A Survey of IoT Privacy Security: Architecture, Technology, Challenges, and Trends

被引:31
作者
Sun, Panjun [1 ]
Shen, Shigen [2 ]
Wan, Yi [1 ]
Wu, Zongda [1 ]
Fang, Zhaoxi [1 ]
Gao, Xiao-Zhi [3 ]
机构
[1] Shaoxing Univ, Dept Comp Sci & Engn, Shaoxing 312000, Peoples R China
[2] Huzhou Univ, Sch Informat & Engn, Huzhou 313000, Peoples R China
[3] Univ Eastern Finland, Sch Comp, Kuopio 70211, Finland
来源
IEEE INTERNET OF THINGS JOURNAL | 2024年 / 11卷 / 21期
关键词
Privacy; Security; Internet of Things; Authentication; Industrial Internet of Things; Wireless sensor networks; Law; Access control; blockchain; firmware; Internet of Things (IoT); privacy security; WIRELESS SENSOR NETWORKS; ACCESS-CONTROL; INDUSTRIAL INTERNET; DEVICES; THINGS; BLOCKCHAIN; FRAMEWORK; FIRMWARE; ATTACKS; ISSUES;
D O I
10.1109/JIOT.2024.3372518
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Internet of Things (IoT) is used in homes and hospitals and deployed outdoors to control and report environmental changes, prevent fires, and perform many more beneficial functions. However, all these benefits come at the tremendous risk of loss of privacy and security issues. To protect the IoT, much research has been carried out to address these risks and find better ways to eliminate them or at least minimize their impact on user privacy and security requirements. This article expounds various network security risks faced by the IoT, analyzes their impacts, discusses risk assessment methods, shows the causes and hazards of these threats, and proposes an overall framework of privacy security protection. This article summarizes the typical defect types in the implementation of IoT firmware, analyzes the generation mechanism of typical defects from the perspectives of fuzzy testing, program verification and machine learning, and compares and expounds the progress of security research for several common IoT protocols. This article analyzes and summarizes the mainstream access control model in the existing IoT and the access control model after using the blockchain and builds a new integrated AIoT architecture for intelligent information processing. Finally, this article expounds on the current legal development status of the privacy protection of network information in various countries and discusses the future prospects of the IoT.
引用
收藏
页码:34567 / 34591
页数:25
相关论文
共 139 条
  • [1] Privacy-Preserving and Security in SDN-Based IoT: A Survey
    Ahmadvand, Hossein
    Lal, Chhagan
    Hemmati, Hadi
    Sookhak, Mehdi
    Conti, Mauro
    [J]. IEEE ACCESS, 2023, 11 : 44772 - 44786
  • [2] Akestoridis Dimitrios-Georgios, 2020, WiSec '20: Proceedings of the 13th ACM Conference on Security and Privacy in Wireless and Mobile Networks, P77, DOI 10.1145/3395351.3399363
  • [3] AI-Enabled Automation for Completeness Checking of Privacy Policies
    Amaral, Orlando
    Abualhaija, Sallam
    Torre, Damiano
    Sabetzadeh, Mehrdad
    Briand, Lionel C.
    [J]. IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2022, 48 (11) : 4647 - 4674
  • [4] Hybrid Approaches (ABAC and RBAC) Toward Secure Access Control in Smart Home IoT
    Ameer, Safwa
    Benson, James
    Sandhu, Ravi
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (05) : 4032 - 4051
  • [5] [Anonymous], 2020, Data Sheet
  • [6] Visual Surveillance Within the EU General Data Protection Regulation A Technology Perspective
    Asghar, Mamoona N.
    Kanwal, Nadia
    Lee, Brian
    Fleury, Martin
    Herbst, Marco
    Qiao, Yuansong
    [J]. IEEE ACCESS, 2019, 7 : 111709 - 111726
  • [7] ASSURED: Architecture for Secure Software Update of Realistic Embedded Devices
    Asokan, N.
    Nyman, Thomas
    Rattanavipanon, Norrathep
    Sadeghi, Ahmad-Reza
    Tsudik, Gene
    [J]. IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS, 2018, 37 (11) : 2290 - 2300
  • [8] A Machine Learning Security Framework for Iot Systems
    Bagaa, Miloud
    Taleb, Tarik
    Bernabe, Jorge Bernal
    Skarmeta, Antonio
    [J]. IEEE ACCESS, 2020, 8 : 114066 - 114077
  • [9] Tracking GDPR Compliance in Cloud-Based Service Delivery
    Barati, Masoud
    Rana, Omer
    [J]. IEEE TRANSACTIONS ON SERVICES COMPUTING, 2022, 15 (03) : 1498 - 1511
  • [10] GDPR Compliance Verification in Internet of Things
    Barati, Masoud
    Rana, Omer
    Petri, Ioan
    Theodorakopoulos, George
    [J]. IEEE ACCESS, 2020, 8 : 119697 - 119709