ELEC6242 Cryptography

  • Subject Code :  

    ELEC6242

  • Country :  

    UK

  • University :  

    University of Southampton

Answer:-

Introduction

The world today has been using smart devices since the technology has improved over the years. Examples of these devices include the use of smartwatches, remote-controlled lamps, and google lenses. These devices are interconnected when being used via applications and the internet (Mollin 2019). The connection in this case makes communication be passed to various people. This process makes issues like the Internet of things be considered in many places that look at data, a connection of people, and different processes used in acquiring information.

According to Forouzan & Mukhopadhyay (2015), they suggested that billions of units are being installed and are using the Internet of Things when communicating with each other. In this case, smartphones and mobiles have been excluded from the units being used. The developers are also working hard to develop systems that apply intelligent devices when communicating with each other. The application of this connection is done on the following domains (Peikert 2016):

  1. Healthcare
  2. Smart environment
  3. Logistics and transport
  4. Social and personal

The application of these devices is made to improve the daily life of people. Various power devices that use wireless connection apply technologies like (Boneh & Shoup 2020):

  1. WiFi
  2. RFID
  3. ZigBee
  4. Bluetooth
  5. Cellular

The technologies are seen as a component of IoT. Over the years the use of smartphones and tablets has dominated the IoT field. Application of these devices normally results in many issues arising especially when looking at privacy and those resulting from security (Katz & Lindell 2020).

Menezes, Van Oorschot, & Vanstone (2018) suggested that physical attacks on devices can be done using simple mechanisms meaning users should be secured while interacting with them. In most cases users tend to ignore the dangers that may arise when using these devices if they are not acted upon. Other issues to be considered include limited resources based on the hardware to be used and energy being applied. This kind of issue makes it hard for complex security protocols to be implemented when handling both information and systems (Stinson & Paterson 2018).

Around 2013, Snowden who was an employee from the CIA disclosed various surveillance programs and how they operate. This lead to the placing of various rules that restricted the use of different applications when looking at issues that deal with privacy and safety of information. This activity has made organizations concentrate more on ways of securing connection through the internet and information being exchanged on daily basis (McKay et al., 2016). The success of this lies in the proper application of cryptography to systems. The main of this application is to make a python program that will demonstrate security among different components. The program will enhance security communication among two or multiple users. The program will be able to receive the messages from the user encode the messages and the same message to the receiver once the information is shared to the receiver the program will decrypt the same message and the receiver will have access to the plaintext. The program will also allow the user to be able to send files that are secured from one network to another. The following sections explains all the process that were used in sending secure information among different users.

Information Background and motives

Most of the system beings in making work easier or platforms that are linked via the internet have decided to improve efficiency and satisfaction acquired when using the demand application (Biryukov & Perrin 2017). This means that issues to consider for this to be possible lie on privacy and security. That is always relying on the integrity and process followed during authentication of different messages and users or devices being added to another system.

For proper integrity to be achieved, the standard techniques being used in handling cryptography must be considered in the process. This is done while keeping in mind other essential tools that might be applicable in the process (Joshi & Karkade 2015). Proper selection of cryptographic techniques leads to the enhancement of security procedures protecting users while interacting with a system. Studies and trials should be considered when looking at devices that incorporate IoT in their system since most of these devices do not apply complex security protocols in their systems. This shows that the protocols to be used in this case should be feasible and also flexible making it easy for it to be applied in different situations.

Application of these techniques in particular normally relies on the structure of the network being used in the process (Alqad et al., 2019). This means that the use of techniques will rely mostly on whether the system or the application uses a distribution or a centralized network when using IoT systems. Most organizations normally prefer a distributed network as opposed to a centralized network since they are not highly affected when looking at scalability and problems referred to as a bottleneck. This means that the system being designed will have the ability to authenticate different users without using an authentication center (Almeida et al., 2017).

According to Aumasson (2017), the focus should be applied to the issues surrounding the password and management of secret keys. This is important since the management of secret keys normally relies on passwords being used in the process where private keys and other certifications must be applied in the process (Pachghare 2019). This means that disclosure issues are always caused by mismanagement of protocols used when looking at password handling. When any system is vulnerable to issues that surround security then it is easily affected by daily problems that may be found affecting other applications and systems such as breach of trust (Wu & Feng 2016). This means that the cryptographic techniques being used in the process should always try as much as possible to avoid issues that surround security and privacy.

Overall aim

The major concern of this research is based on improving the security of how information is being handled. Since this is considered a major threat when it comes to how data is being handled when looking at computer science. In the public section, the major concern that they have is based on the confidentiality of data. This dissertation aims to implement a file system that is secure and can provide the required confidentiality to its users. This feature is to be made in such a way that its effect will not affect a great section of how the system is performing. The goal, in this case, is to ensure that encryption mechanism through cryptography is being used in different fields. Through this privacy of data will enable making information transmission to be as efficient and transparent as possible. The following aspects are considered in this case:

Confidentiality – this means that the application or system in use must always ensure that data from users are kept private and are accessed by authorized personnel only. Through this, any unauthorized access to these data should be notified while denying the service.

