Authentication in a Body Area Network (Ban) Using Openssl
Total Page:16
File Type:pdf, Size:1020Kb
AUTHENTICATION IN A BODY AREA NETWORK (BAN) USING OPENSSL by Josiah Mololuwa Oyinola Bachelor of ComputEr SciEncE, Ajayi Crowther University, 2016 A Report SubmittEd In Partial FulfillmEnt Of The RequiremEnt For The DEgreE Of MastEr of ComputEr SciEnce In thE GraduatE AcadEmic Unit of ComputEr SciEncE Supervisor(s): Rongxing Lu, Ph.D., ComputEr SciEncE Examining Board: Suprio Ray. Ph.D., ComputEr SciEncE Arash Habibi Lashkari, Ph.D., ComputEr SciEncE This report is accEptEd by the Dean of GraduatE StudiEs THE UNIVERSITY OF NEW BRUNSWICK DEcEmber, 2019 © Josiah Mololuwa Oyinola, 2020 Abstract IntErnet of Things (IoT), which EnablE the connection and communication of objEcts (Things) over the intErnet, have recEived considerablE attention in recEnt years. The internet is the main mEdium (backbone) of communication, whilE the things are smart devicEs, machineriEs, industry lEvel EquipmEnt, Etc., which generatE data to share and procEss for somE intElligent decision making. Ever sincE the tErm IoT was coined out and described by KEvin Ashton in 1999, industriEs have adoptEd the idea of IoT and began intEgrating it into their product developmEnt procEss widely. As a popular application scEnario of IoT, body area network (BAN) is one IoT nEtwork formEd by body sEnsors, which can sEnsE the health relatEd data, deliver the data to the remotE EHEalthcare cEntEr for a bettEr health monitoring through somE gatEways over the IntErnet. HowEver, due to the congestion of the intErnet and the fast rise in cyberattacks, it is very important to sEcure packet Exchange via advancEd lEvel Encryption mEthods to prevent possiblE sEssion hijacking, Man-In- The-MiddlE (MITM) attacks, cross sitE scripting, Etc. FortunatEly, there are numErous Encryption standards availablE. In this study, in order to address the cyber sEcurity issues in body area network, wE will be considering the OpenSSL, one popular software library which is open sourcE for usEr revision. According to openssl.org, OpenSSL is a robust, commErcial-grade, and full-featured toolkit for the Transport Layer SEcurity (TLS) and SEcure Sockets Layer (SSL) protocols. It is also a general- purposE cryptography library, and it is licEnsEd under the Apache-stylE licEnsE which makes it freE to usE by Everyone. ii ConcretEly, the report Examines the OpenSSL cryptographic architEcture, proposE and implEmEnt a “layer-in-layer” lEvel cryptographic model in a bid to sEcure our communication whilE intErfacing with generatEd data betwEEn the BAN and IoT. The study involves dissEcting the sElEctEd authentication procEss, sEEing how it ticks, and why, look into its applications and its sEtbacks. The ultimatE goal of this study is to creatE an Extra layer of sEcurity on the samE tEchnology and put it to usE. It is ExpectEd that this stratEgy will make the authentication algorithm more sEcurE iii Acknowledgements My sincEre gratitude goes first to God who out of His loving kindness made it possiblE for mE to complEtE this report and for his provision sincE I startEd my academic pursuit. I sincErely appreciatE my supervisor Dr Rongxing Lu for his intEllEctual guidancE, advicE and accEssibility. Your height of knowlEdge and ExpertisE with your students is simply excEptional. To my Mother Dr Olufunto Olufolake Alonge who gavE Everything for mE to pursue my mastEr’s degreE, I thank you so much. I am glad that I am gradually making you proud and sEEing you smilE at my achiEvemEnts. My big sistEr Josiah Motunrayo whosE landmarks I have happily followEd, I thank you for your assistancE both monetarily and academically. I would also like to appreciatE my spiritual parents Pastors SEgun and Lola Idahor for their prayers and advicEs, Daddy and Mummy Army—Rtd Major GEneral and Dr US EssiEn whosE inspiration and EncouragemEnt has beEn a positive motivation to my academic pursuit. I also thank my special friEnd, motivator and study partner Mr ToluwalasE Adebayo Adeniji for Encouraging mE when I was down, always being there for mE when I neEded it and lEading mE academically. You always bEliEved in mE Even when you didn’t have to and you supportEd mE throughout this projEct. I also appreciatE Imhoede Jude, OsagiE Ayodeji, Nwolisa Zara, AjEtunmobi Tomilola, Ibiyemi Bukunmi, and Isijola Bunmi, for their moral support and for beliEving in mE iv Table of Contents ABSTRACT ..................................................................................................................... II ACKNOWLEDGEMENTS .......................................................................................... IV LIST OF TABLES ....................................................................................................... VII TABLE 1: PATIENT TABLE .................................................................................... VII TABLE 2: HISTORY TABLE .................................................................................... VII LIST OF FIGURES ................................................................................................... VIII CHAPTER 1 INTRODUCTION .................................................................................... 