LiSB: Lightweight Secure Boot and Attestation Scheme for IoT and Edge Devices

dc.contributor.authorYounis, Mohamed
dc.contributor.authorEbrahimabadi, Mohammad
dc.contributor.authorSanjana Mehjabin, Suhee
dc.contributor.authorPozniak, Emily
dc.contributor.authorSookoor, Tamim
dc.contributor.authorKarimi, Naghmeh
dc.date.accessioned2025-08-13T20:14:22Z
dc.date.issued2025-07-24
dc.description.abstractWith the increasing popularity of small computing devices and applications of IoT, the need for platform integrity grows both in scale and scope. In particular, the detection of successful attempts to inject a malicious software module or modify an existing one is of utmost importance. This paper promotes LiSB, a novel approach for validating software/firmware integrity and ensuring secure boot-up for resource-constrained embedded devices. LiSB is lightweight, yet very robust. A hardware primitive is used as a Root-of-Trust to support the confidentiality of generated digests and the security of the attestation protocol. Specifically, LiSB employs Physically Unclonable Functions (PUFs) to make the digest device-specific without storing any secrets in the device memory. The performance and robustness of LiSB are validated using a prototype implementation on an FPGA. The results demonstrate that LiSB outperforms recently-published and prominent commercial attestation schemes like TPM, and consumes 25 times less power than SHA-256, which serves as the core component of most existing attestation schemes. The security properties of LiSB are formally analyzed.
dc.description.sponsorshipThis work was supported at the University of Maryland Baltimore County by grant #184825 from Johns Hopkins University Applied Physics Laboratory (JHU-APL). The authors thank Noah Reneau from JHU-APL for fruitful discussion on supporting attestation on the ESP-32 platform.
dc.description.urihttps://ieeexplore.ieee.org/abstract/document/11095728
dc.format.extent16 pages
dc.genrejournal articles
dc.genrepostprints
dc.identifierdoi:10.13016/m2thma-ixoi
dc.identifier.citationYounis, Mohamed, Mohammad Ebrahimabadi, Suhee Sanjana Mehjabin, Emily Pozniak, Tamim Sookoor, and Naghmeh Karimi. “LiSB: Lightweight Secure Boot and Attestation Scheme for IoT and Edge Devices.” IEEE Transactions on Information Forensics and Security, July 24, 2025, 1–1. https://doi.org/10.1109/TIFS.2025.3592573.
dc.identifier.urihttps://doi.org/10.1109/TIFS.2025.3592573
dc.identifier.urihttp://hdl.handle.net/11603/39745
dc.language.isoen
dc.publisherIEEE
dc.relation.isAvailableAtThe University of Maryland, Baltimore County (UMBC)
dc.relation.ispartofUMBC Faculty Collection
dc.relation.ispartofUMBC Student Collection
dc.relation.ispartofUMBC Computer Science and Electrical Engineering Department
dc.rights© 2025 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works
dc.subjectRandom access memory
dc.subjectMathematical models
dc.subjectPerformance evaluation
dc.subjectMicroprogramming
dc.subjectPhysical Unclonable Function
dc.subjectCodes
dc.subjectSoftware Integrity Attestation
dc.subjectSecurity
dc.subjectPhysical unclonable function
dc.subjectSecure Boot
dc.subjectUMBC Cybersecurity Institute
dc.subjectInternet of Things
dc.subjectAuthentication
dc.subjectNonvolatile memory
dc.subjectHardware
dc.titleLiSB: Lightweight Secure Boot and Attestation Scheme for IoT and Edge Devices
dc.typeText
dcterms.creatorhttps://orcid.org/0000-0003-3865-9217
dcterms.creatorhttps://orcid.org/0000-0001-6831-8339
dcterms.creatorhttps://orcid.org/0009-0002-6840-2850
dcterms.creatorhttps://orcid.org/0000-0002-5825-6637

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
LiSB_Lightweight_Secure_Boot_and_Attestation_Scheme_for_IoT_and_Edge_Devices.pdf
Size:
6.18 MB
Format:
Adobe Portable Document Format