Secure FoTA Object for IoT

Krishna Doddapaneni, Ravi Lakkundi, Suhas Rao, Sujay Gururaj Kulkarni, B Rukmini Bhat · 2017

Internet of Things (IoT) is slowly taking over the world where its predicted that by 2025, it will grow to 1-3 trillion connected machines/devices. With large scale deployments, maintaining these devices is a seeming burden on the operations. Also, with huge deployments of IoT devices, most concerns center around privacy and security. To reduce the efforts of on-field maintenance and to perform such tasks remotely and securely, Firmware over The Air (FoTA) can be adopted. FoTA is largely adopted in the mobile world, standardized by Open Mobile Alliance (OMA). In an IoT device ecosystem firmware of nodes/gateways can be updated remotely over the air for feature updates, functional updates, device behaviour updates or more importantly compromised/corrupted firmware, however to avoid the problem of malicious updates, FoTA itself needs to be secure. This paper presents a FoTA procedure for an IoT device ecosystem and defines a new secure object. This proposed Firmware Object Signing and Encryption FOSE is a secure object format in which the FoTA payload is encoded using a secure representation/format such as JOSE (JSON Object signing Encryption). This paper also proposes a simple procedure for over-the-air updates.

Read the paper · More papers on PaperTik