Michela Menting

Protecting Devices From Data Breach: Identity of Things (IDoT)

How to Identify and Authenticate in the Expanding IoT Ecosystem

It is a necessity to protect IoT devices and their associated data. As the IoT ecosystem continues to expand, the need to create an identity to newly-connected things is becoming increasingly crucial. These ‘things’ can include anything from basic sensors and gateways to industrial controls systems, retail terminals and scanners, and kiosks to medical devices, heating and lighting systems, connected homes, and smart cars.

Identity and authentication for the IoT enables the use of foundational information security concepts, including confidentiality, integrity, availability, authentication, and non-repudiation. At the core, identity binds credentials. It allows an operator to well manage IoT devices, define access, set policies, and secure communications to protect devices and data. But within the Identity of Things (IDoT), how does one clearly define the credential and the accompanying authentication and encryption services?

Identity and Access Management

The Cloud Security Alliance (CSA) first raised this issue back in September 2015 when the organization released a Summary Guidance on Identity and Access Management (IAM) for the IoT. Within the document, the CSA emphasized the importance of properly identifying things in order to enable authentication, encryption, and data integrity in an ecosystem. Currently, there are more than 20 different study groups, consortiums, alliances, and standards initiatives working toward creating a secure framework for the IDoT.

connected-iot

(Image Source: Shutterstock)

Issues such as scale, power and computational constraints, ruggedized requirements, energy limitations, increased number and variation of connectivity protocols, and cost factors, among others, make it difficult to simply impose a legacy enterprise IAM or credential management solution. Furthermore, while scenarios for IoT authentication are numerous, there are three notable challenges: token-based authentication currently only works for HTTP, symmetric key mechanisms require input at manufacture, and standard Public Key Infrastructure (PKI) is generally considered impracticable for constrained environments.

Cybersecurity Obstacles 

The three obstacles are ones the cybersecurity industry is working diligently to overcome. For token-based authentication, new methods need to be devised for all the new connectivity vectors (cellular, Bluetooth, Wi-Fi, NFC, RFID, etc.), either as one, convergent authentication method or one for each vector. Both approaches will require significant research and development.

identity

Alternatively, and with some modifications, symmetric key mechanisms can be adapted for the IDoT. For example, Digital Short Range Communications (DSRC), used in vehicle-to-vehicle communications, supports a much smaller certificate structure than the standard X.509. Meanwhile, the use of certificates requires some form of central mechanisms and management structure, such as PKI. In fact, many (and notably certification authorities) tout PKI as the contending standard for identification, encryption, and authentication of IoT devices, but traditional PKI does not scale well for the IoT. A more dynamic key architecture may need to be developed. Essentially the method chosen will depend on the constrained devices in question and their respective environment.

From a private sector perspective, a number of firms are already promoting authentication, identity, and related management services to address the challenges head-on. The movement in the private sector is dynamic, with numerous firms—from startups to big players in the enterprise IAM and authentication and key management space—investing in the IoT market. While some are offering data-centric security platforms for IoT and M2M, others are developing cloud-based IoT security platforms to create and manage digital identities. The solutions are wide-ranging and varied.

In all, the IDoT market opportunity is still nascent, but it is evidently expanding quickly. Most pressing is the development of adapted identity solutions. These solutions will need to revolve around data centric encryption, dynamic certificates and key architecture.

By Michela Menting

Michela Menting

Michela Menting, Research Director at ABI Research, delivers analyses and forecasts concerning digital security. Through this service, she studies the latest solutions in cybersecurity technologies, critical infrastructure protection, risk management and strategies, and opportunities for growth.

Her past experience includes working as a cybersecurity policy analyst for the United Nation’s International Telecommunication Union in Geneva, Switzerland.

Michela obtained both an LLB in English and French Law and an LLM in Information Technology, Media and E-commerce from the University of Essex.

View Website
Is Machine Learning Making Your Data Scientists Obsolete?

Is Machine Learning Making Your Data Scientists Obsolete?

Data Scientists In a recent study, almost all the businesses surveyed stated that big data analytics were fundamental to their ...
The Computer Interface of the Future Is Voice

The Computer Interface of the Future Is Voice

The Computer Interface of the Future Is Voice Only a few years ago, many people viewed voice-recognition technology as something ...
Survey: 87% of Businesses Are Confident About Cybersecurity

Survey: 87% of Businesses Are Confident About Cybersecurity

Businesses Confident About Cybersecurity In a year that has seen multiple massive data breaches and troubling cyberattacks, a new survey ...
Here’s everything you need to know about serverless architectures

Here’s everything you need to know about serverless architectures

Serverless Architectures Serverless is an increasingly popular approach to software development that is growing extremely fast in companies of all ...
IoT Trends

The Internet of Attacks: Disturbing Online IoT Trends

Disturbing Online IoT Trends If you thought the worst thing to come out of the Internet of Things (IoT) trend ...
Big Data Gives Insight to Consumer Trends

Big Data Is a Competitive Advantage in Any Industry

Big Data Competitive Advantage The various ways major companies — and even entire industries — have begun utilizing methods to ...
The Cure for Cloud Sprawl: Nimble Operationalization in the Multi-Cloud

The Cure for Cloud Sprawl: Nimble Operationalization in the Multi-Cloud

The Cure for Cloud Sprawl Enterprises are shifting to a cloud-first footing. That’s no secret. But just as companies and ...
Get Ready For Virtual Reality and the Cloud

Get Ready For Virtual Reality and the Cloud

Virtual Reality Cloud We’re lucky to live in an era where virtual reality is no longer relegated to the confines ...
5 Ways Cloud-based Tools Can Help Accountants Escape The IT Treadmill

5 Ways Cloud-based Tools Can Help Accountants Escape The IT Treadmill

Accountant Cloud Tools Digital tools and software have become an inseparable part of any accountant's profession. There are software for ...
What Futuristic Transportation Will Look Like In Your Lifetime

What Futuristic Transportation Will Look Like In Your Lifetime

Futuristic Transportation Being stuck in traffic or late for work because of a hold up on the dreaded commute could ...