PUFSSL: An OpenSSL Extension for PUF based Authentication

Urbi Chatterjee, Rajat Sadhukhan, Vidya Govindan, Debdeep Mukhopadhyay, Rajat Subhra Chakraborty, Sweta Pati, Debashis Mahata, Mukesh M. Prabhu · 2018

Connected devices in Internet-of-Things (IoT) framework have become more functional and commonplace in modern day-to-day living recently. One of the major security challenges in IoT framework is authentication and key management and hence, rigorous security analysis of these networked devices has been surfaced on demand. In this work, first we show how our recent work on designing certificate-less authentication and key exchange scheme using Physically Unclonable Functions (PUF) and Identity based Encryption (IBE) aptly fits this scenario and can be integrated with TLS layer for widespread deployment. Next, we propose an idea to modify the Handshake Protocol in the SSL/TSL layer for authentication of client-server pair and secret key share, substituting the RSA/DSA certificate exchange with the proposed PUF based scheme. For validation, we implement the proposed client-server authentication and key exchange modules in OpenSSL and compare it with RSA/DSA/ECDSA certificate sign and verify modules along with ECDH key generation module which already exist in OpenSSL. We finally discuss the pros and cons of of the proposed approach in the paper.

Read the paper · More papers on PaperTik