Patterns to establish a secure communication channel

Andreas Daniel Sinnhofer, Felix Jonathan Oppermann, Klaus Potzmader, Clemens Orthacker, Christian Steger, Christian Kreiner · 2016

Nowadays, cyber-physical systems (CPS) are omnipresent in our daily lives and are increasingly used to process confidential data. While the variety of portable devices we use excessively at home and at work is steadily increasing, their security vulnerabilities are often not noticed by the user. Therefore, portable devices such as wearables are becoming more and more interesting for adversaries. Additionally, the increasing functionalities like internet capabilities, cameras, microphones, GPS trackers and other senor devices make them an interesting target for hacking. Furthermore, such CPS devices are often deployed in unsupervised and untrusted environments raising the question about privacy and security to a crucial topic. Thus, a robust and secure software design is required for the implementation of cryptographic communication protocols and encryption algorithms. In our opinion, Software-Patterns have proven to be an efficient way to support the development of such systems. Therefore, we will present patterns for solving the issue of Man-in-the-middle attacks. The presented patterns provide generic guidance on how to establish secure communication channels based on symmetric and / or asymmetric cryptography. Further, a selection graph is presented which helps to find the appropriate pattern in a specific context.

Read the paper · More papers on PaperTik