EVOKE: Efficient Revocation of Verifiable Credentials in IoT Networks

Carlo Mazzocca (University of Bologna), Abbas Acar, Selcuk Uluagac, Rebecca Montanari

33rd USENIX Security Symposium · Day 1 · USENIX Security '24 · USENIX Security '24

Overview

The talk "EVOKE: Efficient Revocation of Verifiable Credentials in IoT Networks" by Carlo Mazzocca from the University of Bologna, in collaboration with Florida International University, introduces a groundbreaking approach to managing trust and identity in the burgeoning landscape of Internet of Things (IoT) devices. As billions of IoT devices connect and generate vast amounts of data, establishing and maintaining trust among them becomes paramount for secure collaboration and effective data utilization by third-party organizations. However, the inherent constraints of IoT networks—such as limited computational power, storage, bandwidth, and intermittent connectivity—pose significant challenges to traditional identity management and credential revocation mechanisms.

Watch on YouTube

Visual summary for EVOKE: Efficient Revocation of Verifiable Credentials in IoT Networks by Carlo Mazzocca, Abbas Acar, Selcuk Uluagac, Rebecca Montanari
Visual summary for EVOKE: Efficient Revocation of Verifiable Credentials in IoT Networks by Carlo Mazzocca, Abbas Acar, Selcuk Uluagac, Rebecca Montanari

Key moments

  1. 0:00 Introduction to IoT identity challenges and decentralization
  2. 1:59 Explaining Verifiable Credentials (VCs) and IoT applicability
  3. 3:16 Limitations of traditional revocation methods for IoT
  4. 4:53 Introducing EVOKE: efficient, constant-size revocation for VCs
  5. 5:50 EVOKE's core mechanism: Elliptic Curve Cryptography Accumulator
  6. 7:20 EVOKE's dynamic update and indirect propagation capabilities

EVOKE: Efficient Revocation of Verifiable Credentials in IoT Networks

Speakers: Carlo Mazzocca, Abbas Acar, Selcuk Uluagac, Rebecca Montanari

Conference: USENIX Security '24

YouTube: https://www.youtube.com/watch?v=J5xq52Bh3HQ

Overview

The talk "EVOKE: Efficient Revocation of Verifiable Credentials in IoT Networks" by Carlo Mazzocca from the University of Bologna, in collaboration with Florida International University, introduces a groundbreaking approach to managing trust and identity in the burgeoning landscape of Internet of Things (IoT) devices. As billions of IoT devices connect and generate vast amounts of data, establishing and maintaining trust among them becomes paramount for secure collaboration and effective data utilization by third-party organizations. However, the inherent constraints of IoT networks—such as limited computational power, storage, bandwidth, and intermittent connectivity—pose significant challenges to traditional identity management and credential revocation mechanisms.

EVOKE directly addresses these challenges by proposing a novel, highly efficient revocation mechanism for Verifiable Credentials (VCs) tailored specifically for resource-constrained IoT environments. Unlike conventional methods that suffer from scalability issues and high overhead, EVOKE leverages advanced cryptographic techniques to provide a constant-sized data structure for revocation information. This innovation allows IoT devices to verify the validity of credentials with minimal computational and storage requirements, thereby enabling robust decentralized identity management even in the most constrained settings.

This work is critical because it paves the way for a more secure and trustworthy IoT ecosystem. By ensuring that compromised or malfunctioning devices can have their credentials swiftly and efficiently revoked, EVOKE enhances the overall security posture of IoT deployments. It offers a practical solution to a long-standing problem in decentralized identity for IoT, promoting greater collaboration and data integrity across diverse and dynamic device networks.

Background

▶ Watch: Introduction to IoT identity challenges and decentralization (0:00)

The proliferation of IoT devices, now numbering in the billions worldwide, has underscored the urgent need for robust identity management systems. These devices generate enormous datasets and often collaborate, requiring mechanisms to identify trusted entities and ensure the integrity of their communications and data contributions. However, the unique characteristics of IoT networks—including devices with limited storage and computing capabilities, frequent connectivity issues, bandwidth constraints, and low transmission ranges—make traditional security solutions largely impractical.

