175
Naming Services in the Internet of Things
9.2.1.2 Security Requirements
Someone who places value into an information asset and wants it to be protected is called
a stakeholder of that asset. This definition allows for a generalization of classical security
requirements engineering to the multiple stakeholders of multilateral security [27]. In classic security requirements engineering, for example in parts of the Common Criteria, only
one stakeholder is considered, i.e., the owner of a target of evaluation (ToE) [28].
In the following, we use the classical triad of protection goals, which a stakeholder may
have with respect to an information asset: availability, integrity [29], and confidentiality [30].
We subsume, for example, anonymity under confidentiality of identity, and authenticity
under integrity.
• Availability: The property of being accessible and usable upon demand by an
authorized entity [31]. Alternatively, formulated by avoidance; the prevention of
unauthorized withholding of information or resources.
• Integrity: The property of safeguarding the accuracy and completeness of assets.
That means the prevention of unauthorized modification of information.
• Confidentiality: The property that information is not made available or disclosed
to unauthorized individuals, entities, or processes. That means the prevention of
unauthorized disclosure of information. Extending classical security engineering,
the concept of multilateral security emphasizes the importance of taking the security goals of most or ideally all stakeholders into account before designing and
building a system, not only of system owners or investors. This becomes especially important for confidentiality requirements of system users.
9.2.1.2.1 Availability
The system S, i.e., the IOTNS (Figure 9.4), should be constructed, and its data should be
available to authorized users any time they need to access it. We assume this to be a
requirement shared by all stakeholders. In particular, S should offer robustness to targeted
(Distributed) Denial-of-Service (DDoS) attacks; the system should avoid single points of
failure, and be able to adjust itself to failures of single components (servers or nodes).
9.2.1.2.2 Multipolarity
A specific case of availability concerns the anticipated future role of the IoT as critical IT
infrastructure in many countries. Considered as stakeholders of S, those countries will
Header
Filter
value
Partition
Company prefix
(EPC manager)
Item reference
(object class)
Serial number
8 bits
3 bits
3 bits
Total length: 44 bits
4–24 bits
38 bits
00110000
“SGTiN-96”
001
“retail”
101
“24:20 bits”
4012345 (decimal)
734 (dec.)
2 (dec.)
20–40 bits
FIGURE 9.4
IOTNS function in context.
Naming Services in the Internet of Things
9.2.1.2 Security Requirements
Someone who places value into an information asset and wants it to be protected is called
a stakeholder of that asset. This definition allows for a generalization of classical security
requirements engineering to the multiple stakeholders of multilateral security [27]. In classic security requirements engineering, for example in parts of the Common Criteria, only
one stakeholder is considered, i.e., the owner of a target of evaluation (ToE) [28].
In the following, we use the classical triad of protection goals, which a stakeholder may
have with respect to an information asset: availability, integrity [29], and confidentiality [30].
We subsume, for example, anonymity under confidentiality of identity, and authenticity
under integrity.
• Availability: The property of being accessible and usable upon demand by an
authorized entity [31]. Alternatively, formulated by avoidance; the prevention of
unauthorized withholding of information or resources.
• Integrity: The property of safeguarding the accuracy and completeness of assets.
That means the prevention of unauthorized modification of information.
• Confidentiality: The property that information is not made available or disclosed
to unauthorized individuals, entities, or processes. That means the prevention of
unauthorized disclosure of information. Extending classical security engineering,
the concept of multilateral security emphasizes the importance of taking the security goals of most or ideally all stakeholders into account before designing and
building a system, not only of system owners or investors. This becomes especially important for confidentiality requirements of system users.
9.2.1.2.1 Availability
The system S, i.e., the IOTNS (Figure 9.4), should be constructed, and its data should be
available to authorized users any time they need to access it. We assume this to be a
requirement shared by all stakeholders. In particular, S should offer robustness to targeted
(Distributed) Denial-of-Service (DDoS) attacks; the system should avoid single points of
failure, and be able to adjust itself to failures of single components (servers or nodes).
9.2.1.2.2 Multipolarity
A specific case of availability concerns the anticipated future role of the IoT as critical IT
infrastructure in many countries. Considered as stakeholders of S, those countries will
Header
Filter
value
Partition
Company prefix
(EPC manager)
Item reference
(object class)
Serial number
8 bits
3 bits
3 bits
Total length: 44 bits
4–24 bits
38 bits
00110000
“SGTiN-96”
001
“retail”
101
“24:20 bits”
4012345 (decimal)
734 (dec.)
2 (dec.)
20–40 bits
FIGURE 9.4
IOTNS function in context.
