Abstract
The exponential growth of Internet-of-Things (IoT) devices and applications may expose tremendous security vulnerabilities in practice, as there are different protocols in the application layer to exchange sensor data, e.g., MQTT, AMQP, CoAP. For the MQTT protocol, IoT devices would publish a plain message that could potentially cause loss of data integrity and data stealing. Motivated by this, we first present a risk assessment on the communication channel between smartphones and IoT using the method of CORAS, which is a model-based security risk analysis framework. Then the paper analyzes several known cryptographic methods and mechanisms to identify which cryptography solution best fits resource constrained IoT devices. Further, we discuss appropriate cryptographic algorithms that can help protect data integrity between smartphones and IoT.
Original language | English |
---|---|
Title of host publication | Proceedings of 12th International Conference on Network and System Security |
Volume | 11058 |
Publisher | Springer |
Publication date | 2018 |
Pages | 251-265 |
ISBN (Print) | 9783030027438 |
DOIs | |
Publication status | Published - 2018 |
Event | 12th International Conference on Network and System Security - Hong Kong Polytechnic University, Hong Kong, China Duration: 27 Aug 2018 → 29 Aug 2018 Conference number: 12 |
Conference
Conference | 12th International Conference on Network and System Security |
---|---|
Number | 12 |
Location | Hong Kong Polytechnic University |
Country/Territory | China |
City | Hong Kong |
Period | 27/08/2018 → 29/08/2018 |
Series | Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) |
---|---|
Volume | 11058 |
ISSN | 0302-9743 |
Keywords
- CORAS
- Data integrity
- Internet-of-Things
- Network security
- Risk assessment
- Smartphone security