Historically, digital identification methods have fallen into two main categories: centralized and decentralized. Centralized identity management systems, such as those relying on Public Key Infrastructure (PKI) and Certification Authorities (CAs), suffer from inherent drawbacks like low scalability, single points of failure, increased latency, and heavy network dependence. These issues are particularly exacerbated in the dynamic, heterogeneous, and often disconnected nature of IoT environments.

Recognizing these limitations, the Worldwide Web Consortium (W3C) has standardized Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs) as foundational technologies for implementing the "Identity of Things" concept. VCs are digital credentials containing a set of statements about an entity (e.g., an IoT device) that can be cryptographically verified by any third party. Similar to PKI certificates but far more flexible, VCs allow proving authenticity over any type of data. They are issued by trusted entities (e.g., device manufacturers attesting to firmware versions or security compliance) and presented by a holder device to a verifier device. The verifier can then directly retrieve public keys from a verifiable data registry and, through asymmetric encryption, verify both the authenticity and ownership of the credential. This decentralized model aligns well with IoT requirements, offering greater resilience and autonomy.

Despite the promise of VCs, the challenge of credential revocation remains. While similar to PKI certificates, simply extending existing PKI revocation mechanisms to VCs in IoT networks is problematic:

  • Online Certificate Status Protocol (OCSP): Requires a reliable network connection to the issuer for every status query. In IoT, this is difficult to guarantee, and a multitude of devices querying the issuer would introduce remarkable network overhead.
  • Certificate Revocation Lists (CRLs): The issuer periodically distributes a list of revoked credentials. However, the size of these lists grows linearly with the number of revoked credentials, leading to significant storage and network overhead, especially for resource-constrained IoT devices.
  • Bit String Status Lists: An alternative where each VC includes an index referring to a bit in a bit string, indicating revocation status. While more compact than CRLs, the size of this bit string still grows over time with the number of credentials, leading to similar network overhead issues.

These limitations underscore the necessity for a new, efficient revocation mechanism specifically designed for the unique constraints and scale of IoT networks, which EVOKE aims to provide.

Key Findings

▶ Watch: Limitations of traditional revocation methods for IoT (3:16)

EVOKE's fundamental contribution lies in its innovative approach to overcoming the inherent limitations of traditional credential revocation in IoT environments. The core insight of the proposal is to employ a data structure for storing and verifying credential validity that is independent of the number of credentials in the network. This radical departure from existing methods forms the bedrock of EVOKE's efficiency and scalability.

The key findings and contributions of EVOKE include:

  1. Minimal Computing and Storing Overhead: EVOKE drastically reduces the resource footprint required for revocation. Each IoT device needs to store only 1.5 kilobytes of data for the accumulator value and its corresponding witness. This extremely low requirement makes EVOKE viable for even the most constrained IoT devices, which often have limited memory and processing power.
  2. Constant-Sized Revocation Data: By utilizing elliptic curve cryptography accumulators, EVOKE consolidates the revocation status of potentially millions of credentials into a single, fixed-size accumulator value. This ensures that the data size for verification does not grow with the number of issued or revoked credentials, addressing a critical scalability bottleneck of prior methods.
  3. Efficient Verification Time: The time required for a device to verify the validity of a credential using EVOKE is in the order of a few milliseconds. This rapid verification process is crucial for maintaining responsiveness and efficiency in dynamic IoT interactions.
  4. Low Networking Overhead for Updates: The minimal amount of data required for devices to share and update revocation information significantly reduces network bandwidth consumption, a vital aspect in bandwidth-constrained IoT networks.
  5. High Scalability: EVOKE's design ensures that verification time and memory requirements do not depend on the total number of Verifiable Credentials in the system. This makes it inherently scalable to networks with thousands or even millions of IoT devices, as demonstrated in large-scale simulations.
  6. Robust Offline and Indirect Update Mechanism: EVOKE incorporates a sophisticated mechanism for updating revocation information, accommodating devices that may be intermittently connected or in power-saving hibernation. Even in worst-case scenarios, such as when 50% of devices are missing updates, EVOKE is capable of updating nearly the entire network, ensuring that stale revocation information does not compromise security.

In summary, EVOKE provides a highly efficient, scalable, and resource-friendly mechanism for the revocation of Verifiable Credentials in IoT networks, effectively addressing the critical challenges posed by resource constraints and dynamic connectivity.

