A decade of research on patterns and architectures for IoT security

被引:8
|
作者
Rajmohan, Tanusan [1 ]
Nguyen, Phu H. [2 ]
Ferry, Nicolas [3 ]
机构
[1] Capgemini, Oslo, Norway
[2] SINTEF, Oslo, Norway
[3] Univ Cote Azur, I3S INRIA Kairos, Sophia Antipolis, France
基金
欧盟地平线“2020”;
关键词
Internet of Things; IoT; Security; Privacy; Architecture; Pattern; Review; SLR; INTERNET; PRIVACY;
D O I
10.1186/s42400-021-00104-7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Security of the Internet of Things (IoT)-based Smart Systems involving sensors, actuators and distributed control loop is of paramount importance but very difficult to address. Security patterns consist of domain-independent time-proven security knowledge and expertise. How are they useful for developing secure IoT-based smart systems? Are there architectures that support IoT security? We aim to systematically review the research work published on patterns and architectures for IoT security (and privacy). Then, we want to provide an analysis on that research landscape to answer our research questions. We follow the well-known guidelines for conducting systematic literature reviews. From thousands of candidate papers initially found in our search process, we have systematically distinguished and analyzed thirty-six (36) papers that have been peer-reviewed and published around patterns and architectures for IoT security and privacy in the last decade (January 2010-December 2020). Our analysis shows that there is a rise in the number of publications tending to patterns and architectures for IoT security in the last three years. We have not seen any approach of applying systematically architectures and patterns together that can address security (and privacy) concerns not only at the architectural level, but also at the network or IoT devices level. We also explored how the research contributions in the primary studies handle the different issues from the OWASP Internet of Things (IoT) top ten vulnerabilities list. Finally, we discuss the current gaps in this research area and how to fill in the gaps for promoting the utilization of patterns for IoT security and privacy by design.
引用
收藏
页数:29
相关论文
共 50 条
  • [41] Protocol Architectures for IoT Domains
    Misic, Jelena
    Ali, M. Zulfiker
    Misic, Vojislav B.
    [J]. IEEE NETWORK, 2018, 32 (04): : 81 - 87
  • [42] A Taxonomy of IoT Client Architectures
    Taivalsaari, Antero
    Mikkonen, Tommi
    [J]. IEEE SOFTWARE, 2018, 35 (03) : 83 - 88
  • [43] A Survey on IoT Application Architectures
    Dauda, Abdulkadir
    Flauzac, Olivier
    Nolot, Florent
    [J]. SENSORS, 2024, 24 (16)
  • [44] A decade of security research in ubiquitous computing: results of a systematic literature review
    Kusen, Ema
    Strembeck, Mark
    [J]. INTERNATIONAL JOURNAL OF PERVASIVE COMPUTING AND COMMUNICATIONS, 2016, 12 (02) : 216 - 259
  • [45] Deriving metrics for software architectures from the "protected entry points" security patterns
    Buitrago, Monica
    Borne, Isabelle
    Buisson, Jeremy
    [J]. 38TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, SAC 2023, 2023, : 1473 - 1475
  • [46] Patterns of research on food security, 2020–2022
    Serge Savary
    [J]. Food Security, 2023, 15 : 1421 - 1429
  • [47] Architectures for Practical Security
    Gligor, Virgil
    [J]. SACMAT 2010: PROCEEDINGS OF THE 15TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2010, : 161 - 161
  • [48] Security in Microservices Architectures
    Mateus-Coelho, Nuno
    Cruz-Cunha, Manuela
    Ferreira, Luis Gonzaga
    [J]. INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS / INTERNATIONAL CONFERENCE ON PROJECT MANAGEMENT / INTERNATIONAL CONFERENCE ON HEALTH AND SOCIAL CARE INFORMATION SYSTEMS AND TECHNOLOGIES 2020 (CENTERIS/PROJMAN/HCIST 2020), 2021, 181 : 1225 - 1236
  • [49] Internet of Things (IOT) in Healthcare - Smart Health and Surveillance, Architectures, Security Analysis and Data Transfer: A Review
    Panchatcharam, Parthasarathy
    Vivekanandan, S.
    [J]. INTERNATIONAL JOURNAL OF SOFTWARE INNOVATION, 2019, 7 (02) : 21 - 40
  • [50] Design and Development of IOT Testbed with DDoS Attack for Cyber Security Research
    Arthi, R.
    Krishnaveni, S.
    [J]. ICSPC'21: 2021 3RD INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND COMMUNICATION (ICPSC), 2021, : 586 - 590