Performance – the mechanism used by the application or any system in ensuring that privacy of data is kept as required must be very efficient and does not affect the overall performance of the system also. It is always considered that the technique to be used must fully engage the computing resource of GPU when it wants to provide the required efficiency.

Usability – the users of the system are the ones responsible for promoting various techniques being used in providing security. Since they are responsible for providing comments on how easy it is to apply changes and use a particular technique. The system in this case should be more transparent making it easy for an end-user to follow all the necessary activities. It is always best for users to work in an ad hoc environment when looking at other security aspects.

This dissertation aims to focus on designing and implementing systems that will enhance the security and privacy of data found when using a system within a given network where efficiency is improved and transparency is evident in the process

Scope 

The research in this case concentrates more on the design to be used when looking at the security protocol to be used in this case. Where the focus is on IoT and other media that pass information that needs protection by implementing proper security protocols.  The protocol to be used in this case will also focus on the authentication procedures and integrity found when sharing messages. For transmission pattern to be satisfied when looking at the wireless connection of sensors in IoT then the transmission is supposed to be short and frequent where security level that is dynamic needs to be adjusted. Logic analysis of the protocol will be showcased in the report while showing the security protocols that need to be placed as a prototype of what the IoT is using that will handling different modules and functions that are necessary.

Security of applications and systems covers a wide range of things that must be considered. The project in this case focuses on a security protocol that is deemed as the main section. However, other security issues will be outlined and covered on this project that will help in outlining issues surrounding the following aspects:

  1. Management of passwords
  2. File privilege
  3. Security attack test based on the mentioned protocol

Outline

The project in this thesis is structured in the following manner:

Chapter 1 – will consist of the introduction, background of information as well as general goals to be considered.

Chapter 2 – will showcase other related studies and work based on a similar project.

Chapter 3 – shows the methodology and procedures used in achieving a particular research work.

Chapter 4 – describes the structure found when looking at security protocol. It also illustrates a design of communication channels being used.

Chapter 5 – issues evaluation of how the system is performing while looking at the logic analysis.

Chapter 6 – will contain a summary of the whole research while looking at considerations to be made in the future.

Literature Review

This chapter provides brief evidence of situations and studies that have been carried out when it comes to how security is viewed in the field of computing. The following are some of the things to be checked in the process:

  1. Concepts covered in security
  2. Algorithms used in cryptographic
  3. BAN logic
  4. Situations found in IoT based on security

Concepts in security

Computer security can be defined as follows:

Protecting information systems with aim of reaching the intended objective that is based on maintaining the core values surrounding confidentiality, integrity, and availability of system resources (Petrenko 2018). The resources in question include the following:

  • Hardware
  • Software
  • Data
  • Telecommunication
  • Firmware

According to the definition, the main concepts to be considered when looking at computer security relies upon the following (Warner 2015):

  1. Confidentiality – This means that access to information found in any system should be restricted to specified people unless asked otherwise.
  2. Integrity – this act ensures that information is stored in the system cannot be destroyed or modified without the required procedure.
  3. Availability – this act ensures that the is reliable when it comes to how information can be accessed via the system.

In most cases of research, it is always argued that features like authenticity and accountability can be included in what is found on the CIA triad to make any system complete. Where authentication is used for verification purposes where it is used to prove that the user is the person who they claim to be. Accountability implies that the system being used can be relied upon when tracing back faults and issues that may arise when using the system. This process makes it easy for the system to recover its data.

Algorithms applied in cryptography

Algorithms being applied in this case are the ones used in enhancing the security of different systems. This means different algorithms will be picked based on what system is being developed (Pittalia 2019). Through this many attacks can be avoided since the security techniques being applied are always improving with time. This section will cover examples of cryptographic algorithms that will be applied to this dissertation.

Advanced Encryption Standards (AES)

This algorithm was published by NIST in the year 2001 to replace the existing DES. The algorithm works through the block cipher that applies 128 bits on its blocks and key in terms of size (Aleisa 2015). This type of key is considered more secure. The algorithm applies a different technique from that of the Feistel structure. Where it uses the following functions (Abdullah 2017):

  1. XOR
  2. Substitution
  3. Arithmetic operation
  4. Permutation

When compared to the RSA algorithm, AES applies a complex technique where the plaintext is used to cover the 128-bit block (Singh & Dod 2016). The algorithm uses a matrix in the process of encrypting and decrypting where the four functions mentioned above are used in the process. During this activity, the application of permutation and substitution is based on the ratio of one to three respectively. The first stage to be handle is the substitute being handled in the S-box that checks the situation in a byte by byte step of substitution. The next stage is the shifting of rows done through permutation (Xin 2015). After this, the arithmetic operations are used in mixing the columns.

