Publishing Service

Polishing & Checking

Frontiers of Information Technology & Electronic Engineering

ISSN 2095-9184 (print), ISSN 2095-9230 (online)

Privacy and security federated reference architecture for Internet of Things

Abstract: Physical objects are getting connected to the Internet at an exceptional rate, making the idea of the Internet of Things (IoT) a reality. The IoT ecosystem is evident everywhere in the form of smart homes, health care systems, wearables, connected vehicles, and industries. This has given rise to risks associated with the privacy and security of systems. Security issues and cyber attacks on IoT devices may potentially hinder the growth of IoT products due to deficiencies in the architecture. To counter these issues, we need to implement privacy and security right from the building blocks of IoT. The IoT architecture has evolved over the years, improving the stack of architecture with new solutions such as scalability, management, interoperability, and extensibility. This emphasizes the need to standardize and organize the IoT reference architecture in federation with privacy and security concerns. In this study, we examine and analyze 12 existing IoT reference architectures to identify their shortcomings on the basis of the requirements addressed in the standards. We propose an architecture, the privacy-federated IoT security reference architecture (PF-IoT-SRA), which interprets all the involved privacy metrics and counters major threats and attacks in the IoT communication environment. It is a step toward the standardization of the domain architecture. We effectively validate our proposed reference architecture using the architecture trade-off analysis method (ATAM), an industry-recognized scenario-based approach.

Key words: Architecturally significant requirement (ASR); Architecture trade-off analysis method (ATAM); Internet architecture board; Internet of Things (IoT); Privacy enhancing technologies; Privacy validation chain

Chinese Summary  <31> 物联网隐私与安全联合参考架构

Musab KAMAL1, Imran RASHID1, Waseem IQBAL1, Muhammad Haroon SIDDIQUI1,
Sohaib KHAN1, Ijaz AHMAD2
1国立科技大学信息安全系,巴基斯坦伊斯兰堡,44000
2马甲大学学院信息技术系,阿曼马斯喀特,112
摘要:各种物体正以惊人速度连接到互联网,使物联网概念成为现实。物联网生态系统正以智能家居、医疗保健系统、可穿戴设备、联网车辆和多种产业形式普及,由此增加了与系统隐私和安全相关的风险。架构缺陷带来的物联网设备安全问题和网络攻击可能阻碍物联网产品的发展。解决这些问题,需在物联网构建块中设置隐私和安全权限。多年来,物联网架构不断演变,通过可测量性、管理、互操作性和可扩展性等新方案改进了架构。为此,亟需结合隐私和安全考量,对物联网参考架构进行标准化和有效管理。本文检查了12个现有物联网参考架构,对照标准中的要求,分析各自不足之处。基于此,提出一种新的架构,即结合隐私的物联网安全参考架构(PF-IoT-SRA),其诠释了物联网通信环境中所有隐私指标,可以对抗主要威胁和攻击。这是朝着领域架构标准化迈出的一步。我们使用架构权衡分析法(ATAM)--一种行业认可的基于场景的方法--验证了所提参考架构的有效性。

关键词组:架构上重要的需求(ASR);架构权衡分析法(ATAM);互联网架构板;物联网;隐私增强技术;隐私验证链


Share this article to: More

Go to Contents

References:

<Show All>

Open peer comments: Debate/Discuss/Question/Opinion

<1>

Please provide your name, email address and a comment





DOI:

10.1631/FITEE.2200368

CLC number:

TP393

Download Full Text:

Click Here

Downloaded:

4930

Download summary:

<Click Here> 

Downloaded:

224

Clicked:

1367

Cited:

0

On-line Access:

2023-05-06

Received:

2022-08-31

Revision Accepted:

2023-05-06

Crosschecked:

2022-12-13

Journal of Zhejiang University-SCIENCE, 38 Zheda Road, Hangzhou 310027, China
Tel: +86-571-87952276; Fax: +86-571-87952331; E-mail: jzus@zju.edu.cn
Copyright © 2000~ Journal of Zhejiang University-SCIENCE