177
Naming Services in the Internet of Things
to state confidentiality requirements for Ubiquitous Computing (UC) in a rigorous way.
Not only does the what to protect become harder to specify the more concrete a system
becomes in the development process, also the against whom becomes difficult to state precisely for omnipresent, globally connected machines and environments operated by multiple stakeholders, some of which may not even be known in advance. On the other hand,
protection against all potential adversaries seems to be impossible to achieve in practice.
Furthermore, mappings between counter-stakeholders and functional system roles are
not always clear, in addition to the ever-present possibility of external attacks. Counterstakeholders and adversaries usually also differ in the degree of background knowledge
they have available for data analysis, which could abstractly be described by general conditional probability distributions, but seems nearly impossible to quantify for all adversaries during run-time, or in earlier development stages. To cope with those problems, we can
use a pragmatically oriented approach and apply a rule-of-thumb guideline: low-level data
in S should be as hard to collect or analyze as possible.
Consequently, while using the IoT, there will be many situations when the EPC belonging to
an RFID-tagged item should be regarded as sensitive information—be it in a private context,
where people fear to be tracked or have their belongings read by strangers, or in a business
(a)
Confidentiality
goal
Information
Lifestyle
Bob
concerned
Stakeholder
practices
Neighbour
Manufacturer
EPCIS
provider
Local
government
Internet
service
provider
Marketing
company
Counter-stakeholders
Insurance
company
Criminals
Foreign
government
VeriSign
Confidentiality
goal
{Distinct}
Information
Turnover
(b)
Shop
Stakeholder
produces
Shop
Counter-stakeholder
FIGURE 9.5
(a, b) Examples of stakeholders and confidentiality goals.
Naming Services in the Internet of Things
to state confidentiality requirements for Ubiquitous Computing (UC) in a rigorous way.
Not only does the what to protect become harder to specify the more concrete a system
becomes in the development process, also the against whom becomes difficult to state precisely for omnipresent, globally connected machines and environments operated by multiple stakeholders, some of which may not even be known in advance. On the other hand,
protection against all potential adversaries seems to be impossible to achieve in practice.
Furthermore, mappings between counter-stakeholders and functional system roles are
not always clear, in addition to the ever-present possibility of external attacks. Counterstakeholders and adversaries usually also differ in the degree of background knowledge
they have available for data analysis, which could abstractly be described by general conditional probability distributions, but seems nearly impossible to quantify for all adversaries during run-time, or in earlier development stages. To cope with those problems, we can
use a pragmatically oriented approach and apply a rule-of-thumb guideline: low-level data
in S should be as hard to collect or analyze as possible.
Consequently, while using the IoT, there will be many situations when the EPC belonging to
an RFID-tagged item should be regarded as sensitive information—be it in a private context,
where people fear to be tracked or have their belongings read by strangers, or in a business
(a)
Confidentiality
goal
Information
Lifestyle
Bob
concerned
Stakeholder
practices
Neighbour
Manufacturer
EPCIS
provider
Local
government
Internet
service
provider
Marketing
company
Counter-stakeholders
Insurance
company
Criminals
Foreign
government
VeriSign
Confidentiality
goal
{Distinct}
Information
Turnover
(b)
Shop
Stakeholder
produces
Shop
Counter-stakeholder
FIGURE 9.5
(a, b) Examples of stakeholders and confidentiality goals.
