Security Risks Introduced by Weak Authentication in Smart Home IoT Systems
Daniyal Ganiuly, Nurzhau Bolatbek, Assel Smaiyl

TL;DR
This paper empirically analyzes how authentication mechanisms in smart home IoT devices often reuse authentication states, persist without expiration, and are vulnerable to replay attacks, highlighting security risks in current systems.
Contribution
It provides a comprehensive empirical evaluation of authentication behaviors in deployed smart home IoT devices, revealing persistent trust relationships and vulnerabilities.
Findings
Authentication states are reused across control actions.
Authentication persists after network events without explicit expiration.
Replay attacks can successfully issue commands from other local hosts.
Abstract
Smart home IoT systems rely on authentication mechanisms to ensure that only authorized entities can control devices and access sensitive functionality. In practice, these mechanisms must balance security with usability, often favoring persistent connectivity and minimal user interaction. This paper presents an empirical analysis of authentication enforcement in deployed smart home IoT devices, focusing on how authentication state is established, reused, and validated during normal operation and under routine network conditions. A set of widely deployed consumer devices, including smart plugs, lighting devices, cameras, and a hub based ecosystem, was evaluated in a controlled residential environment using passive network measurement and controlled interaction through official mobile applications. Authentication behavior was examined during initial pairing, over extended periods of…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsUser Authentication and Security Systems · Advanced Authentication Protocols Security · Advanced Malware Detection Techniques
