How Does Identity Secure Internet of Things?

1.2K views
•
June 14, 2018
by
RSAC Cybersecurity
YouTube video player
How Does Identity Secure Internet of Things?

TL;DR

IoT security depends on verifying every user, device, software component, and data source before allowing it to influence connected systems. A cohesive identity layer should combine enrollment, authentication, authorization, policy enforcement, integrity protection, resilient local operation, and user control over data collection and sharing, with safeguards matched to the full range of IoT risks.

Transcript

Uh, my name is Rob. Um, my background is in marketing security technologies for chips. Um, I used to work at a company called Arm, where I marketed trust zone security and smart card security. And for the last eighteen months, I've been helping Ping Identity figure out Internet of Things and how identity and access management can solve an awful lot... Read More

Key Insights

  • IoT systems are distinguished by external inputs that can influence connected outputs. A controller once driven only by local sensors may now respond to data from potentially anywhere, increasing the need to establish which sources and actions deserve trust.
  • Business intelligence is the reason organizations connect things, because the stated objective is to cut costs or add value through better decisions. Those decisions remain dependable only when analytics and rules operate on information supplied by trustworthy, properly enrolled sources.
  • An IoT identity layer is responsible for registering users and devices, authenticating them, authorizing their actions, and enforcing policies. A central registry or directory provides the control point for determining which entities belong to the platform.
  • Device identity is needed so each connected thing can communicate with the cloud service in which it is enrolled. Cloud gateways should protect the collection of data by confirming that it originates from known devices rather than blindly accepting every submission.
  • Edge gateways preserve local functionality when cloud services are inaccessible. The Tesla example shows the practical weakness of assuming continuous connectivity when a phone must contact a cloud service before a nearby physical device can respond.
  • Secure device operation requires integrity-checked software, protected code, operating-system privilege separation, secure communications, and embedded firmware that controls startup. Secure boot and integrity checking help ensure that a device runs software recognized as good.
  • Hardware security can protect sensitive, long-lived keys through tamper-resistant components such as SIM cards or embedded SIM cards. Embedded cryptographic modules can also accelerate cryptographic operations efficiently, which matters for battery-powered devices expected to operate for years.
  • Good privacy requires users to control how their devices collect, store, and share data. The description proposes a consistent, interoperable identity layer across IoT platforms, verticals, and protocols, while acknowledging that different risks require appropriately matched security measures.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How does identity management improve IoT security?

Identity management improves IoT security by establishing who or what each user and device is, then controlling what that entity may do. The described architecture uses enrollment, a central registry or directory, authentication, authorization, policy enforcement, device identities, and protected gateways. Together, these controls reduce reliance on blindly trusted data and help ensure that connected outputs respond only to approved sources and actions.

Q: What makes Internet of Things systems difficult to secure?

Internet of Things systems are difficult to secure because inputs from outside a device can affect its software and physical outputs. A simple controller may only process a local sensor, while a connected system can receive information from remote services or potentially anywhere. Security must therefore span cloud analytics, gateways, networks, device software, operating systems, firmware, cryptographic hardware, processor architecture, users, and devices.

Q: Why must IoT platforms validate devices and users?

IoT platforms must validate devices and users because unverified entities can submit deceptive information that changes system behavior. In the Waze demonstration, researchers enrolled ghost devices and users, supplied fake GPS coordinates, and created an artificial traffic jam that caused legitimate users to reroute. The platform did not validate devices, email addresses, social identities, or whether data arrived through a SIM card access point.

Q: What security layers are needed in an IoT architecture?

The presented model contains fifteen layers extending from the cloud to chips inside devices. It includes business intelligence, rules and analytics, device management, registries, authentication, authorization, policies, cloud and edge gateways, device identity, application software, operating systems, communications, embedded firmware, tamper-resistant silicon, cryptographic blocks, and processor-level separation. These layers collectively protect decisions, communications, code, startup, credentials, and sensitive assets.

Q: How should IoT software and firmware be protected?

IoT software should be checked for integrity and protected when it contains sensitive intellectual property. The operating system should separate privileges so one body of user code cannot interfere with another. Embedded firmware should control device startup, secure boot, and integrity checking so the system runs known good software. Communications modules also require protection when connecting the device to a network.

Q: Why do IoT devices need edge gateways and offline operation?

Edge gateways allow connected devices to retain local functionality when the cloud is inaccessible. The Tesla story illustrates the risk of designing access around continuous cloud availability: the phone's request to open the car traveled to a cloud service and then back to the car. When connectivity was unavailable in the desert, two nearby computing devices could not complete the expected access process.

Q: What does the Nest thermostat update show about IoT risk?

The Nest incident shows that IoT harm can result from a flawed authorized update, even without a hack. A firmware bug drained thermostat batteries in 2016. Many residents could recharge and reboot their thermostats after waking to cold homes, but owners relying on thermostats in holiday homes faced more serious consequences, including burst pipes. Update authorization and downstream effects therefore require careful consideration.

Q: How can IoT systems protect security and user privacy?

IoT systems can protect security by identifying devices and users, limiting their permitted actions, validating data sources, enforcing policies, protecting communications, checking software integrity, and securing sensitive keys. Privacy additionally requires giving users control over how devices collect, store, and share information. The description identifies OAuth, UMA, FIDO, and DLTs as existing or emerging tools that may help meet these requirements.

Summary & Key Takeaways

  • Internet of Things systems differ from isolated controllers because external inputs can affect physical outputs. A connected car, for example, may combine local sensors with information supplied by remote services. This expanded trust boundary makes the identity, integrity, and authorization of devices, users, software, and incoming data essential to safe operation.

  • The proposed IoT model contains fifteen layers extending from business intelligence and cloud analytics to device software, operating systems, communications, firmware, tamper-resistant chips, cryptographic blocks, and processor architecture. Identity management connects these layers through device enrollment, directories, authentication, authorization, policy enforcement, gateways, software integrity checks, secure boot, and protected keys.

  • The Waze research demonstration, the Nest thermostat update, and the cloud-dependent Tesla access story illustrate different failures of trust and design. Effective IoT protection therefore requires validated devices and users, controlled software updates, trustworthy data sources, local functionality during cloud outages, and privacy controls governing how device information is collected, stored, and shared.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