416
X. Liu et al.
structure has poor scalability. The problem will become even worse when billions
of new physical objects are to be added to IoT networks in the near future.
The second weakness of the centralized IoT architecture is a single point of
failure, because every physical object is potentially a vulnerable point and can
compromise the security of the entire IoT network. Failure of a single physical
object can potentially bring down the entire IoT network as well.
The third weakness of the centralized IoT architecture is to do with maintenance.
Updating software in the current IoT network is extremely difficult due to the fact
that software updates need to be distributed to a huge number of physical objects
which can be physically located anywhere.
The fourth weakness is related to security and privacy. Data spoofing and
corruption can occur anywhere on the IoT network, ranging from the physical
objects, the communication networks over which IoT data travel through, and the
cloud storage where IoT data are gathered, stored, and processed. Unauthorized
access to personal data in the cloud can happen which has always been the concern
of the general public.
The fifth weakness is that IoT systems frequently use resource-constrained
computing devices such as microcontrollers. These microcontrollers lack the computing power and storage capacity to support advanced and computation-intensive
algorithms which can assist in protecting data security and privacy.
The sixth weakness is that current IoT systems have no immutable records of the
history of interactions among physical objects. Because of this weakness, it is very
difficult to track down the causes if problems do occur.
Another weakness of IoT is that the current centralized structure has only one
copy of the data stored in the cloud. If this copy of data is tampered, there is no
way to know what has been changed. There is no way to prevent the tampering from
happening as well.
Because of these weaknesses, IoT faces the challenge of people lacking trust in
technology, primarily due to their concerns on privacy and security. Their perception
of the scale and complexity of IoT systems makes the situation worse because it
is beyond their comfort zone. Granting device access and control to technological
service providers is frequently a difficult decision and is a sensitive matter for IoT
system owners as well.
IoT devices such as connected actuators are often required to perform actions
according to the commands they receive from the cloud or other IoT devices. If
such commands are hijacked, the consequence could be disastrous. A small example
would be that the door of a house is wrongly opened for a burglar. Improper actions
of devices could also lead to fires and flood in buildings and offices.
Overall, current IoT systems are subject to physical object identity-based attacks,
manipulation-based attacks, cryptanalytic attacks, and service-based attacks.
X. Liu et al.
structure has poor scalability. The problem will become even worse when billions
of new physical objects are to be added to IoT networks in the near future.
The second weakness of the centralized IoT architecture is a single point of
failure, because every physical object is potentially a vulnerable point and can
compromise the security of the entire IoT network. Failure of a single physical
object can potentially bring down the entire IoT network as well.
The third weakness of the centralized IoT architecture is to do with maintenance.
Updating software in the current IoT network is extremely difficult due to the fact
that software updates need to be distributed to a huge number of physical objects
which can be physically located anywhere.
The fourth weakness is related to security and privacy. Data spoofing and
corruption can occur anywhere on the IoT network, ranging from the physical
objects, the communication networks over which IoT data travel through, and the
cloud storage where IoT data are gathered, stored, and processed. Unauthorized
access to personal data in the cloud can happen which has always been the concern
of the general public.
The fifth weakness is that IoT systems frequently use resource-constrained
computing devices such as microcontrollers. These microcontrollers lack the computing power and storage capacity to support advanced and computation-intensive
algorithms which can assist in protecting data security and privacy.
The sixth weakness is that current IoT systems have no immutable records of the
history of interactions among physical objects. Because of this weakness, it is very
difficult to track down the causes if problems do occur.
Another weakness of IoT is that the current centralized structure has only one
copy of the data stored in the cloud. If this copy of data is tampered, there is no
way to know what has been changed. There is no way to prevent the tampering from
happening as well.
Because of these weaknesses, IoT faces the challenge of people lacking trust in
technology, primarily due to their concerns on privacy and security. Their perception
of the scale and complexity of IoT systems makes the situation worse because it
is beyond their comfort zone. Granting device access and control to technological
service providers is frequently a difficult decision and is a sensitive matter for IoT
system owners as well.
IoT devices such as connected actuators are often required to perform actions
according to the commands they receive from the cloud or other IoT devices. If
such commands are hijacked, the consequence could be disastrous. A small example
would be that the door of a house is wrongly opened for a burglar. Improper actions
of devices could also lead to fires and flood in buildings and offices.
Overall, current IoT systems are subject to physical object identity-based attacks,
manipulation-based attacks, cryptanalytic attacks, and service-based attacks.
