• No results found

Security and Privacy in IoT Challenges to be won

N/A
N/A
Protected

Academic year: 2021

Share "Security and Privacy in IoT Challenges to be won"

Copied!
18
0
0

Loading.... (view fulltext now)

Full text

(1)

DINFO

Dipartimento di Ingegneria dell’Informazione Department of Information Engineering

Security and Privacy in IoT

Challenges to be won

June 16-18, 2015 CHIST-ERA Conference 2015 1

Enrico Del Re

University of Florence and CNIT

Italy

(2)

DINFO

Dipartimento di Ingegneria dell’Informazione Department of Information Engineering

June 16-18, 2015 CHIST-ERA Conference 2015 2

FROM WHERE WE START…..

(3)

DINFO

Dipartimento di Ingegneria dell’Informazione Department of Information Engineering

3

ICT-related activities in Horizon2020 - an Overview

(4)

DINFO

Dipartimento di Ingegneria dell’Informazione Department of Information Engineering

4

ICT-related activities in Horizon2020

(5)

DINFO

Dipartimento di Ingegneria dell’Informazione Department of Information Engineering

5

IEEE ComSoc

Vision of the future top technologies

5G

Fiber everywhere

Virtualization, SDN & NFV

Everywhere connectivity for IoT and IoE

Cognitive networks, Big data

Cybersecurity

Green communications

Smarter smartphones and connected devices

Network neutrality, Internet governance

Molecular communications

(6)

DINFO

Dipartimento di Ingegneria dell’Informazione Department of Information Engineering

6

IEEE CompSoc

Vision of the future top technologies

(7)

DINFO

Dipartimento di Ingegneria dell’Informazione Department of Information Engineering

7

Cloud Computing and Internet of Things

Assumption that the recent steady advances in microelectronics,

communications and information technology will continue into the foreseeable future

CC and IoT potentially can provide breakthroughs and enormous benefits to

the society and persons (e.g. e-Health applications and services to disabled and elderly people, environment control and security,…)

However, technical flaws and threats of intrusions might significantly lower

the benefits of the new developments. Traditional protection techniques are insufficient to guarantee users’ security and privacy within the future

framework

Users not trusting in the new technologies could refuse partially or totally

the new services

Or, worse, they could become the new future slaves of a few big players

(8)

DINFO

Dipartimento di Ingegneria dell’Informazione Department of Information Engineering

June 16-18, 2015 CHIST-ERA Conference 2015 8

Some Security threats in IoT

cloning of smart things by untrusted manufacturers

malicious substitution of smart things during installation firmware replacement attack

extraction of security parameters since smart things may be physically unprotected eavesdropping attack if the communication channel is not adequately protected man-in-the-middle attack during key exchange

routing attacks

denial-of-service attacks privacy threats

(9)

DINFO

Dipartimento di Ingegneria dell’Informazione Department of Information Engineering

June 16-18, 2015 CHIST-ERA Conference 2015 9

Some EU Statements on IoT Security and Privacy

Design from the start to meet:

The right of deletion

The right to be forgotten

Data portability

Privacy and data protection principles

with two general principles

The IoT shall not violate human identity, human integrity,

human rights, privacy or individual or public liberties.

Individuals shall remain in control of their personal data

generated or processed within the IoT, except where this

would conflict with the previous principle.

(10)

DINFO

Dipartimento di Ingegneria dell’Informazione Department of Information Engineering

10

Trustworthy user-centric IoT

Widely acknowledged need to guarantee both technically and regulatory the

neutrality of the future internet

All aspects of security and privacy of the user data must be under the control of

their original owner by means of as simple and efficient technical solutions as possible (user-controlled security)

This challenging technical approach is not the only problem

Different security and privacy applicable laws in different countries Different (i.e. opposite) business views from big players

A fundamental and unbiased (i.e. public) research action on this topic is

necessary built on a holistic view for all IoT elements at all stages

Last but not least, user and social involvement since the beginning for two

main reasons:

• Final users education and awareness of their IoT rights • Technical solutions to satisfy shared and agreed objectives

(11)

DINFO

Dipartimento di Ingegneria dell’Informazione Department of Information Engineering

