (IoT) Emptor: Towards Transparency of IoT Device Presence (Full Version)
Sashidhar Jakkamsetti, Youngil Kim, Gene Tsudik

TL;DR
This paper introduces PAISA, a privacy-focused architecture that ensures transparent, secure, and timely announcements of IoT device presence and capabilities using existing hardware features, addressing privacy and security concerns.
Contribution
It proposes a novel, hardware-compatible architecture for IoT device transparency that guarantees device announcements even under software compromise, leveraging ARM TrustZone technology.
Findings
PAISA guarantees timely device presence announcements.
The prototype demonstrates effective detection using WiFi beacons.
PAISA requires no hardware modifications, only off-the-shelf components.
Abstract
As many types of IoT devices worm their way into numerous settings and many aspects of our daily lives, awareness of their presence and functionality becomes a source of major concern. Hidden IoT devices can snoop (via sensing) on nearby unsuspecting users, and impact the environment where unaware users are present, via actuation. This prompts, respectively, privacy and security/safety issues. The dangers of hidden IoT devices have been recognized and prior research suggested some means of mitigation, mostly based on traffic analysis or using specialized hardware to uncover devices. While such approaches are partially effective, there is currently no comprehensive approach to IoT device transparency. Prompted in part by recent privacy regulations (GDPR and CCPA), this paper motivates and constructs a privacy-agile Root-of-Trust architecture for IoT devices, called PAISA: Privacy-Agile…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
