2018/08/09 by Markus Miettinen, Miettinen, Markus, Paul C. van Oorschot +3
Computer Science · Engineering · Social Sciences · #Access Control and Trust #Advanced Malware Detection Techniques #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #IoT and Edge/Fog Computing #Mobile Agent-Based Network Management #Smart Grid Security and Resilience
paper · pdf · doi:10.48550/arxiv.1808.03071
openalex publication_date 2018/08/09 · openalex created_date 2022/08/04 · openalex updated_date 2026/07/28
The emerging Internet of Things (IoT) drastically increases the number of\nconnected devices in homes, workplaces and smart city infrastructures. This\ndrives a need for means to not only ensure confidentiality of device-related\ncommunications, but for device configuration and management---ensuring that\nonly legitimate devices are granted privileges to a local domain, that only\nauthorized agents have access to the device and data it holds, and that\nsoftware updates are authentic. The need to support device on-boarding, ongoing\ndevice management and control, and secure decommissioning dictates a suite of\nkey management services for both access control to devices, and access by\ndevices to wireless infrastructure and networked resources. We identify this\ncore functionality, and argue for the recognition of efficient and reliable key\nmanagement support---both within IoT devices, and by a unifying external\nmanagement platform---as a baseline requirement for an IoT world. We present a\nframework architecture to facilitate secure, flexible and convenient device\nmanagement in commodity IoT scenarios, and offer an illustrative set of\nprotocols as a base solution---not to promote specific solution details, but to\nhighlight baseline functionality to help domain owners oversee deployments of\nlarge numbers of independent multi-vendor IoT devices.\n