Merits of using AES algorithm

  • The algorithm applies relatively less space when using computer resources when compared to algorithms using the asymmetric method.
  • The algorithm is more secured since communication is protected even when one key has been compromised in the process.

Demerits of using AES algorithm

  • Exchanging of keys to be used should occur through a secured media before it can be applied.
  • It makes it difficult to secure different keys since the secret keys are meant to be used by one party.
  • Verification of messages becomes a difficult task since the users in question are applying the same keys.
Rivest Shamir Adleman (RSA)

This encryption is also referred to as asymmetric encryption. In this algorithm, one key is used in the process of encrypting and decrypting messages unlike encryption based on symmetric encryption (Shankar 2018).  This technique is the most widely used when handling cryptosystems. The algorithm uses exponentials as its expression during encryption and decryption methods (Tahir 2015).

Rivest Cipher 4

The algorithm was developed by Ron Rivest and was mostly used by RSA Security. The algorithm is applied in many sections during information transmission based on the following areas (Bhanot & Hans 2015):

  1. SSL is known as Secure Socket Layer
  2. TLS is known as the Transport Layer Security
  3. WEP referred to as Wired equivalent Privacy

Application of security on IoT

Aspects making up the internet of things have been highlighted based on research conducted by different scholars. Where the concentration was on privacy and security issues facing the technology (Aiswarya et al., 2016). The major concern was on how to prevent active attacks that occur through the issues of authentication and integrity of data. Most of these authentication attacks are always occurring since protection requires nodes between IoT structures and the center of authority to be always in sync making it possible to capture the messages during communication. Cryptography is always preferred as a method that will help enhance data integrity when looking at IoT (Karakra & Alsadeh 2016). When applying encryption to IoT the issue arising is always based on the capabilities of devices being used to hold the required level of bandwidth that result from the encryption method to be applied.

This means that most of the devices cannot be able to handle complex cryptographic algorithms which limits them to few light schemes of cryptography that apply symmetric keys. To solve this kind of problem encryption technique is applied on the gateways that make it possible to avoid an issue like abnormal node. When linking sensors to an external network it is good for the setup to be done appropriately since many hackers will always try and use the denial of attack through this. Through this, the best security technique to be applied in this case is end-to-end encryption as opposed to the by-hop style of encryption.

Another aspect to be reviewed on the structure of IoT in terms of security applies on an inspection done to an architecture containing four important levels that include (Liang, Malekian, & Wang 2016):

  1. Perceptual layer – the layer is responsible for collecting data since it has sensors. This section is considered to be a weak layer since there are many challenges to be faced when implementing security on the hardware resources.
  2. Network layer – this is considered the critical layer when dealing with IoT and should be provided with maximum security protection that will prevent an attack like counterfeit from being carried out on the network.
  3. Support layer – provides a reliable platform for the operation of applications. The challenge being faced in this layer is that it is difficult for malicious data to be identified. This is because the section handles much information when an interaction is conducted in this section.
  4. The application layer – is the section responsible for handling different kinds of data that is provided to users (Jaju & Chowhan 2015). This layer also raises many other issues that should be considered in the process such as access level to information, the privacy of data, and information disclosure.

Secure Socket and Transport Layer

The SSL protocol is used in providing security service to information exchange that occurs between TCP and different kind of applications that applies TCP in its functions (Mollin 2019). This means that SSL is in charge of providing end-to-end protection services. In the process of conducting its function, it also provides reliability and the existence of privacy. The SSL protocol has two layers. Where the lower level has been placed on some reliable top part of the transport protocol that has similar capabilities to the TCP (Oppliger 2016). This is referred to as the SSL record of the protocol. Another protocol is the SSL handshake that enables authentication services to occur between the server and client. Before the two applications interact, they will try and decide on how to apply the cryptographic key and select the best encryption algorithm. SSL protocol provides the required transparency.

The ongoing messages that are based on the application layer have the following fields with them (Buchanan, Woodward, & Helme 2017):

  1. Description
  2. Length
  3. Content

The message will be handed to SSL, where they will be placed in fragments of blocks that can be managed easily. The message is issued with MAC after that they are encrypted and transferred to the required destination. On the recipient side the following processes occur respectively (Krüger et al., 2017):

  1. Decryption of data
  2. Verification of data
  3. Decompressing the block to information that was sent
  4. Reassembling the blocks and finally delivering them to the high-level client.

The Transport Layer Security (TSL) protocol performs the same function as that of SSL that provides integrity of data and while ensuring privacy exists between the interacting applications. The protocol also contains two layers that include (Diro, Chilamkurti, & Kumar 2017):

  1. TLS handshake that has a similar function to those of SSL
  2. TLS record that ensures there is security during the connection process. This layer is responsible for ensuring that there is privacy as well as reliability.

