用于无线嵌入式系统的熵引导
Entropy Bootstrapping for Wireless Embedded Systems
浏览论文内容
中文总结 AI 辅助
研究廉价无线传感器因弱随机性存在风险,提出为ESP32类物联网节点构建深度防御引导路径,结合多种技术,通过无线电突发提取等方式获取熵,经基准测试支持特定准入策略,保障系统安全。
中文摘要 AI 辅助
弱随机性已通过实现漏洞、引导熵稀缺和后门生成器破坏了已部署的密码学。廉价无线传感器集中了风险,因为许多在高度确定性条件下启动或运行,同时依赖基本、初级或不透明的随机数生成器。在ESP32类板上,射频禁用的无线设备随机数生成器寄存器(WDEV)输出按规范是伪随机的,但通过与射频激活状态相同的统计筛选,表明输出测试不能替代源状态准入。我们为ESP32类物联网节点提出了一种深度防御引导路径,结合了静态随机存取存储器启动材料、无线电突发提取和明确源状态准入下的非对称熵胶囊。在无线电突发提取中,本地物联网网络中的可信节点发送公共数据包突发以打开测量窗口。客户端在该窗口期间对自身WDEV输出和数据包定时进行采样,然后仅计入本地响应。胶囊通过预配置的非对称密钥对覆盖冷启动情况。可信节点用客户端公钥加密新鲜种子材料并对胶囊签名;客户端在有本地熵之前进行验证、解封装和哈希。我们在几种无线电操作模式、固定突发提取窗口、确定性胶囊客户端路径和静态随机存取存储器启动读取下对ESP32随机数生成器进行基准测试。这些测量共同支持一种准入策略,即只有当其所需的源状态和协议检查成立时,每个根才被计入。
英文摘要
Cryptographic protocols require unpredictable randomness at first boot, yet wireless sensors often wake with uninitialized hardware or noise sources running in unverified operating states. In platforms like the ESP32, statistical testing cannot catch this cold-start failure because the internal random number generator continues returning statistically plausible bytes even when analog radio noise is disabled, producing pure pseudorandomness by design. To prevent nodes from silently anchoring security in a single unverified source, we introduce a defense-in-depth boot architecture governed by explicit source-state admission. The system combines three orthogonal roots of unpredictability: startup noise from uninitialized SRAM cells, local wireless RNG output gathered during a bounded window defined by an external packet burst, and a signed post-quantum asymmetric capsule delivering fresh entropy from a trusted peer without requiring local random generation. Rather than blending unverified numbers, the admission policy gates entropy credit on the verified operating mode of the hardware, admitting wireless RNG output only while the radio frequency circuits are active. Empirical trials confirm that incoming network traffic successfully bounds repeatable, uncorrelated hardware sampling windows, while remote capsule verification completes with minimal processing overhead. By coupling physical operating state to cryptographic accounting, commodity microcontrollers can bootstrap reliable seed entropy across complementary roots without relying on additional dedicated security hardware.