Secure Path-Key Revocation for Symmetric Key Pre-Distribution Schemes in Sensor Networks
Path keys are secrets established between communicating devices that do not share a pre-distributed key. They are required by most key pre-distribution schemes for sensor networks, because topology is unknown before deployment and storing complete pairwise-unique keys is infeasible for low-cost devices such as sensors. Unfortunately, path keys have often been neglected by existing work on sensor network security. In particular, proposals for revoking identified malicious nodes from a sensor network fail to remove any path keys associated with a revoked node. This paper describes a number of resulting attacks which allow a revoked node to continue participating on a network.