Technical Deep Dive

▶ Watch: Introducing EVOKE: efficient, constant-size revocation for VCs (4:53)

At the heart of EVOKE's efficiency and scalability lies the judicious application of elliptic curve cryptography accumulators. These cryptographic primitives are designed to accumulate multiple distinct elements into a unique, fixed-size value, known as the accumulator value. This constant size, regardless of the number of elements accumulated, is the key property that differentiates EVOKE from traditional linear-growth revocation schemes.

In EVOKE's architecture, the issuer (e.g., a device manufacturer) accumulates all currently valid Verifiable Credentials (VCs) into a single accumulator value. For each valid VC, the issuer also generates a corresponding witness. This witness is essentially a cryptographic proof of inclusion, demonstrating that a specific VC was part of the set of valid credentials used to compute the current accumulator value. These witnesses are then provided to each device holding a valid VC.

The verification process unfolds as follows: When a holder device needs to prove its authenticity and present a valid VC to another device (the verifier), it provides both its VC and the corresponding witness. The receiving verifier device then combines this information (the VC and its witness) with the latest known accumulator value. If the combination of the VC and witness cryptographically matches the accumulator value, the VC is deemed valid, and the holder device is marked as trusted. This process is highly efficient, requiring minimal computation and storage on the verifier's part, primarily involving cryptographic operations on small, fixed-size data.

The dynamic nature of IoT environments necessitates a robust revocation process. Devices can become compromised, malfunction, or simply be decommissioned, requiring their VCs to be revoked. When a VC needs to be revoked, the issuer performs the following steps:

  1. Updates the accumulator value: The issuer removes the revoked credential from the set of valid VCs and recomputes a new accumulator value.
  2. Recomputes witnesses: Since the accumulator value has changed, all witnesses for the remaining valid VCs must be recomputed to reflect the updated set. These updated witnesses and the new accumulator value are then made available.

A critical aspect of EVOKE is its sophisticated update mechanism, designed to handle the intermittent connectivity common in IoT. There are two primary ways devices receive updates:

  1. Direct Retrieval: Devices with sufficient networking capabilities can directly query a Verifiable Data Registry (VDR). This registry, maintained by the issuer or a trusted entity, stores the latest accumulator value and updated witnesses. Devices can pull this information as needed, ensuring they always operate with the most current revocation status.
  2. Indirect Retrieval (Peer-to-Peer Updates): This mechanism is crucial for devices with limited connectivity or those in power-saving modes. When two devices interact, they exchange their current accumulator version, which is also accompanied by a timestamp. If one device detects that its accumulator version is outdated compared to its peer, it acknowledges this status. Crucially, an outdated device immediately disables trusted communication based on its old accumulator version, preventing potential security exploits where a compromised device might leverage an old, unrevoked credential. The outdated device can then request and receive the updated accumulator value and witnesses from the updated peer, effectively propagating revocation information through the network without direct interaction with the VDR. This peer-to-peer update capability ensures broad and timely dissemination of revocation information, even in partially connected networks.

This intricate interplay of cryptographic accumulators, efficient verification, and a resilient update mechanism allows EVOKE to maintain a consistently accurate and up-to-date revocation status across a large, dynamic, and resource-constrained IoT network.

Demo / Proof of Concept

▶ Watch: EVOKE's core mechanism: Elliptic Curve Cryptography Accumulator (5:50)

The efficacy and efficiency of EVOKE were rigorously evaluated across several realistic IoT settings, moving from individual device performance to large-scale network simulations.

Firstly, EVOKE was tested on commodity IoT devices. Due to programmability constraints on many deeply embedded IoT devices, the initial focus was on devices that supported browser connections, providing a baseline for practical implementation. The results demonstrated the remarkably low resource footprint of EVOKE: each device was required to store only 1.5 kilobytes of data, which includes both the accumulator value and its corresponding witness. Furthermore, the time required for a device to verify the validity of a credential was consistently in the order of a few milliseconds, highlighting the rapid processing capabilities of the system even on constrained hardware.

