We present a bootstrapping protocol for IoT devices that uses visible light as a second channel for initial authentication with a trusted gateway. This dual-channel approach mitigates man-inthe-middle attacks during device setup. Our system design prioritizes security, simplicity, versatility, and cost-effectiveness using inexpensive components and minimal user interaction. However, it makes the initial bonding step depend on human user interaction thereby ensuring that the ‘human as a firewall’ can be facilitated and user involvement and visible identification of the device is used to gather the user’s consent for the identified device to become authorised. The protocol would be applicable to diverse smart home devices (e. g., light bulbs, speakers) with a visible light source. The protocol establishes authenticated, confidential wireless communication between device and gateway, preventing eavesdropping during the critical bootstrapping phase when device trustworthiness is uncertain.
Pöhls et al. (Thu,) studied this question.