arrow
Return

Security Vulnerabilities in LoRaWAN

delete2018-04-01
delete76
PRE
AI
X
Xueying Yang *
E
Evgenios Karampatzakis
C
Christian Doerr
F
Fernando Kuipers
DOI:10.1109/IoTDI.2018.00022delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
LoRaWAN is a MAC-layer protocol for long-range low-power communication. Since its release in 2015, it has experienced a rapid adoption in the field of Internet-of-Things (IoT). However, given that LoRaWAN is fairly novel, its level of security has not been thoroughly analyzed, which is the main objective of this paper. We highlight the security features present in LoRaWAN, namely activation methods, key management, cryptography, counter management, and message acknowledgement. Subsequently, we discover and analyze several vulnerabilities of LoRaWAN. In particular, we design and describe 5 attacks: (1) a replay attack that leads to a selective denial-of-service on individual IoT devices, (2) plaintext recovery, (3) malicious message modification, (4) falsification of delivery reports, and (5) a battery exhaustion attack. As a proof-of-concept, the attacks are implemented and executed in a controlled LoRaWAN environment. Finally, we discuss how these attacks can be mitigated or protected against.
Keywords:
LoRaWAN
security
replay attack
eavesdropping
bit flipping
ACK spoofing
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

I
IEEE/ACM Third International Conference on Internet-of-Things Design and Implementation
IF:
0
Papers:
5
Citations:
0

Organization

D
Delft University of Technology
Scholars:
2.6W
Papers: 2.5W
Citations: 3.8W