To overcome the programmability limitations of typical commodity IoT devices and explore more complex network topologies, the researchers then evaluated EVOKE in hybrid networks. This setup involved a star network topology, combining various commercial IoT devices with Raspberry Pi units. In this configuration, the Raspberry Pis served as controllers, acting on behalf of the less capable IoT devices. They implemented the EVOKE functionalities (such as managing accumulator values and witnesses) through their APIs, effectively abstracting the cryptographic complexities from the end devices. This hybrid model is highly relevant to many real-world IoT deployments where gateway devices or edge controllers manage clusters of simpler sensors and actuators.

Within the hybrid network, two key performance metrics were evaluated:

  1. Latency for establishing mutual trust: This measured the time taken for two devices to successfully verify each other's credentials using EVOKE.
  2. End-to-end latency: This assessed the time required to transfer revocation information from one point in the network to another, including the propagation of updated accumulator values and witnesses.

To contextualize these measurements, EVOKE's performance was compared against a baseline scenario. This baseline involved the same network configuration but only transferred a minimal amount of data without performing any cryptographic operations. The comparison revealed that the overhead introduced by EVOKE was only in the order of a few milliseconds, indicating that its cryptographic operations add negligible delay to typical IoT communications.

Finally, recognizing the impracticality of evaluating EVOKE on millions of physical IoT devices, a large-scale analysis was conducted through simulation. This simulation modeled up to 1 million nodes within an IoT network. Key parameters for the simulation included:

  • A yearly revocation rate of 10% of credentials.
  • Each device interacting with five random devices within an hour, simulating typical peer-to-peer communication patterns.
  • Accounting for different percentages of devices missing updates, simulating real-world connectivity challenges.

The simulation results provided crucial insights into the scalability and robustness of EVOKE:

  • The witness generation operation was identified as the most expensive in terms of computational resources. However, it was observed that as a higher number of credentials get revoked over time, the cost of witness generation actually decreases, as there are fewer valid credentials for which witnesses need to be maintained and recomputed.
  • Regarding offline updates (indirect retrieval), the simulation demonstrated remarkable resilience. Even in the worst-case scenario where 50% of devices were missing updates, EVOKE was still able to update nearly the entire network. This highlights the effectiveness of EVOKE's peer-to-peer update mechanism in propagating critical revocation information across intermittently connected and partially updated networks.

These comprehensive evaluations, spanning from individual device performance to large-scale network simulations, robustly validate EVOKE's claims of efficiency, scalability, and resilience in diverse IoT environments.

Defensive Implications

▶ Watch: EVOKE's dynamic update and indirect propagation capabilities (7:20)

EVOKE presents significant defensive implications for the design, deployment, and ongoing management of secure IoT ecosystems. Its novel approach to Verifiable Credential revocation offers powerful tools for defenders looking to enhance trust, mitigate risks, and respond effectively to security incidents in resource-constrained environments.

  1. Enhanced Incident Response and Compromise Mitigation: The most direct defensive benefit of EVOKE is its ability to facilitate rapid and efficient revocation of compromised or misbehaving device credentials. In the event of a device compromise, EVOKE allows the issuer to swiftly revoke the device's VC, preventing it from continuing to operate as a trusted entity. The efficient update mechanism, particularly the indirect peer-to-peer updates, ensures that this revocation information propagates quickly throughout the network, even to intermittently connected devices. This drastically reduces the window of opportunity for attackers to leverage stolen or compromised credentials.
  1. Robust Trust Anchoring in Decentralized Identity: By providing a scalable and resource-efficient revocation mechanism, EVOKE strengthens the overall integrity of decentralized identity (DID) and Verifiable Credential (VC) frameworks in IoT. Defenders can confidently deploy VCs as the primary means of device identity and authentication, knowing that a robust revocation mechanism is in place to manage the lifecycle of these credentials effectively. This moves away from the vulnerabilities of centralized PKI, offering greater resilience against single points of failure.
  1. Minimal Resource Overhead for Security Features: EVOKE's requirement of only 1.5 KB of storage and millisecond-level verification times means that robust security, specifically credential revocation, does not come at the cost of device performance or functionality. This is a critical advantage for IoT devices where every byte of memory and every clock cycle counts. Defenders can integrate this vital security feature without needing to deploy more powerful (and thus more expensive or power-hungry) hardware.
  1. Facilitating Compliance and Regulatory Requirements: Many industry standards and regulations require robust identity and access management, including timely revocation capabilities. EVOKE provides a practical and auditable mechanism to meet these requirements in IoT contexts, helping organizations achieve compliance for their device fleets. The ability to demonstrate efficient and widespread revocation propagation, even with offline devices, is a strong argument for regulatory adherence.
  1. Guidance for IoT Manufacturers and Developers: Manufacturers should consider integrating EVOKE's principles, specifically elliptic curve cryptography accumulators, into their device identity stacks. This would allow them to issue VCs that are inherently revocable in a scalable manner. Developers building IoT applications and platforms should design their systems to leverage EVOKE's update mechanisms, ensuring that devices can both receive direct updates from VDRs and participate in indirect, peer-to-peer revocation information exchange.
  1. Network Design for Resilience: Defenders should design IoT network topologies that facilitate EVOKE's indirect update mechanism. This might involve strategically placing gateway devices or local hubs that can serve as update propagators for clusters of less connected devices. Ensuring some level of peer-to-peer connectivity, even if intermittent, can significantly enhance the speed and reach of revocation propagation.
  1. Proactive Security Posture: EVOKE enables a more proactive security posture by ensuring that trust decisions are always based on the most current revocation status. It helps prevent "zombie" devices—compromised devices that continue to operate with seemingly valid credentials due to delayed or failed revocation—from undermining the network's security.