June 16-18, 2015 CHIST-ERA Conference 2015 11

Information-centric security

Shift from protecting data from the outside (system and applications

which use the data) to protecting data from within

Put intelligence in the data itself

Data needs to be self-describing and defending, regardless of the

environment

Data needs to be encrypted and packaged with a usage policy

When accessed, data should consult its policy and attempt to re-create

a secure environment using virtualization and reveal itself only if the environment is verified as trustworthy

Information-centric security is a natural extension of the trend toward

finer, stronger, and more usable data protection

R. Chow, et al., Controlling Data in the Cloud: Outsourcing Computation without Outsourcing Control, ACM CCSW’09, 2009

(12)

DINFO

Dipartimento di Ingegneria dell’Informazione Department of Information Engineering

June 16-18, 2015 CHIST-ERA Conference 2015 12

…….LOOKING FORWARD…….

(13)

DINFO

Dipartimento di Ingegneria dell’Informazione Department of Information Engineering

June 16-18, 2015 CHIST-ERA Conference 2015 13

Secure Communication: Message Security

How to protect messages confidentiality and integrity?

Lightweight IPsec, Lightweight DTLS, IEEE 802.15.4 Security

Secure Network: Intrusion Detection

How to protect nets from attacks?

new Intrusion Detection Systems (IDSs)

Secure Device: Data Security

How to securely store data?

combining secure storage and communication for

IP6LoWPAN networks

(14)

DINFO

Dipartimento di Ingegneria dell’Informazione Department of Information Engineering

June 16-18, 2015 CHIST-ERA Conference 2015 14

Encryption

Lightweight crypthography

efficiency of E2E communication

applicability to low resource devices

Homomorphic encryption

processing carried out on cyphertext, generating an

encrypted result that, when decrypted, gives the result

of operations performed on the plaintext.

Quantum cryptography

Optical networks

Physical layer cryptography

(15)

DINFO

Dipartimento di Ingegneria dell’Informazione Department of Information Engineering

Information and media authentication

IoT will be more and more populated with contents directly generated

by the users, according to a typical peer-to-peer communication

paradigm.

The ease with which false information can be diffused on the web

increases doubt on the validity of the information gathered “on-line”

as an accurate and trustworthy representation of reality

visual signals are the preferred means to get access to information

immediacy

supposed objectivity

But can we trust visual data?

manipulation of visual data is becoming common

Examples in several fields: propaganda, gossip, fashion …

(16)

DINFO

Dipartimento di Ingegneria dell’Informazione Department of Information Engineering

Multimedia Forensics

It aims at extracting important information on the history of

audio-visual contents

Idea: inherent traces (like digital fingerprints or footprints) are

left behind in a digital media during creation phase and any

further successive processing

These digital traces are extracted for understanding the history of

digital content

2D-3D data protection and anticounterfeiting (watermarking)

(17)

DINFO

Dipartimento di Ingegneria dell’Informazione Department of Information Engineering

Necessary Breakthroughs

Information retrieval and data mining in a big data scenario

contextual and semantic

information to help media

authentication in the extreme heterogeneity of the data

available on the web

Social studies

what

impact on society

of counterfeited information in the web and

mechanisms to minimize such an impact

Social computing

social authentication model

: technological tools with social

computing mechanisms together for information verification

Legal aspects

Ideally same regulations along the whole web

(18)

DINFO

Dipartimento di Ingegneria dell’Informazione Department of Information Engineering

June 16-18, 2015 CHIST-ERA Conference 2015 18

Thank you

for

References

Related documents

Results of the company characteristics show that the effective premium rate of a company’s crop insurance business has a positive relationship with placement of a particular policy

Our counter-factual simulations compare the …tted prices for both unique and common items (…tted from the equilibrium pricing model) under the existing mix of each, to prices that

It was agreed that all areas of the first floor of the Millennium Centre should be included to ensure that the Heritage Centre provided adequate area so that the

However, the risk of death for the different age groups in the institution, as compared with the general population, varied enormously, As seen in Table V, the rate of death of

Using a combined potential ansatz, we derive a singular integral equation with Fredholm operator of index zero from time-harmonic Maxwell’s equations and prove its equivalence to

Two-dimensional (2D) convolutional codes are the generalization of classi- cal convolutional codes by considering polynomial vectors and matrices on 2 variables.. In this sense,

This paper investigates the performance of a cognitive hybrid satellite terrestrial network, where the primary satellite communication network and the secondary terrestrial