Protocol analysis

The logic used is the Burrows-Abdi-Needham logic that is also referred to as BAN logic. This simply refers to rules that are used in the process of modeling and analyzing protocols used in information security. The logic is used in analyzing authentication protocols that derive different beliefs from logical deductions. This process makes it possible for users to conclude the security of the protocol. The following are some of the questions that the BAN logic is capable of answering (Ghani et al., 2019):

  1. The aim of the protocol to be used.
  2. Comparing assumptions of one protocol to another.
  3. Weaknesses of the protocol to be checked.
  4. Techniques used in encrypting information.

Peer-to-peer Security network

The networking concepts found in the peer-to-peer (P2P) structure of a network are normally different when compared to what is base on the client-server relationships. When looking at how information is being exchanged in the process of interaction (Hong 2020). Attack in P2P systems can be classified based on structure. This implies that when looking at the unstructured format of the system the following are some of the attacks that should be considered in the process (Han 2015):

  • Self-replication attack
  • Man-in-the-middle attack

While the structured system of P2P has to consider the following (Kim, Lee, & Kim 2020):

  • Routing attacks
  • Storage and retrieval
  • Concentration to be placed on node joins since many attacks can be carried through them

The aspect that follows has been used in enhancing the security of P2P. The plan of this security is formed through the use of Simple Public Key Infrastructure and Simple Distributed Security Infrastructure. The issue arising in this kind of situation will require the placement of authentication centers that will help prevent issues of scalability as well as a bottleneck.

Methodology

In every research project conducted methodology always plays a crucial role in ensuring that the development of the project is carried out using the appropriate and best method. This section will discuss some of the methodologies used in completing the research.

Accumulation of Knowledge

This research has been based on events that occur through the internet when handling devices found in areas like the IoT and other systems. Where the focus is on security aspects and capabilities. The areas to be checked in the process of solving this problem of security will be as follows (Reyad 2018):

  1. Basic principles in an involved situation
  2. Algorithms to be used
  3. Considered protocols

The above suggestions will be closely checked based on how it relates to cryptography and measures of security. The knowledge applied in this research cover many sections of learning where knowledge will be extracted from different books and both research journals and paper. In the process of accumulating the required knowledge, it is best for the merits and demerits of algorithms used in cryptography to be highlighted as well as those covering security protocols.

The concepts on vulnerabilities must be considered also on different types of protocols since it will help in avoiding similar issues when working on another protocol. It is also best for follow-ups to be done on an attack that has not been published in books making it relatively easy to work with different algorithms during the implementation process.

Design ideas

The ideas to be applied in this case will come from the application of the SensibleThings framework that supports the development of IoT devices while linking them to different networks. The features that must be considered in the process of developing ideas should contain the following sections (Rodríguez, Corredor, & Suárez 2019):

  1. Scalability – this means that the proposed protocol should try and ensure its performance of operation be through the distributed servers and third parties are not involved during communication of two entities.
  2. Lightweight – this feature makes it possible for the proposed solution to work on devices with limited resources.
  3. Fast – the speed can be improved in this case by reducing the rate of handshake occurring in each session.
  4. Integrity – information, in this case, should not be modified by other sources apart from those with the required access.
  5. Flexibility – it should be supported by different dynamic mechanisms.
  6. Authentic – the proposed solution should comply with what is required by the authorities and also contain a signed certificate.

The above principles should be considered in the preparation of developing a platform that functions through the distributed server. The application of the mentioned principles leads to the development of a new style that develops keys through local storage mechanisms as well as certificates (Kavitha et al., 2019). Management applies the hierarchy style since the storage is applied to the local context during the implementation process. Adaption of the mutual mechanism of authentication will be used since the servers are distributed in this scenario.

Design Styles

Before developing any desired design when handling systems it is always best to gain a proper understanding of principles and important logics that should be maintained when coding. The design styles check at different modules to be used when looking at the proposed security protocol. This is done through the use of the object-oriented design of the software. That will enable features to be placed based on real-life situations. This kind of technique is mainly used since the process makes it easy for modules generated to be reused easily. This relatively reduces the coupling of modules while increasing their cohesion. The style used in this case includes the abstract factory method (Timothy & Santra 2017).

Test-driven development

The unit test platform is used in increasing the efficiency and quality of different modules found on the system. The main aim of many developers in this stage is to identify and prevent the bugs from crushing the system when it is being used. This section also ensures that the modules have been placed in a way that enables them to focus on a single task. For this process to achieve the system development should ensure the following principles are used based on object-oriented design (Rashmi & Jyothi 2018):

  1. Single responsibility
  2. Open-closed
  3. Liskov substitution
  4. Interface segregation
  5. Dependency inversion

The above principles are used in ensuring that different classes of the system are performing on required task based on the single responsibility principle.