In essence, EVOKE provides a foundational building block for constructing highly secure and resilient IoT environments, allowing defenders to manage device trust with unprecedented efficiency and scale.

Key Takeaways

  • Efficient Revocation for IoT: EVOKE introduces an innovative and highly efficient mechanism for revoking Verifiable Credentials (VCs) in resource-constrained IoT networks, directly addressing the limitations of traditional PKI revocation schemes (OCSP, CRLs) in such environments.
  • Leverages Cryptographic Accumulators: The core of EVOKE's efficiency is its use of elliptic curve cryptography accumulators, which consolidate revocation information into a constant-sized accumulator value, independent of the number of VCs.
  • Minimal Resource Footprint: EVOKE requires remarkably low resources, with each device needing to store only 1.5 kilobytes of data and verify credentials in a matter of milliseconds, making it viable for even the most constrained IoT devices.
  • Highly Scalable and Resilient: The system is inherently scalable, with verification time and memory requirements not depending on the total number of VCs. Its robust update mechanism, including efficient indirect (peer-to-peer) updates, ensures widespread revocation propagation even when up to 50% of devices are missing direct updates.
  • Enhances Decentralized Identity Security: EVOKE strengthens the "Identity of Things" concept by providing a practical, secure, and scalable way to manage the lifecycle of VCs, enabling timely isolation of compromised devices and fostering greater trust in dynamic IoT ecosystems.
  • Practical for Hybrid Deployments: Demonstrated effective operation in hybrid networks combining commodity IoT devices with more powerful controllers like Raspberry Pis, showcasing its applicability to diverse real-world IoT architectures.

About the Speaker(s)

The primary presenter for "EVOKE: Efficient Revocation of Verifiable Credentials in IoT Networks" was Carlo Mazzocca from the University of Bologna. This work was a joint research effort, involving collaboration with researchers from Florida International University (FIU), specifically Abbas Acar, Selcuk Uluagac, and Rebecca Montanari. The presentation focused on their collective research in developing efficient and scalable security solutions for the unique challenges presented by Internet of Things (IoT) environments.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This research delivers a genuinely novel and highly effective approach to Verifiable Credential revocation in IoT, leveraging elliptic curve cryptography accumulators. It directly addresses critical scalability and resource constraints with a constant-sized data structure and a robust, peer-to-peer update mechanism. This isn't just theoretical; it's a practical, deployable solution that fundamentally improves trust management in constrained environments.

Heather Calloway (CISO) — STRONG ACCEPT

This work presents a robust and scalable solution for a critical governance gap in IoT: efficient credential revocation. EVOKE provides a path to manage trust and untrustworthiness for billions of devices with minimal resource overhead, enabling timely incident response and strengthening decentralized identity frameworks.

→ Top-rated talks at 33rd USENIX Security Symposium

All talks from 33rd USENIX Security Symposium