Affiliation:
1. Cardiff University, UK and King Saud University, Riyadh, Saudi Arabia
2. Cardiff University, Cardiff, UK
Abstract
The design and development process for internet of things (IoT) applications is more complicated than that for desktop, mobile, or web applications. First, IoT applications require both software and hardware to work together across many different types of nodes with different capabilities under different conditions. Second, IoT application development involves different types of software engineers such as desktop, web, embedded, and mobile to work together. Furthermore, non-software engineering personnel such as business analysts are also involved in the design process. In addition to the complexity of having multiple software engineering specialists cooperating to merge different hardware and software components together, the development process requires different software and hardware stacks to be integrated together (e.g., different stacks from different companies such as Microsoft Azure and IBM Bluemix). Due to the above complexities, non-functional requirements (such as security and privacy, which are highly important in the context of the IoT) tend to be ignored or treated as though they are less important in the IoT application development process. This article reviews techniques, methods, and tools to support security and privacy requirements in existing non-IoT application designs, enabling their use and integration into IoT applications. This article primarily focuses on design notations, models, and languages that facilitate capturing non-functional requirements (i.e., security and privacy). Our goal is not only to analyse, compare, and consolidate the empirical research but also to appreciate their findings and discuss their applicability for the IoT.
Publisher
Association for Computing Machinery (ACM)
Reference129 articles.
1. ISO/IEC JTC 1/SC 27. 2011. ISO/IEC 29100:2011(en): Information technology—Security techniques—Privacy framework. Retrieved from https://www.iso.org/obp/ui/#iso:std:iso-iec:29100:ed-1:v1:en. ISO/IEC JTC 1/SC 27. 2011. ISO/IEC 29100:2011(en): Information technology—Security techniques—Privacy framework. Retrieved from https://www.iso.org/obp/ui/#iso:std:iso-iec:29100:ed-1:v1:en.
2. Evaluation of the Pattern-based method for Secure Development (PbSD): A controlled experiment
3. ProtectMyPrivacy
4. Reconstructing a formal security model
5. Cyber and Physical Security Vulnerability Assessment for IoT-Based Smart Homes
Cited by
39 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献