Analyzing protocol

BANs Logic is considered the best tool for analyzing security protocol. It is applied to a system that has been fully designed and revision is done to different stages of each module of the system. This kind of practice aims to reduce and identify weaknesses in the finished design (Basu et al., 2019). The whole process of testing is conducted on a setup that resembles the actual environment and helps in the reinforcement of different sectors.

Design and Implementation process

This section looks at the finer details of the security protocol to be developed. It looks at different aspects such as:

  1. Structure
  2. Philosophy
  3. communication

Sections of the SensibleThings framework will be illustrated by looking at different modules forming the platform and also its structure.

Applied Security Protocol

Security protocol applied on P2P systems found in IoT plays a crucial part in the survival of the system. This is because it looks at the process of communication and procedures used in the authentication. The protocol also makes it easy to define the logic and platform of the system. The protocol to be designed ensures that the following concepts are achieved in the process of development (Glissa & Meddeb 2019):

  1. Relatively low cost of development
  2. Achievement of high efficiency
  3. Provision of high-security concept

Principles

Parts of principles have been mentioned in the methodology section. In this chapter the principles will be described in detail making it easy for logic to be derived when looking at the protocol of the proposed solution. This process aims to enhance the development of systems that contain distributed servers. That makes the system to be very scalable in the process. Application of this principle results in the implementation of new techniques on the system that promotes mutual authentication carried through certified authority nodes. Another aspect includes the use of hierarchical management that results from local storage applications.

The system should ensure that authentication and safekeeping of sensitive information are maintained without the application of central server systems that will make the system suffer from issues like a bottleneck. This means that another procedure should be identified on how the protocol will be able to do the authentication process. Where nodes of bootstrap can be applied in the process to ensure to help with the integration of the system to new platforms. Also, the selection process should ensure that the node is stable and from a trustworthy source. The selected node will have the capabilities of permitting other networks to interact with its system where the new nodes are issued with trust before requesting to join.

A well-known and trusted bootstrap node must be used in the process. This is is because they are trusted when it comes to making a secure connection by other systems. The certificate issued by a bootstrap node is essential since it contains information from the sender that is very essential and must be considered. In this case, it includes (Badra 2016):

  1. The name of the subject
  2. The public key in use
  3. Signature from bootstrap node

Entities containing signatures from bootstrap can authenticate each other by verifying their certificates. Through this, they can manage to share session keys within them. It is difficult to modify the content of the certificate hence making them to be more important. It is also important to ensure that the session and private keys are only visible when being used within the hierarchy management since they contain sensitive data.

Overview of the protocol

The sections to be considered in the proposed security protocol include:

  1. The registration point
  2. Joining and communication section

When applications are joining the system, the first thing to consider in the process is their registration process. New keys will be generated by the new application as well as a signed certificate of its own. The two pieces of information will be stored in the permanent key store referred to as (PCS). This store is protected using a different mechanism of protection and is only visible to those with the required level of access authority. The store requires this level of security since it contains important information including private keys and other certificates that have been signed.

Certificate logging request is normally produced when the security protocol is used for the first time where they are sent to the Authority Server and Authority Node. Upon receiving the request a private key is issued and sent back to the server together with the root certificate. During the interaction process, a mutual key controlling the session is generated before the process continues. This means that information is transferred in the process is encrypted through the use of key sessions.

The stage that follows is the joining and communication. In this section, the applications are only allowed to access the P2P framework when they exist on the registration access list. Identifiers are applied when maintaining the distributed hash table preferred as (DHT). This means that different entities are capable of searching for these identifiers. Different execution will be generated based on the certificate and session key contained in each entity.

Registration process

This part will handle the process followed during the registration process. It occurs mainly through the client who has joined and the authority node. At the start, there will be a common connection generated to support the Transmission Control Protocol (TCP). During the process of register, the SSL is the one that sends the first request to AS. The preceding action will rely mostly on SSL. This is mainly done to improve security during registration transactions.

The registration request will be sent to AS by the client where it will be attached with the identity and nonce. Replay attacks that are common in this section are prevented through the application of nonce. That ensures old data can never be used again in performing similar communication.

A self-signed certificate plus the nonce are sent by the AS after receiving a request that handles registration from the client. The signature in this case makes it easy for verification to occur. The certification received in the process will be stored on the local permanent key store.

The AS issues request sent to it by the client where it checks the identity to validate its credentials. Where certificate will be awarded and information will be encapsulated and sent to the client

The process in this case almost reaches its end when the client issued a certificate showcasing the signing of a response message. This stage also tries to check the details of the protocol based on identity and signature as well as a nonce. The session that has been encrypted in this case will be stored in a temporary and local place (Jover 2016). This process is done to enhance security through the stored session in case the process is required. At the of this, a certificate representing the acceptance of the message is issued back to AS while being accompanied by the nonce. The process of shifting the SSL communication is done last when there are no other registered transactions to be conducted in the process.

