DINFO
Dipartimento di Ingegneria dell’Informazione Department of Information Engineering
Security and Privacy in IoT
Challenges to be won
June 16-18, 2015 CHIST-ERA Conference 2015 1
Enrico Del Re
University of Florence and CNIT
Italy
DINFO
Dipartimento di Ingegneria dell’Informazione Department of Information Engineering
June 16-18, 2015 CHIST-ERA Conference 2015 2
FROM WHERE WE START…..
DINFO
Dipartimento di Ingegneria dell’Informazione Department of Information Engineering
3
ICT-related activities in Horizon2020 - an Overview
DINFO
Dipartimento di Ingegneria dell’Informazione Department of Information Engineering
4
ICT-related activities in Horizon2020
DINFO
Dipartimento di Ingegneria dell’Informazione Department of Information Engineering
5
IEEE ComSoc
Vision of the future top technologies
5G
Fiber everywhere
Virtualization, SDN & NFV
Everywhere connectivity for IoT and IoE
Cognitive networks, Big data
Cybersecurity
Green communications
Smarter smartphones and connected devices
Network neutrality, Internet governance
Molecular communications
DINFO
Dipartimento di Ingegneria dell’Informazione Department of Information Engineering
6
IEEE CompSoc
Vision of the future top technologies
DINFO
Dipartimento di Ingegneria dell’Informazione Department of Information Engineering
7
Cloud Computing and Internet of Things
Assumption that the recent steady advances in microelectronics,
communications and information technology will continue into the foreseeable future
CC and IoT potentially can provide breakthroughs and enormous benefits to
the society and persons (e.g. e-Health applications and services to disabled and elderly people, environment control and security,…)
However, technical flaws and threats of intrusions might significantly lower
the benefits of the new developments. Traditional protection techniques are insufficient to guarantee users’ security and privacy within the future
framework
Users not trusting in the new technologies could refuse partially or totally
the new services
Or, worse, they could become the new future slaves of a few big players
DINFO
Dipartimento di Ingegneria dell’Informazione Department of Information Engineering
June 16-18, 2015 CHIST-ERA Conference 2015 8
Some Security threats in IoT
cloning of smart things by untrusted manufacturers
malicious substitution of smart things during installation firmware replacement attack
extraction of security parameters since smart things may be physically unprotected eavesdropping attack if the communication channel is not adequately protected man-in-the-middle attack during key exchange
routing attacks
denial-of-service attacks privacy threats
DINFO
Dipartimento di Ingegneria dell’Informazione Department of Information Engineering
June 16-18, 2015 CHIST-ERA Conference 2015 9
Some EU Statements on IoT Security and Privacy
Design from the start to meet:
The right of deletion
The right to be forgotten
Data portability
Privacy and data protection principles
with two general principles
The IoT shall not violate human identity, human integrity,
human rights, privacy or individual or public liberties.
Individuals shall remain in control of their personal data
generated or processed within the IoT, except where this
would conflict with the previous principle.
DINFO
Dipartimento di Ingegneria dell’Informazione Department of Information Engineering
10
Trustworthy user-centric IoT
Widely acknowledged need to guarantee both technically and regulatory the
neutrality of the future internet
All aspects of security and privacy of the user data must be under the control of
their original owner by means of as simple and efficient technical solutions as possible (user-controlled security)
This challenging technical approach is not the only problem
Different security and privacy applicable laws in different countries Different (i.e. opposite) business views from big players
A fundamental and unbiased (i.e. public) research action on this topic is
necessary built on a holistic view for all IoT elements at all stages
Last but not least, user and social involvement since the beginning for two
main reasons:
• Final users education and awareness of their IoT rights • Technical solutions to satisfy shared and agreed objectives
DINFO
Dipartimento di Ingegneria dell’Informazione Department of Information Engineering
June 16-18, 2015 CHIST-ERA Conference 2015 11
Information-centric security
Shift from protecting data from the outside (system and applications
which use the data) to protecting data from within
Put intelligence in the data itself
Data needs to be self-describing and defending, regardless of the
environment
Data needs to be encrypted and packaged with a usage policy
When accessed, data should consult its policy and attempt to re-create
a secure environment using virtualization and reveal itself only if the environment is verified as trustworthy
Information-centric security is a natural extension of the trend toward
finer, stronger, and more usable data protection
R. Chow, et al., Controlling Data in the Cloud: Outsourcing Computation without Outsourcing Control, ACM CCSW’09, 2009
DINFO
Dipartimento di Ingegneria dell’Informazione Department of Information Engineering
June 16-18, 2015 CHIST-ERA Conference 2015 12
…….LOOKING FORWARD…….
DINFO
Dipartimento di Ingegneria dell’Informazione Department of Information Engineering
June 16-18, 2015 CHIST-ERA Conference 2015 13
•
Secure Communication: Message Security
–
How to protect messages confidentiality and integrity?
•
Lightweight IPsec, Lightweight DTLS, IEEE 802.15.4 Security
•
Secure Network: Intrusion Detection
–
How to protect nets from attacks?
•
new Intrusion Detection Systems (IDSs)
•
Secure Device: Data Security
–
How to securely store data?
•
combining secure storage and communication for
IP6LoWPAN networks
DINFO
Dipartimento di Ingegneria dell’Informazione Department of Information Engineering
June 16-18, 2015 CHIST-ERA Conference 2015 14
Encryption
Lightweight crypthography
•
efficiency of E2E communication
•
applicability to low resource devices
Homomorphic encryption
•
processing carried out on cyphertext, generating an
encrypted result that, when decrypted, gives the result
of operations performed on the plaintext.
Quantum cryptography
•
Optical networks
Physical layer cryptography
DINFO
Dipartimento di Ingegneria dell’Informazione Department of Information Engineering
Information and media authentication
IoT will be more and more populated with contents directly generated
by the users, according to a typical peer-to-peer communication
paradigm.
The ease with which false information can be diffused on the web
increases doubt on the validity of the information gathered “on-line”
as an accurate and trustworthy representation of reality
visual signals are the preferred means to get access to information
•
immediacy
•
supposed objectivity
But can we trust visual data?
•
manipulation of visual data is becoming common
•
Examples in several fields: propaganda, gossip, fashion …
DINFO
Dipartimento di Ingegneria dell’Informazione Department of Information Engineering
Multimedia Forensics
It aims at extracting important information on the history of
audio-visual contents
Idea: inherent traces (like digital fingerprints or footprints) are
left behind in a digital media during creation phase and any
further successive processing
These digital traces are extracted for understanding the history of
digital content
2D-3D data protection and anticounterfeiting (watermarking)
DINFO
Dipartimento di Ingegneria dell’Informazione Department of Information Engineering
Necessary Breakthroughs
Information retrieval and data mining in a big data scenario
•
contextual and semantic
information to help media
authentication in the extreme heterogeneity of the data
available on the web
Social studies
•
what
impact on society
of counterfeited information in the web and
mechanisms to minimize such an impact
Social computing
•
social authentication model
: technological tools with social
computing mechanisms together for information verification
Legal aspects
•
Ideally same regulations along the whole web
DINFO
Dipartimento di Ingegneria dell’Informazione Department of Information Engineering
June 16-18, 2015 CHIST-ERA Conference 2015 18