Provisioning, Authentication and Secure Communications for IoT Devices on FIWARE

The increasing pervasiveness of the Internet of Things is resulting in a steady increase of cyberattacks in all of its facets. One of the most predominant attack vectors is related to its identity management, as it grants the ability to impersonate and circumvent current trust mechanisms. Given that...

Full description

Bibliographic Details
Main Authors: Patrícia R. Sousa, Luís Magalhães, João S. Resende, Rolando Martins, Luís Antunes
Format: Article
Language:English
Published: MDPI AG 2021-09-01
Series:Sensors
Subjects:
Online Access:https://www.mdpi.com/1424-8220/21/17/5898
_version_ 1797520799829065728
author Patrícia R. Sousa
Luís Magalhães
João S. Resende
Rolando Martins
Luís Antunes
author_facet Patrícia R. Sousa
Luís Magalhães
João S. Resende
Rolando Martins
Luís Antunes
author_sort Patrícia R. Sousa
collection DOAJ
description The increasing pervasiveness of the Internet of Things is resulting in a steady increase of cyberattacks in all of its facets. One of the most predominant attack vectors is related to its identity management, as it grants the ability to impersonate and circumvent current trust mechanisms. Given that identity is paramount to every security mechanism, such as authentication and access control, any vulnerable identity management mechanism undermines any attempt to build secure systems. While digital certificates are one of the most prevalent ways to establish identity and perform authentication, their provision at scale remains open. This provisioning process is usually an arduous task that encompasses device configuration, including identity and key provisioning. Human configuration errors are often the source of many security and privacy issues, so this task should be semi-autonomous to minimize erroneous configurations during this process. In this paper, we propose an identity management (IdM) and authentication method called YubiAuthIoT. The overall provisioning has an average runtime of 1137.8 ms <inline-formula><math display="inline" xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo>±</mo><mspace width="3.33333pt"></mspace><mn>65</mn><mo>.</mo><mn>11</mn><mo>+</mo><mi>δ</mi></mrow></semantics></math></inline-formula>. We integrate this method with the FIWARE platform, as a way to provision and authenticate IoT devices.
first_indexed 2024-03-10T08:03:43Z
format Article
id doaj.art-2c989f6fb41547cea070fcda5d3cc978
institution Directory Open Access Journal
issn 1424-8220
language English
last_indexed 2024-03-10T08:03:43Z
publishDate 2021-09-01
publisher MDPI AG
record_format Article
series Sensors
spelling doaj.art-2c989f6fb41547cea070fcda5d3cc9782023-11-22T11:14:09ZengMDPI AGSensors1424-82202021-09-012117589810.3390/s21175898Provisioning, Authentication and Secure Communications for IoT Devices on FIWAREPatrícia R. Sousa0Luís Magalhães1João S. Resende2Rolando Martins3Luís Antunes4Department of Computer Science, Faculty of Sciences, University of Porto, 4169-007 Porto, PortugalDepartment of Computer Science, Faculty of Sciences, University of Porto, 4169-007 Porto, PortugalDepartment of Computer Science, Faculty of Sciences, University of Porto, 4169-007 Porto, PortugalDepartment of Computer Science, Faculty of Sciences, University of Porto, 4169-007 Porto, PortugalDepartment of Computer Science, Faculty of Sciences, University of Porto, 4169-007 Porto, PortugalThe increasing pervasiveness of the Internet of Things is resulting in a steady increase of cyberattacks in all of its facets. One of the most predominant attack vectors is related to its identity management, as it grants the ability to impersonate and circumvent current trust mechanisms. Given that identity is paramount to every security mechanism, such as authentication and access control, any vulnerable identity management mechanism undermines any attempt to build secure systems. While digital certificates are one of the most prevalent ways to establish identity and perform authentication, their provision at scale remains open. This provisioning process is usually an arduous task that encompasses device configuration, including identity and key provisioning. Human configuration errors are often the source of many security and privacy issues, so this task should be semi-autonomous to minimize erroneous configurations during this process. In this paper, we propose an identity management (IdM) and authentication method called YubiAuthIoT. The overall provisioning has an average runtime of 1137.8 ms <inline-formula><math display="inline" xmlns="http://www.w3.org/1998/Math/MathML"><semantics><mrow><mo>±</mo><mspace width="3.33333pt"></mspace><mn>65</mn><mo>.</mo><mn>11</mn><mo>+</mo><mi>δ</mi></mrow></semantics></math></inline-formula>. We integrate this method with the FIWARE platform, as a way to provision and authenticate IoT devices.https://www.mdpi.com/1424-8220/21/17/5898Internet of ThingsFIWAREauthenticationsecure communicationssmart cities
spellingShingle Patrícia R. Sousa
Luís Magalhães
João S. Resende
Rolando Martins
Luís Antunes
Provisioning, Authentication and Secure Communications for IoT Devices on FIWARE
Sensors
Internet of Things
FIWARE
authentication
secure communications
smart cities
title Provisioning, Authentication and Secure Communications for IoT Devices on FIWARE
title_full Provisioning, Authentication and Secure Communications for IoT Devices on FIWARE
title_fullStr Provisioning, Authentication and Secure Communications for IoT Devices on FIWARE
title_full_unstemmed Provisioning, Authentication and Secure Communications for IoT Devices on FIWARE
title_short Provisioning, Authentication and Secure Communications for IoT Devices on FIWARE
title_sort provisioning authentication and secure communications for iot devices on fiware
topic Internet of Things
FIWARE
authentication
secure communications
smart cities
url https://www.mdpi.com/1424-8220/21/17/5898
work_keys_str_mv AT patriciarsousa provisioningauthenticationandsecurecommunicationsforiotdevicesonfiware
AT luismagalhaes provisioningauthenticationandsecurecommunicationsforiotdevicesonfiware
AT joaosresende provisioningauthenticationandsecurecommunicationsforiotdevicesonfiware
AT rolandomartins provisioningauthenticationandsecurecommunicationsforiotdevicesonfiware
AT luisantunes provisioningauthenticationandsecurecommunicationsforiotdevicesonfiware