• DocumentCode
    159553
  • Title

    Enforcement of security policy rules for the Internet of Things

  • Author

    Neisse, Ricardo ; Steri, Gary ; Baldini, Gianmarco

  • Author_Institution
    Eur. Comm. Joint Res. Centre, Ispra, Italy
  • fYear
    2014
  • fDate
    8-10 Oct. 2014
  • Firstpage
    165
  • Lastpage
    172
  • Abstract
    According to the European Union data protection legislation, privacy is a fundamental right that should be protected in the interaction of the citizen with the digital world. In the evolution of Internet towards new paradigms like Internet of Things (IoT), protection of privacy can be a challenging task because IoT connected objects can generate an enormous amount of data, some of which actually constitute personal data. In addition, it is difficult to control the flow of data when there is no user interface or adequate tools for the user. In this paper we describe an efficient solution to enforcement security policy rules that addresses this challenge, and takes a more general enterprise architecture approach for security and privacy engineering in IoT. This enforcement solution is based on a Model-based Security Toolkit named SecKit, and its integration with the MQ Telemetry Transport (MQTT) protocol layer, which is a widely adopted technology to enable the communication between IoT devices. In this paper, we describe the motivation and design of our enforcement solution, demonstrating its feasibility and the performance results in a case study.
  • Keywords
    Internet; Internet of Things; computer network security; data protection; legislation; protocols; telemetry; European Union data protection legislation; Internet; Internet of Things; IoT; MQ telemetry transport protocol layer; MQTT; SecKit; general enterprise architecture approach; model-based security toolkit; privacy engineering; protection of privacy; security policy rule enforcement; Authentication; Authorization; Context; Data privacy; Internet of Things; Enforcement; Internet of Things; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Wireless and Mobile Computing, Networking and Communications (WiMob), 2014 IEEE 10th International Conference on
  • Conference_Location
    Larnaca
  • Type

    conf

  • DOI
    10.1109/WiMOB.2014.6962166
  • Filename
    6962166