Elektro- och informationsteknik

Lunds Tekniska Högskola

Denna sida på svenska This page in English


PhD defence: Contributions to Securing Software Updates in IoT


Tid: 2022-12-16 09:15 till 12:00
Plats: E:1406, E-huset, Ole Römers väg 3, LTH, Lund University, Lund, and online
Kontakt: christian [dot] gehrmann [at] eit [dot] lth [dot] se
Spara händelsen till din kalender

Thesis title: Contributions to Securing Software Updates in IoT

Author: Pegah Nikbaht Bideh, Department of Electrical and Information Technology, Lund university

Faculty opponent:  Professor Valtteri Niemi - University of Helsinki, Finland.

Location: E:1406 E-huset, Ole Römers väg 3, LTH, Lund University, Lund.

Streamed at:

Thesis at LU Research Portal


The Internet of Things (IoT) is a large network of connected devices. In IoT, devices can communicate with each other or back-end systems to transfer data or perform assigned tasks. Communication protocols used in IoT depend on target applications but usually require low bandwidth. On the other hand, IoT devices are constrained, having limited resources, including memory, power, and computational resources. Considering these limitations in IoT environments, it is difficult to implement best security practices. Consequently, network attacks can threaten devices or the data they transfer. Thus it is crucial to react quickly to emerging vulnerabilities.
These vulnerabilities should be mitigated by firmware updates or other necessary updates securely. Since IoT devices usually connect to the network wirelessly, such updates can be performed Over-The-Air (OTA). This dissertation presents contributions to enable secure OTA software updates in IoT.

In order to perform secure updates, vulnerabilities must first be identified and assessed. In this dissertation, first, we present our contribution to designing a maturity model for vulnerability handling. Next, we analyze and compare common communication protocols and security practices regarding energy consumption. Finally, we describe our designed lightweight protocol for OTA updates targeting constrained IoT devices.

IoT devices and back-end systems often use incompatible protocols that are unable to interoperate securely. This dissertation also includes our contribution to designing a secure protocol translator for IoT. This translation is performed inside a Trusted Execution Environment (TEE) with TLS interception.

This dissertation also contains our contribution to key management and key distribution in IoT networks. In performing secure software updates, the IoT devices can be grouped since the updates target a large number of devices. Thus, prior to deploying updates, a group key needs to be established among group members.
In this dissertation, we present our designed secure group key establishment scheme.
Symmetric key cryptography can help to save IoT device resources at the cost of increased key management complexity. This trade-off can be improved by integrating IoT networks with cloud computing and Software Defined Networking (SDN).
In this dissertation, we use SDN in cloud networks to provision symmetric keys efficiently and securely.
These pieces together help software developers and maintainers identify vulnerabilities, provision secret keys, and perform lightweight secure OTA updates. Furthermore, they help devices and systems with incompatible protocols to be able to interoperate.