Joining and communication process

This scenario contains three features that must be considered all depending on how the certificate and session key has been shared with the receiver from the sender's side. The worst-case according to this aspect is where the certificate to be sent by the sender is considered invalid which most of the cases happens when it has expired. This shows that the sender does not have the certificate that corresponds to the situation making them responsible for exchanging the certificate. This is when looking at the first situation.

The second situation is somehow favorable for performance where the sender contains a corresponding certificate that is valid to the target acquiring it. The issue, in this case, is that the sender has not yet shared the required session key and at the same time it is not expired. This leaves the choice of the key being negotiated in the process. The best-case scenario occurs when the sender has the key that corresponds to the receiver and is valid. This means that the message will be encrypted and sent to the required destination.

Among the positive situation is when communication begins with clients responding to each other. This situation is positive since both of them have keys that are valid and can communicate without having any redundancy in communication. When it occurs that the session keys have expired without any communication being achieved in the process. The sender will be the one negotiating for session keys with the known target.

Securing communication found on SensibleThings Platform

The section will cover a detailed implementation of the protocol on the SensibleThings platform. To enhance the required transparency it is best to apply the security protocol in the form of communication that resembles the SSL. This process will help developers to secure communication that occurs through the system without having fear of how the protocol works. The details have been discussed in the below section about the platform

The general structure

The structure of the SensibleThings platform has been highlighted while considering the secure communication channel. Implementation of secure communication is based on what has been existing on other platforms like:

  • SSL
  • TCP
  • RUDP

The development process takes a lot of time since the existing platforms are providing some of the best interfaces that easily allow communication to be conducted. The structure of this secure communication system is as follows on the diagram below.

 

The above figure shows how the secure communication protocol should be developed where coupling has been reduced in the process by each module. This process makes the system to be very scalable and while making its reusability features more simple.

Secure communication has three-level that can be used to categories the system. Based on this it is considered that the lowest level is the one responsible for handling communication services. This level is the one in charge of the transmission of data. It handles the following situations:

  1. Acknowledging packets have been received
  2. Retransmission of packets that are considered lost

The level that follows is where this dissertation will be putting its emphasis. Where the implementation of messages is done in this section. Message handler as the name suggests handles the messages being served on this protocol. And at the same time, is in charge encapsulating message that has been transmitted from the upper level.  There is another component that is closer to the message handle known as security configuration. That handles the configurations of communication being carried out in the process. It contains different aspects of the parameter that handles how different issues are being stored in the process.

The remaining structure in this case is responsible for handling different operations such as:

  1. Encryption and decryption process
  2. Storage of keys
  3. Drawing keys

The structure, in this case, is referred to as the security manager that is responsible for providing specific operations used in meeting the needs of secure communication. The module has other smaller sub-modules that act as its staff that is responsible for conducting real operations. Security manager functions through governing of different activities.

Implementation of secure communication

Security configuration has been developed using three main parts that include:

  1. Bootstrap – it acts as an administrator from which the new nodes will be using to join.
  2. Key store – it is responsible for storing the identities of new entities.
  3. Security level – it provides the application with a variety of security measures to be considered.

The security handler in this case is responsible for handling routing to messages being handled with this protocol. The messages in question are always directed to the security manager where they can appear base on the list below:

Communication ShiftingMessage – it aims at sending a signal to the bootstrap node informing it to shift communication. This means that the nodes can be shifted between RUDP and SSL.

Registration Response Messaging – makes it possible for a secure connection to be developed through the use of the asymmetric cipher.

Registration Request messaging – it sends a request for registration to the node of bootstrap based on what has arrived from nodes.

Certificate Requesting Message – this is based on the public key acquired from registration response messaging that enables the node to reply with a certificate requesting message that contains different aspects like a nonce and encrypted ID.

Certificate Responding Message – in this stage the bootstraps issues a certificate that is signed based on how verification has been conducted on certificate request. During this process, a setup is placed that will handle the session key.

Certificate of Accepted Message – nonce is sent back with the node having a session key that is encrypted.

Secure Message – the information, in this case, is used in serving the upper level with messages that will be somehow encapsulated when reaching a secure message.

Certificate Exchanging Message – this process is used when nodes want to share messages but existing valid certificates cannot be seen in the process. Where this certificate will be sent to share information with bootstrap to know what's going on.

Management of security via security manager

In this case, the security manager resembles all the services grouped to be checked by the message handler. It is responsible for controlling almost all the processes dealing with how information is contained in the message section. It goes ahead to handle the management of how keys are stored while showing the interfaces related to cryptography.

