TY - JOUR
T1 - SDPM
T2 - a secure smart device provisioning and monitoring service architecture for smart network infrastructure
AU - Karmakar, Kallol Krishna
AU - Varadharajan, Vijay
AU - Speirs, Pete
AU - Hitchens, Michael
AU - Robertson, Aron
PY - 2022/12/15
Y1 - 2022/12/15
N2 - The Internet of Things (IoT) are becoming a prevalent part of our society offering operational flexibility and convenience. However, insecure provisioning makes the IoT devices susceptible to various cyberattacks. For instance, mal-provisioned devices may leak sensitive information allowing the attackers to eavesdrop or disrupt communication infrastructures. Furthermore, compromised devices can act as zombies to intensify the scale of the attack. Hence, we need secure device provisioning services which can counteract such attacks and adverse circumstances. This article proposes a secure smart device provisioning and monitoring service architecture (SDPM) for smart network infrastructures, such as IoT-enabled smart home or office and Industrial IoT infrastructures. Our architecture allows the provisioning of devices in such a way that the malicious devices can be controlled and their activities using a dynamic policy-based approach. SDPM introduces an IoT device ontology for device registration and authentication and uses the ontology to construct device category and service-specific policies. SDPM provides a fine granular pre and post condition-based policies to provision securely the IoT devices and control their runtime operations. Furthermore, SDPM utilizes the digital twin concept, to monitor dynamically the security status of IoT devices at runtime. The policies associated with a device's twin enables the SDPM to automate security capabilities, such as device firmware updating and patching for security vulnerabilities.
AB - The Internet of Things (IoT) are becoming a prevalent part of our society offering operational flexibility and convenience. However, insecure provisioning makes the IoT devices susceptible to various cyberattacks. For instance, mal-provisioned devices may leak sensitive information allowing the attackers to eavesdrop or disrupt communication infrastructures. Furthermore, compromised devices can act as zombies to intensify the scale of the attack. Hence, we need secure device provisioning services which can counteract such attacks and adverse circumstances. This article proposes a secure smart device provisioning and monitoring service architecture (SDPM) for smart network infrastructures, such as IoT-enabled smart home or office and Industrial IoT infrastructures. Our architecture allows the provisioning of devices in such a way that the malicious devices can be controlled and their activities using a dynamic policy-based approach. SDPM introduces an IoT device ontology for device registration and authentication and uses the ontology to construct device category and service-specific policies. SDPM provides a fine granular pre and post condition-based policies to provision securely the IoT devices and control their runtime operations. Furthermore, SDPM utilizes the digital twin concept, to monitor dynamically the security status of IoT devices at runtime. The policies associated with a device's twin enables the SDPM to automate security capabilities, such as device firmware updating and patching for security vulnerabilities.
UR - http://www.scopus.com/inward/record.url?scp=85135744554&partnerID=8YFLogxK
U2 - 10.1109/JIOT.2022.3195227
DO - 10.1109/JIOT.2022.3195227
M3 - Article
AN - SCOPUS:85135744554
SN - 2327-4662
VL - 9
SP - 25037
EP - 25051
JO - IEEE Internet of Things Journal
JF - IEEE Internet of Things Journal
IS - 24
ER -