Unfettered Access Tokens: Discovering Security Flaws of the Access Token in Smart Home Platforms

Cong Liu, Yiyu Yang, Yuhui Zhang, Yuqing Zhang · 2022

In the smart home platform communication, the access token might properly represent the user’s identity and access permissions. Any access token used in multi-user smart home access should be rigorously regulated by the cloud to guarantee that users only use their devices in permitted ways. However, we were astonished to discover that access tokens in certain popular smart home platforms are unfettered, allowing attackers to illegally eavesdrop on or control IoT devices connected to the cloud. While the access token is essential for managing smart home permissions, there are currently no security checks in place. The fundamental reason is that many standard Web testing tools that check the security of access tokens are disabled by SSL/TLS encryption. Furthermore, whereas many previous studies have focused on the security of OAuth2.0 or smart home apps, only a small amount of research has combined the two. We presented a systematic analysis on smart home platform access token security in this paper. Furthermore, we created a testing tool that allowed us to reuse the app’s underlying logic while also overcoming SSL/TLS encryption issues. We used this tool to examine the security of access tokens in a number of major smart home platforms. Finally, we discovered three types of security issues in seven platforms, one of which is the DoR (Denial of Refresh) flaw, which we discovered for the first time. Our tests revealed that attackers may use these security issues to exploit a total of 106 cloud APIs, posing a serious security risk to device owners.

Read the paper · More papers on PaperTik