 

The figure above has been used to illustrate how the structure of the security manager is supposed to be based on different modules. It contains the following  parts that are dominant:

  1. Asymmetric encryption
  2. Symmetric encryption
  3. Certificate
  4. Signature

The stage that follows shows the operations conducted on the different parts as shown in the figure above. Where they mostly interact with the store holding the keys.

The application on this case was to demonstrate encrypting and decryption process for given application. The user fills in information to the application. The application takes in takes the same information and send to the receiver with a particular key. The key that was used in encrypting the messages from the user is the same key that is used in decrypting the messages from the sender . The following  shows the interfaces that can be used in this case.

The application interface that was used in this case is a show in the figure above.

 

The message is fed into the application

 

The message and key that are used in encrypting the messages are provide as show in the diagram above. The same that will be used in encrypting the messages is the same key that will be used in decrypting the message this can be show in the following figure .

The message that should be decrypted is provided as show in the figure above.

The message is decrypted so that the receiver can have access to its content as shown in the figure above .

Results

This section will look at the analysis of security protocol based on secure communication and its working efficiency.

Environment Testing 

The efficiency to be tested on the communication section will rely on the local area network to be developed where the nodes are set.

 

The nodes shown above are running using windows 10 and is 32 bit

Performance

The performance is tested by looking at different algorithms used in the process of encrypting communication. The process considers different modes that exist when looking at symmetric cipher. The most suitable symmetric ciphers considered in this case include the AES and RC4. The following are some of the different modes that can be applied when looking at the AES block style of encryption.

  1. Cipher blockchain (CBC)
  2. Electronic codebook (ECB)
  3. Cipher feedback
  4. Output feedback
  5. Propagating cipher blockchain
  6. Counter

For this test to work different scenario of the environment applying the symmetric style needs to be tested. This is done through the generation of random messages that are to be encrypted and later on decrypted. The occurs through a small time frame recorded in nanoseconds. The time taken has been measured via testing specified tests whose averages are returned and calculated. The ECB is normally taken as the fastest when it comes to texts having a length of 100,000 bytes.

Comparing to SSL

Communication in this section is mostly developed on the frameworks of SensibleThings. The cipher to be applied in this case is the SSL_DH_anon_WITH_RC4_128_MD5. This indicates what the Diffie Hellman Algorithm exchange meant. This algorithm uses the 128 bits that are applied on RC4 and MD5. The nodes applied in this case can work without the application of certification being applied in the process.

Based on the scenario where there is two-node to be used for testing performance, one will be responsible for generating random test containing specified attributes. That will be transferred to the other node containing the protocol. The information received in the process is sent back to the node again using the quick method since the nodes are not in sync. This means that the transmission time is only read from one side of the two nodes.

When the SSL is compared with the security protocol in a proposition. It is seen that the proposed protocol is much faster based on the 1000 average transmission used in the process of testing between the intervals. Where the SSL takes time to respond as compared to the proposed solution.

Analysis of secured communication

The analysis is based on secure communication of what is on the project. This analysis is not based on looking at the protocol that handles the fundamental logic. This type of analysis is considered to be more complex since it focuses on technical issues that surround the project and requires time for it to be conducted following all the precise measures necessary. The process in this section also goes ahead to illustrate different limitations that can be generated when the proposed security protocol has been fully implemented. This means that results conducted and acquired in the process make it possible to state different issues that might be put to work in the future.

During the process of implementing the proposed security protocol, the main concern is always on a selection of the precise cryptographic technique to use. This is because the developer is left with the choice of selecting the technique from those that are existing or develop their own. The best recommendation is always to select those that exist. The main reason for this is that cryptography principles are public based on the libraries that have tested with many platforms making them more secure. The risk involved in this kind of case is minimum since the application of these libraries results in risks like the Heartbleed bug. The whole process saves much time also when the public algorithm has been selected in the process.

A lifetime of involved session keys play an important role and must be considered in the process of configuring the security aspect of the system. Where the best parameter must be used in controlling how the session key operates in the process. Developers should always try and maintain this aspect of their life when they want to improve both efficiency and security. When the session key contains a lifetime that is too long then it might end up compromising the system. At the same when the lifetime is relatively too short then the frequent exchange of keys might result in the system getting heavy and lowering the efficiency of service delivery.

Conclusion

The use of the internet in the world has made it possible for people to live a different kind of life-based. All of this results from the use of devices that apply IoT during communication and exchange of ideas. The following are some of the main places where lifestyle has changed due to information sharing and application of various technologies in the process:

  1. Smart choices
  2. Safety measures

This process has created many different areas that people can try and venture into them. While at the same time it creates many issues that must be considered by many developers and people when interacting with any system or developing them when need is required. This means that proper security mechanisms should always be applied to systems being developed in the process. Through this approach efficiency of systems will be improved making people not suffer attacks that might occur in the process of interacting with the system.

