93
Evolution of Social IoT World
From a research point of view, it is wise to know about the institutions, organizations,
and government alliances, who work and address issues on IoT, SIoT, and its variants (in
particular privacy and threat issues). We list out in Table 5.4 such additional information
sources which may serve as a starting point for further investigations to the interested
researchers concerned.
5.6 Pro-Business and Pro-People Social IoT Services
Social IoT services can be modeled as pro-business and pro-people types. Facebook,
Google, LinkedIn, and similar services are categorized as pro-business models, where
users have to trade privacy for a free service and must agree to be tracked or snooped
to generate a business intelligence database. In pro-people SIoT service, which we will
TABLE 5.3
Research Questionnaires on Security Issues in IoT/Social IoT
• What is the role of technical and operational standards for the development and deployment of secure,
well-behaving IoT devices?
• How do we effectively identify and measure characteristics of IoT device security?
• How do we measure the effectiveness of IoT security initiatives and countermeasures? How do we ensure
security best practices are implemented?
• Would it be possible for regulation to keep pace and be effective in light of evolving IoT technology and
evolving security threats?
• How should regulation be balanced against the needs of permission-less innovation, Internet freedom,
and freedom of expression?
• What is the optimal role of data encryption with respect to IoT devices?
• Is the use of strong encryption, authentication and access control technologies in IoT devices an adequate
solution to prevent eavesdropping and hijacking attacks of the data streams these devices produce?
• Which encryption and authentication technologies could be adapted for the IoT, and how could they be
implemented within an IoT device’s constraints on cost, size, and processing speed?
• Are the end-to-end processes adequately secure and simple enough for typical consumers to use?
• With an extended service life expected for many IoT devices, should devices be designed for
maintainability and upgradeability in the field to adapt to evolving security threats?
• New software and parameter settings could be installed in a fielded IoT device by a centralized security
management system if each device had an integrated device management agent. But management
systems add cost and complexity; could other approaches to upgrading device software be more
compatible with widespread use of IoT devices?
• Are there any classes of IoT devices that are low risk and therefore don’t warrant these kinds of features?
• Are the user interfaces IoT devices expose (usually intentionally minimal) being properly scrutinized with
consideration for device management (by anyone, including the user)?
• What is the right approach to take with obsolete IoT devices as the Internet evolves and security threats
change?
• Should IoT devices be required to have a built-in end-of-life expiration feature (bio-decomposable) that
disables them? Such a requirement could force older, non-interoperable devices out of service and replace
them with more secure and interoperable devices in the future. Certainly, this would be very challenging
in the open marketplace.
• What are the implications of automatic decommissioning of IoT devices?
• How should we protect data collected by IoT that appears not to be personal at the point of collection or
has been “de-identified”, but may at some point in the future become personal data (e.g. because data can
be reidentified or combined with other data)?
Précédent

- 118/358

Suivant