Reference architecture for secure cloud based remote automation Zero-knowledge initial enrolment of resource-constrained IoT with symbiotic security

被引:0
|
作者
Bartsch, Witali [1 ]
Huebner, Michael [2 ]
机构
[1] PointBlank Secur, Leverkusen, Germany
[2] Brandenburg Tech Univ Cottbus, Cottbus, Germany
来源
ATP MAGAZINE | 2019年 / 09期
关键词
secure embedded architecture; secure key management; secure remote automation; symbiotic security; initial enrolment;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In the first of a series of articles, we introduce the term "Symbiotic Security" to denote an ideal architecture where all essential components (e.g. hardware, software or networks) contribute to raising the architectural security bar. The growing importance of cloud computing for secure and resilient automation and its intended independence from hardware to accommodate all platforms have led us to observe a disconnect between well-known cloud service providers and manufacturers of embedded devices or IoT the unsolved problem of initial enrolment. After elaborating on the root cause of this gulf we present a non-invasive extension and implementation of a cloud IoT reference architecture for an automated, mutually authenticated and encrypted roll-out of IoT nodes. To also enable automated key management without human intervention, the system refrains from using any static secrets usually employed by the hardware vendors - a longstanding point of criticism. Despite our practical choice of a target platform, the idea itself is uniform across such environments given their inherent similarities.
引用
收藏
页码:72 / 81
页数:10
相关论文
共 1 条
  • [1] Integrating Blockchain and Deep Learning Into Extremely Resource-Constrained IoT: An Energy-Saving Zero-Knowledge PoL Approach
    Zhang, Heyi
    Wu, Jun
    Lin, Xi
    Bashir, Ali Kashif
    Al-Otaibi, Yasser D.
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (03) : 3881 - 3895