Based on this research the network that was used as an example is the P2P network. To solve the issue of security when using the network this platform will be best recommended where it will be applying the P2P security protocol in addressing different issues at the end. The research also looks at the SensibleThings Framework since many devices using IoT are always applying concepts covering this kind of direction.

The aspects being checked in this case mostly concentrate on the distributed server and preventing the use of third parties in the communication process where two entities are involved in the process. The system in this case is considered to be lightweight making it stores keys and different certificates to a specified store making the system run smoothly on mobile devices that contain limited resources. The protocol in this case is faster when compared to the SSL cipher that is being applied in many platforms. The main reason for this is that the number of extra handshakes has been relatively reduced in different existing sessions. The adjustment in the dynamic nature of the security level makes it more flexible to be applied in other application requirements. The integrity of the system has been provided through the application of good encryption methods and signatures required in the process of interaction. The authentication aspect is provided by the existing signed certificate from the authorized node. The information transmission is reliable and much faster. The protocol use principles applied to the SensibleThing framework making it to be very secure in the process.

Secure communication is achieved through the application of an abstract interface pattern that increases the existing cohesion of each module that has been developed while decreasing the coupling effect. The template is applied in this case making it possible for basic functions to be tested through the test-driven development that allows an extension of the security aspect in this case.  This process increases the efficiency and robustness of communication that is secured.

The security protocol is analyzed through the application of BAN logic as a tool that will help in conducting analysis that will highlight the existing weaknesses of a system. At the same time, it makes it possible to reduce the existing redundancy without causing effects like weakening of the system in the end. Also based on tests that have been conducted it is evident that the proposed security protocol is more efficient as compared to SSL by reducing the rate of handshake occurring.

The dissertation identifies the main issues and provides the required solution which is very efficient in handling a different situation that arises when using any network connection that is not secured. This has been achieved through the implementation of a security protocol that works best as compared to SSL. The system has been built in such a way that it can run on different devices while maintaining the level of security required in the process. Through this technique, people can work and interact without getting the feeling of being exposed to attacks that are likely to occur when using the internet for communication in particular. The same issue also encouraged the development of various devices that can apply IoT functionalities while maintaining the high-end security required in the process.

Future work

The aspect to be considered in the later stages of the system will include issue like:

  1. Management of permission
  2. Management of passwords
  3. Detection of malicious activities on the node
  4. Preventing and testing serious attacks on communication systems that are secure

Issues like the management of passwords play an important role in ensuring that the system tries to handle privacy-related scenarios with much care. Where the process covers also the aspect of recovery users passwords that can be handled in the following ways:

  1. Resetting through use of email approach
  2. Reset done via text messages of the user
  3. The other style is through the voice calls

The different ways of managing and resetting passwords need to be checked in detail. This is because there are many ways through which this process can be conducted and many items can be included in the process making it possible for the system to be completely secured.

Management of permission can be tackled through the implementation of policies that will encourage authentication and authorization of services to be handled with much care since the system is responsible for handling crucial and sensitive information. The information is stored in this case is the key used in identifying different entities that are in communication.

Detection of malicious services on specified nodes should also be included when improvement is to be done on the proposed system. The process of identifying this kind of activity takes time but it is useful in knowing different activities being conducted on the system and preventing them before greater harm is induced when an interaction is occurring between nodes.

Serious attacks need to be tested on the system to determine its capabilities in case of this kind of attack happening. The problem being faced in the process is that the test needs to be conducted through professionals. Where they used specified tools such as the Kali Linux. The process also requires the application of good strategy in the process of testing different aspects.

Are you in dire need of assignment help in the UK? Can’t figure out who can help you whenever you find yourself thinking, “Wouldn’t it be great if I could pay someone to do my assignment?” With Myassignmenthelp.co.uk, you can fulfil your desires without any hassle.

Send us your requirements, and our paper writers will take care of your assignment worries quickly. So now, you don't have to worry about, "Where can I find someone to do my assignment for me in the UK?” Instead, let our experts provide you with the best assignment help in London, Bristol, Manchester, Liverpool and more!

Why Student Prefer Us ?
Top quality papers

We do not compromise when it comes to maintaining high quality that our customers expect from us. Our quality assurance team keeps an eye on this matter.

100% affordable

We are the only company which offers qualitative and custom assignment writing services at low prices. Our charges will not burn your pocket.

Timely delivery

We never delay to deliver the assignments. We are very particular about this. We assure that you will receive your paper on the promised date.

Round the clock support

We assure 24/7 live support. Our customer care executives remain always online. You can call us anytime. We will resolve your issues as early as possible.

Privacy guaranteed

We assure 100% confidentiality of all your personal details. We will not share your information. You can visit our privacy policy page for more details.

Upload your Assignment and improve Your Grade

Boost Grades