Security and Privacy Requirements for the Internet of Things

Author:

Alhirabi Nada1ORCID,Rana Omer2,Perera Charith2

Affiliation:

1. Cardiff University, UK and King Saud University, Riyadh, Saudi Arabia

2. Cardiff University, Cardiff, UK

Abstract

The design and development process for internet of things (IoT) applications is more complicated than that for desktop, mobile, or web applications. First, IoT applications require both software and hardware to work together across many different types of nodes with different capabilities under different conditions. Second, IoT application development involves different types of software engineers such as desktop, web, embedded, and mobile to work together. Furthermore, non-software engineering personnel such as business analysts are also involved in the design process. In addition to the complexity of having multiple software engineering specialists cooperating to merge different hardware and software components together, the development process requires different software and hardware stacks to be integrated together (e.g., different stacks from different companies such as Microsoft Azure and IBM Bluemix). Due to the above complexities, non-functional requirements (such as security and privacy, which are highly important in the context of the IoT) tend to be ignored or treated as though they are less important in the IoT application development process. This article reviews techniques, methods, and tools to support security and privacy requirements in existing non-IoT application designs, enabling their use and integration into IoT applications. This article primarily focuses on design notations, models, and languages that facilitate capturing non-functional requirements (i.e., security and privacy). Our goal is not only to analyse, compare, and consolidate the empirical research but also to appreciate their findings and discuss their applicability for the IoT.

Funder

EPSRC PETRAS

EPSRC PACE

Publisher

Association for Computing Machinery (ACM)

Reference129 articles.

1. ISO/IEC JTC 1/SC 27. 2011. ISO/IEC 29100:2011(en): Information technology—Security techniques—Privacy framework. Retrieved from https://www.iso.org/obp/ui/#iso:std:iso-iec:29100:ed-1:v1:en. ISO/IEC JTC 1/SC 27. 2011. ISO/IEC 29100:2011(en): Information technology—Security techniques—Privacy framework. Retrieved from https://www.iso.org/obp/ui/#iso:std:iso-iec:29100:ed-1:v1:en.

2. Evaluation of the Pattern-based method for Secure Development (PbSD): A controlled experiment

3. ProtectMyPrivacy

4. Reconstructing a formal security model

5. Cyber and Physical Security Vulnerability Assessment for IoT-Based Smart Homes

Cited by 28 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Towards a taxonomy of privacy requirements based on the LGPD and ISO/IEC 29100;Information and Software Technology;2024-04

2. UbiMeta: A Ubiquitous Operating System Model for Metaverse;International Journal of Crowd Science;2023-12

3. A hybrid IDS for detection and mitigation of sinkhole attack in 6LoWPAN networks;International Journal of Information Security;2023-11-02

4. Two protocols for improving security during the authentication and key agreement procedure in the 3GPP networks;Computer Communications;2023-11

5. Energy-Aware Dynamic Digital Twin Placement in Mobile Edge Computing;2023 13th International Conference on Computer and Knowledge Engineering (ICCKE);2023-11-01

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3