1 1.1. RESEARCH BACKGROUND ..................................................................................... 1 1.2. RESEARCH PROBLEM ............................................................................................ 5 1.3. PURPOSE OF RESEARCH ........................................................................................ 5 1.4. SIGNIFICANCE OF RESEARCH ................................................................................ 6 1.5. RESEARCH OBJECTIVES ........................................................................................ 6 1.6. ORGANIZATION OF REPORT .................................................................................. 7 1.7. DEFINITION OF TERMS .......................................................................................... 8 CHAPTER 2 LITERATURE REVIEW ...................................................................... 10 2.1. INTRODUCTIONS ................................................................................................. 10 2.2. AUTHENTICATION METHODS [8] ........................................................................ 12 2.2.1 PASSWORD AUTHENTICATION [8] ...................................................................... 12 2.2.2 AUTHENTICATION TOKEN [8] ............................................................................. 13 2.2.3 SYMMETRIC- KEY AUTHENTICATION [8] ........................................................... 14 2.2.4 PUBLIC- KEY AUTHENTICATION:THE DIFFIE-HELLMAN AUTHENTICATION [8] . 15 2.2.5 BIOMETRIC AUTHENTICATION [8] ...................................................................... 16 2.3. IOT ARCHITECTURE ........................................................................................... 19 2.3.1 PERCEPTION LAYER [22] .................................................................................... 22 2.3.2 NETWORK LAYER [22] ....................................................................................... 22 2.3.3 APPLICATION LAYER [22] .................................................................................. 23 2.3.4 BUSINESS LAYER [23] ........................................................................................ 23 2.3.5 PROCESSING LAYER [23] .................................................................................... 24 2.4. IOT SECURITY .................................................................................................... 24 2.5. IOT PASSWORD AUTHENTICATION ..................................................................... 25 2.6. CRYPTOGRAPHY BASED AUTHENTICATION [8] .................................................. 28 CHAPTER 3 RESEARCH METHODOLOGY .......................................................... 30 3.1. INTRODUCTION ................................................................................................... 30 3.2. SYSTEM METHODOLOGY .................................................................................... 30 3.2.1 METHODOLOGY ADOPTED ................................................................................. 30 3.3. RESEARCH MODEL .............................................................................................. 32 3.4. RESEARCH REQUIREMENTS ................................................................................ 34 3.4.1 FRONT END TECHNOLOGIES ............................................................................... 34 3.4.1.1 JAVASCRIPT (REACT JS) ................................................................................. 34 3.4.1.2 CASCADING STYLE SHEET (CSS) ................................................................... 35 v 3.4.1.3 MYSQL WORKBENCH .................................................................................... 35 3.4.2 AUTHENTICATION APPLICATION PROGRAMMING INTERFACE (API) .................. 35 3.4.3 A WIRELESS BODY AREA NETWORK (WBAN) .................................................. 36 3.4.4 CRYPTOGRAPHIC METHOD (OPEN SSL) ............................................................. 38 3.4.5 APPLICATION DATABASE SYSTEMS .................................................................... 43 3.4.5.1 WHAT IS A DBMS? ........................................................................................ 43 3.4.6 DATABASE SCHEMA ........................................................................................... 44 3.4.7 ENTITY RELATIONSHIP DIAGRAM