Compliance Evaluation of Cryptographic Security Requirements on IoT Gateways

被引:0
|
作者
Felix, Eduardo F. [1 ]
Lins, Fernando A. A. [1 ]
Nobrega, Obionor O. [1 ]
Gomes, Diego R. [1 ]
Jesus, Bruno A. [2 ]
Vieira, Marco [2 ]
机构
[1] Univ Fed Rural Pernambuco, Recife, PE, Brazil
[2] Univ Coimbra, Coimbra, Portugal
关键词
Security; Internet of Things; Gateway; Cryptography Requirements;
D O I
10.1145/3569902.3569915
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The Internet of Things is one of the new trends that has been drawing attention due to its rapid dissemination and acceptance. However, not knowing whether personal data and information are secure can hamper a more widespread acceptance of this technology by users. In this context, the security of one of the main components of the IoT system, the gateway, becomes even more relevant, as it is essential in connecting heterogeneous IoT devices. The IoT gateway ends up centralizing communication and system management, thus becoming a high-value target in terms of security. To improve confidentiality, IoT gateways should use cryptographic services implemented with appropriate configurations based on organizations or technical standards accepted by the scientific community. In this context, the main objective of this paper is to evaluate the security level of IoT gateways considering encryption requirements. For this, a subset of encryption requirements suggested by international technical organizations, such as IoTSF and OWASP, is selected. This evaluation was carried out in the security assessment of four IoT gateways considering cryptographic requirements. None of the gateways achieved more than 80% compliance with the selected requirements, which raises concerns regarding the security of their users' data.
引用
收藏
页码:67 / 72
页数:6
相关论文
共 50 条
  • [1] Evaluating Cryptographic Security Requirements in IoT Gateways
    Felix, Eduardo F.
    Lins, Fernando A. A.
    Gomes, Diego R.
    Nobrega, Obionor O.
    Jesus, Bruno A.
    Vieira, Marco
    [J]. 2023 IEEE 9TH WORLD FORUM ON INTERNET OF THINGS, WF-IOT, 2023,
  • [2] Security Evaluation of Authentication Requirements in IoT Gateways
    Gomes, Diego R. R.
    Lins, Fernando A. Aires
    Nobrega, Obionor O. O.
    Felix, Eduardo F. F.
    Jesus, Bruno A. A.
    Vieira, Marco
    [J]. JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2023, 31 (04)
  • [3] Security Evaluation of Authentication Requirements in IoT Gateways
    Diego R. Gomes
    Fernando A. Aires Lins
    Obionor O. Nóbrega
    Eduardo F. Felix
    Bruno A. Jesus
    Marco Vieira
    [J]. Journal of Network and Systems Management, 2023, 31
  • [4] Security Requirements and Solutions for IoT Gateways: A Comprehensive Study
    Lins, Fernando A. Aires
    Vieira, Marco
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (11) : 8667 - 8679
  • [5] Sapphire: Using network gateways for IoT security
    Giura, Paul
    Jim, Trevor
    [J]. PROCEEDINGS OF THE 8TH INTERNATIONAL CONFERENCE ON THE INTERNET OF THINGS (IOT'18), 2018,
  • [6] Security Requirements Analysis for the IoT
    Oh, Se-Ra
    Kim, Young-Gab
    [J]. 2017 INTERNATIONAL CONFERENCE ON PLATFORM TECHNOLOGY AND SERVICE (PLATCON), 2017, : 305 - 310
  • [7] Efficiency and Security Evaluation of Lightweight Cryptographic Algorithms for Resource-Constrained IoT Devices
    Radhakrishnan, Indu
    Jadon, Shruti
    Honnavalli, Prasad B.
    [J]. SENSORS, 2024, 24 (12)
  • [8] Evaluation of Autoscaling Metrics for (stateful) IoT Gateways
    Dickel, Helge
    Podolskiy, Vladimir
    Gerndt, Michael
    [J]. 2019 IEEE 12TH CONFERENCE ON SERVICE-ORIENTED COMPUTING AND APPLICATIONS (SOCA 2019), 2019, : 17 - 24
  • [9] Security Requirements for Internet of Things (IoT)
    Jaiswal, Shruti
    Gupta, Daya
    [J]. PROCEEDINGS OF INTERNATIONAL CONFERENCE ON COMMUNICATION AND NETWORKS, 2017, 508 : 419 - 427
  • [10] A Review of Data Security and Cryptographic Techniques in IoT based devices
    Mustafa, Ghulam
    Ashraf, Rehan
    Mirza, Muhammad Ayzed
    Jamil, Abid
    Muhammad
    [J]. ICFNDS'18: PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON FUTURE NETWORKS AND DISTRIBUTED SYSTEMS, 2018,