Security Evaluation of Authentication Requirements in IoT Gateways

被引:2
|
作者
Gomes, Diego R. R. [1 ]
Lins, Fernando A. Aires [1 ]
Nobrega, Obionor O. O. [1 ]
Felix, Eduardo F. F. [1 ]
Jesus, Bruno A. A. [2 ]
Vieira, Marco [2 ]
机构
[1] Univ Fed Rural Pernambuco, Dept Comp, Recife, Brazil
[2] Univ Coimbra, Dept Informat Engn, Coimbra, Portugal
关键词
Security; Internet of Things; Gateway; Authentication requirements;
D O I
10.1007/s10922-023-09754-z
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In the Internet of Things (IoT) context, gateways are devices that play a strategic role in the communication of things with the external environment. Gateways help with the problem of heterogeneity, acting to carry out the communication of the devices even if they use different protocols. Their centralized and strategic position in an IoT network makes security a key concern, as an attack on this device may leave the entire system vulnerable. Considering the security requirements in IoT, authentication is essential since devices should be authenticated before being inserted into the environment. The main contribution of this paper is the evaluation of the authentication compliance levels of currently used IoT gateways. A methodology is proposed to assess authentication requirements in IoT gateways, making it possible to analyze and select various authentication requirements published by recognized technical organizations such as IoTSF and OWASP. Several gateways currently used were chosen, installed, and configured, and a requirements inspection process was performed. In terms of results, it is possible to observe that, in their default configuration, the current gateways can only meet approximately 66% of the authentication requirements proposed by technical organizations.
引用
收藏
页数:24
相关论文
共 50 条
  • [1] Security Evaluation of Authentication Requirements in IoT Gateways
    Diego R. Gomes
    Fernando A. Aires Lins
    Obionor O. Nóbrega
    Eduardo F. Felix
    Bruno A. Jesus
    Marco Vieira
    [J]. Journal of Network and Systems Management, 2023, 31
  • [2] Compliance Evaluation of Cryptographic Security Requirements on IoT Gateways
    Felix, Eduardo F.
    Lins, Fernando A. A.
    Nobrega, Obionor O.
    Gomes, Diego R.
    Jesus, Bruno A.
    Vieira, Marco
    [J]. PROCEEDINGS OF 2022 11TH LATIN-AMERICAN SYMPOSIUM ON DEPENDABLE COMPUTING, LADC 2022, 2022, : 67 - 72
  • [3] Evaluating Cryptographic Security Requirements in IoT Gateways
    Felix, Eduardo F.
    Lins, Fernando A. A.
    Gomes, Diego R.
    Nobrega, Obionor O.
    Jesus, Bruno A.
    Vieira, Marco
    [J]. 2023 IEEE 9TH WORLD FORUM ON INTERNET OF THINGS, WF-IOT, 2023,
  • [4] Security Requirements and Solutions for IoT Gateways: A Comprehensive Study
    Lins, Fernando A. Aires
    Vieira, Marco
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (11) : 8667 - 8679
  • [5] Sapphire: Using network gateways for IoT security
    Giura, Paul
    Jim, Trevor
    [J]. PROCEEDINGS OF THE 8TH INTERNATIONAL CONFERENCE ON THE INTERNET OF THINGS (IOT'18), 2018,
  • [6] Security Requirements Analysis for the IoT
    Oh, Se-Ra
    Kim, Young-Gab
    [J]. 2017 INTERNATIONAL CONFERENCE ON PLATFORM TECHNOLOGY AND SERVICE (PLATCON), 2017, : 305 - 310
  • [7] Security Implementation for Authentication in IoT Environments
    Rattanalerdnusorn, Ekkachan
    Thaenkaew, Phithak
    Vorakulpipat, Chalee
    [J]. 2019 IEEE 4TH INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATION SYSTEMS (ICCCS 2019), 2019, : 678 - 681
  • [8] Evaluation of Autoscaling Metrics for (stateful) IoT Gateways
    Dickel, Helge
    Podolskiy, Vladimir
    Gerndt, Michael
    [J]. 2019 IEEE 12TH CONFERENCE ON SERVICE-ORIENTED COMPUTING AND APPLICATIONS (SOCA 2019), 2019, : 17 - 24
  • [9] An adaptive authentication and authorization scheme for IoT's gateways: a blockchain based approach
    Fayad, Achraf
    Hammi, Badis
    Khatoun, Rida
    [J]. 2018 THIRD INTERNATIONAL CONFERENCE ON SECURITY OF SMART CITIES, INDUSTRIAL CONTROL SYSTEM AND COMMUNICATIONS (SSIC), 2018,
  • [10] Security Requirements for Internet of Things (IoT)
    Jaiswal, Shruti
    Gupta, Daya
    [J]. PROCEEDINGS OF INTERNATIONAL CONFERENCE ON COMMUNICATION AND NETWORKS, 2017, 508 : 419 - 427