Valkyrie: A Generic Framework for Verifying Privacy Provisions in Wireless Networks - Chaire Internet des Objets entre INSA Lyon et SPIE ICS Access content directly
Conference Papers Year : 2020

Valkyrie: A Generic Framework for Verifying Privacy Provisions in Wireless Networks

Abstract

Wireless communications integrated in connected devices can expose their users to tracking via the exposure of link layer identifiers (e.g. MAC addresses). To counter this threat, it has been proposed to replace those permanent identifiers with periodically changing random pseudonyms [16]. This practice, called address randomization has been progressively adopted by vendors [27, 36] and has even made its way to wireless standards [1, 35]. However, an effective implementation of address randomization requires more than periodically rotating the link layer identifier. Indeed, several works [7, 10, 11, 15, 26, 27, 36] identified issues with address randomization implementation, where in-frames counters and identifiers can undermine the anti-tracking measure. In this paper, we address the problem of verifying the correctness of an address randomization implementation. To this end, we introduce an approach to identify issues based on a capture of the traffic generated by a device. This approach relies on rules specifying requirements for a correct implementation of address randomization. Then, we prototype Valkyrie (Verification of Addresses LinKabilitY in address Randomization ImplemEntations), a software tool that, based on a set of rules, verifies that a given sequence of frames generated by a device does not compromise the address randomization scheme. Finally, we evaluate this tool on a corpus of frame captures corresponding to 60 devices implementing address randomization for Wi-Fi and Bluetooth Low Energy (BLE).
Fichier principal
Vignette du fichier
paper.pdf (1.13 Mo) Télécharger le fichier
Origin : Files produced by the author(s)
Loading...

Dates and versions

hal-02651398 , version 1 (29-05-2020)

Identifiers

Cite

Guillaume Celosia, Mathieu Cunche. Valkyrie: A Generic Framework for Verifying Privacy Provisions in Wireless Networks. WiSec 2020 - 13th ACM Conference on Security and Privacy in Wireless and Mobile Networks, Jul 2020, Linz, Austria. pp.278-283, ⟨10.1145/3395351.3399340⟩. ⟨hal-02651398⟩
209 View
248 Download

Altmetric

Share

Gmail Facebook X LinkedIn More