OTA-Key: Over the Air Key Management for Flexible and Reliable IoT Device Provision
Qian Zhang, Yi He, Yue Xiao, Xiaoli Zhang, Chunhua Song

TL;DR
OTA-Key provides a secure, scalable, and efficient method for managing unique device keys in IoT devices by decoupling key storage from firmware and using an intermediary server for key distribution and updates.
Contribution
It introduces OTA-Key, a novel scheme that decouples device keys from firmware, enabling secure, large-scale key management with reduced update times and communication overhead.
Findings
ProVerif security verification confirms scheme security.
Significantly lower update times compared to existing schemes.
Reduced data transfer volumes during key updates.
Abstract
As the Internet of Things (IoT) industry advances, the imperative to secure IoT devices has become increasingly critical. Current practices in both industry and academia advocate for the enhancement of device security through key installation. However, it has been observed that, in practice, IoT vendors frequently assign shared keys to batches of devices. This practice can expose devices to risks, such as data theft by attackers or large-scale Distributed Denial of Service (DDoS) attacks. To address this issue, our intuition is to assign a unique key to each device. Unfortunately, this strategy proves to be highly complex within the IoT context, as existing keys are typically hardcoded into the firmware, necessitating the creation of bespoke firmware for each device. Furthermore, correct pairing of device keys with their respective devices is crucial. Errors in this pairing process…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
