Towards Transparent and Secure IoT: Improving the Security and Privacy through a User-Centric Rules-Based System

In recent years, we have seen a growing wave in the integration of IoT (Internet of Things) technologies into society. This has created new opportunities, but at the same time given rise to several critical issues, creating new challenges that need to be addressed. One of the main challenges is the...

Full description

Bibliographic Details
Main Authors: João Lola, Carlos Serrão, João Casal
Format: Article
Language:English
Published: MDPI AG 2023-06-01
Series:Electronics
Subjects:
Online Access:https://www.mdpi.com/2079-9292/12/12/2589
_version_ 1797595188664729600
author João Lola
Carlos Serrão
João Casal
author_facet João Lola
Carlos Serrão
João Casal
author_sort João Lola
collection DOAJ
description In recent years, we have seen a growing wave in the integration of IoT (Internet of Things) technologies into society. This has created new opportunities, but at the same time given rise to several critical issues, creating new challenges that need to be addressed. One of the main challenges is the security and privacy of information that is processed by IoT devices in our daily lives. Users are, most of the time, unaware of IoT devices’ personal information collection and transmission activities that affect their security and privacy. In this work, we propose a solution that aims to increase the privacy and security of data in IoT devices, through a system that controls the IoT device’s communication on the network. This system is based on two basic and simple principles. First, the IoT device manufacturer declares their device’s data collection intentions. Second, the user declares their own preferences of what is permitted to the IoT device. The design of the system includes tools capable of analyzing packets sent by IoT devices and applying network traffic control rules. The objective is to allow the declaration and verification of communication intentions of IoT devices and control the communication of such devices to detect potential security and privacy violations. We have created a test-bed to validate the developed solution, based on virtual machines, and we concluded that our system has little impact on how the overall system performed.
first_indexed 2024-03-11T02:33:15Z
format Article
id doaj.art-fa9f2e4112be497abfe6683ec7c7a1fc
institution Directory Open Access Journal
issn 2079-9292
language English
last_indexed 2024-03-11T02:33:15Z
publishDate 2023-06-01
publisher MDPI AG
record_format Article
series Electronics
spelling doaj.art-fa9f2e4112be497abfe6683ec7c7a1fc2023-11-18T10:07:53ZengMDPI AGElectronics2079-92922023-06-011212258910.3390/electronics12122589Towards Transparent and Secure IoT: Improving the Security and Privacy through a User-Centric Rules-Based SystemJoão Lola0Carlos Serrão1João Casal2Information Sciences, Technologies and Architecture Research Center (ISTAR), Instituto Universitário de Lisboa (ISCTE-IUL), 1600-189 Lisboa, PortugalInformation Sciences, Technologies and Architecture Research Center (ISTAR), Instituto Universitário de Lisboa (ISCTE-IUL), 1600-189 Lisboa, PortugalSCNL Truphone, S.A., 1700-158 Lisboa, PortugalIn recent years, we have seen a growing wave in the integration of IoT (Internet of Things) technologies into society. This has created new opportunities, but at the same time given rise to several critical issues, creating new challenges that need to be addressed. One of the main challenges is the security and privacy of information that is processed by IoT devices in our daily lives. Users are, most of the time, unaware of IoT devices’ personal information collection and transmission activities that affect their security and privacy. In this work, we propose a solution that aims to increase the privacy and security of data in IoT devices, through a system that controls the IoT device’s communication on the network. This system is based on two basic and simple principles. First, the IoT device manufacturer declares their device’s data collection intentions. Second, the user declares their own preferences of what is permitted to the IoT device. The design of the system includes tools capable of analyzing packets sent by IoT devices and applying network traffic control rules. The objective is to allow the declaration and verification of communication intentions of IoT devices and control the communication of such devices to detect potential security and privacy violations. We have created a test-bed to validate the developed solution, based on virtual machines, and we concluded that our system has little impact on how the overall system performed.https://www.mdpi.com/2079-9292/12/12/2589securityprivacyIoT networksintent declarationcommunication rights and permissionstraffic analysis
spellingShingle João Lola
Carlos Serrão
João Casal
Towards Transparent and Secure IoT: Improving the Security and Privacy through a User-Centric Rules-Based System
Electronics
security
privacy
IoT networks
intent declaration
communication rights and permissions
traffic analysis
title Towards Transparent and Secure IoT: Improving the Security and Privacy through a User-Centric Rules-Based System
title_full Towards Transparent and Secure IoT: Improving the Security and Privacy through a User-Centric Rules-Based System
title_fullStr Towards Transparent and Secure IoT: Improving the Security and Privacy through a User-Centric Rules-Based System
title_full_unstemmed Towards Transparent and Secure IoT: Improving the Security and Privacy through a User-Centric Rules-Based System
title_short Towards Transparent and Secure IoT: Improving the Security and Privacy through a User-Centric Rules-Based System
title_sort towards transparent and secure iot improving the security and privacy through a user centric rules based system
topic security
privacy
IoT networks
intent declaration
communication rights and permissions
traffic analysis
url https://www.mdpi.com/2079-9292/12/12/2589
work_keys_str_mv AT joaolola towardstransparentandsecureiotimprovingthesecurityandprivacythroughausercentricrulesbasedsystem
AT carlosserrao towardstransparentandsecureiotimprovingthesecurityandprivacythroughausercentricrulesbasedsystem
AT joaocasal towardstransparentandsecureiotimprovingthesecurityandprivacythroughausercentricrulesbasedsystem