A secure and effective device pairing protocol
Trung Van Nguyen, Jean Leneutre · 2015
The need to secure communications between personal devices is increasing nowadays, especially in the context of Internet of Things. Authentication between devices which have no prior common knowledge is a challenging problem. One solution consists in using a pre-authenticated auxiliary channel, human assisted or location limited, usually called out-of-band channel. A large number of device pairing protocols using an out-of-band channel were proposed. However most of these propositions lacks a formal analysis, and therefore may be vulnerable to some attacks. In this paper, we introduce a new key agreement protocol between two wireless devices. This protocol, only using two wireless messages and one out-of-band message, offers better communication costs than currently existing solutions, yet still ensuring a reasonable security. Security of our proposal is validated both via a formal proof of the security of our protocol in an extension of the strand space model and an estimation of the attack success probability in a computational model.