The growth of IoT has increased the need for robust device provisioning. However, many deployments operate under strict cost constraints. In the low-cost segment, dedicated secure elements are often not affordable. At the same time, complex global supply chains enlarge the attack surface and expose devices to cloning, tampering, and credential injection before deploy- ment. This setting requires a careful balance between security and cost. In this paper, we present a lightweight provisioning protocol designed for low-cost IoT devices without secure elements. The protocol is based on a simplified variant of the Noise framework, adapted to reduce protocol and implementation complexity while maintaining authentication and key-establishment guarantees within a precisely defined attacker model. Given the complexity of cryptographic protocol design, we formally model and verify the protocol in Tamarin to establish authentication and session- key secrecy under explicit trust assumptions. To the best of our knowledge, this is the first formally verified provisioning protocol specifically targeting low-budget IoT deployments. Our notion of lightweightness is structural, referring to protocol simplicity and reduced state-management requirements rather than to a full embedded performance evaluation. The verified guarantees concern disclosure through the modeled protocol and channel abstractions, while extraction of bootstrap key material from the provisioning firmware binary remains outside the scope of the formal analysis.

A Formally Verified Provisioning Protocol for Low-Cost IoT Devices

M. Busi;R. Focardi;F. L. Luccio;F. Palmarini
In corso di stampa

Abstract

The growth of IoT has increased the need for robust device provisioning. However, many deployments operate under strict cost constraints. In the low-cost segment, dedicated secure elements are often not affordable. At the same time, complex global supply chains enlarge the attack surface and expose devices to cloning, tampering, and credential injection before deploy- ment. This setting requires a careful balance between security and cost. In this paper, we present a lightweight provisioning protocol designed for low-cost IoT devices without secure elements. The protocol is based on a simplified variant of the Noise framework, adapted to reduce protocol and implementation complexity while maintaining authentication and key-establishment guarantees within a precisely defined attacker model. Given the complexity of cryptographic protocol design, we formally model and verify the protocol in Tamarin to establish authentication and session- key secrecy under explicit trust assumptions. To the best of our knowledge, this is the first formally verified provisioning protocol specifically targeting low-budget IoT deployments. Our notion of lightweightness is structural, referring to protocol simplicity and reduced state-management requirements rather than to a full embedded performance evaluation. The verified guarantees concern disclosure through the modeled protocol and channel abstractions, while extraction of bootstrap key material from the provisioning firmware binary remains outside the scope of the formal analysis.
In corso di stampa
2026 IEEE Intenational Conderence on Cyber Security and Resilience (IEEE CSR)
File in questo prodotto:
File Dimensione Formato  
IEEE_CSR_Provisioning_Protocol.pdf

non disponibili

Tipologia: Documento in Pre-print
Licenza: Accesso chiuso-personale
Dimensione 235.8 kB
Formato Adobe PDF
235.8 kB Adobe PDF   Visualizza/Apri

I documenti in ARCA sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/10278/5124807
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact