Evaluating Cryptographic Security Requirements in IoT Gateways

被引:0
作者
Felix, Eduardo F. [1 ]
Lins, Fernando A. A. [2 ]
Gomes, Diego R. [1 ]
Nobrega, Obionor O. [2 ]
Jesus, Bruno A. [1 ]
Vieira, Marco [1 ]
机构
[1] Univ Coimbra, Dept Informat Engn, Coimbra, Portugal
[2] Univ Fed Rural Pernambuco, Dept Comp, Recife, Brazil
来源
2023 IEEE 9TH WORLD FORUM ON INTERNET OF THINGS, WF-IOT | 2023年
关键词
Security; Internet of Things; Gateway; Cryptography Requirements;
D O I
10.1109/WF-IOT58464.2023.10539403
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The need to improve the security of devices and systems is widely acknowledged in the context of the Internet of Things (IoT). In theory, users will not adopt IoT solutions without evidence that preventive security measures have been taken to avoid problems such as unlimited data exposure and privacy violations. This is even more relevant when considering IoT gateways, as they act as a central resource for IoT systems to communicate with each other. A key resource is cryptographic security, which aims to improve the level of system protection by assessing the adoption of cryptographic security requirements. This paper presents and discusses the results of a study on the cryptographic security features of several gateways currently used by the IoT community. We discuss the encryption quality levels of these gateways and show that corrective actions must be urgently taken to improve security to an advanced level. The study is based on a solid methodology, described through a BPMN process, to support the engineering of cryptographic security requirements for IoT gateways. The methodology describes how to conduct the requirements adoption assessment, from the search and selection of specific requirements to their verification.
引用
收藏
页数:6
相关论文
共 21 条
  • [1] [Anonymous], 2015, WebIOPi Gateway Documentation
  • [2] [Anonymous], 2018, OTA-IoT Trust by Design
  • [3] [Anonymous], 2017, WebThings Documentation
  • [4] [Anonymous], 2017, Enisa: Baseline security recommendations for IoT
  • [5] [Anonymous], 2020, Nokia threat intelligence report warns of rising cyberattacks on internet-connected devices
  • [6] [Anonymous], 2018, GSMA-GSMA IoT Security Assessment Checklist
  • [7] [Anonymous], 2020, ETSI-releases world-leading Consumer IoT Security standard
  • [8] [Anonymous], 2019, ThingsBoard IoT Gateway Documentation
  • [9] [Anonymous], 1977, Data Encryption Standard (DES)
  • [10] [Anonymous], 2015, Eclipse Kura Documentation