Safeguarding from abuse by IoT vendors: Edge messages verification of cloud-assisted equipment

2019 IFIP/IEEE Symposium on Integrated Network and Service Management (IM)(2019)

引用 23|浏览85
暂无评分
摘要
The fact that most IoT solutions are provided by 3rd-parties, along with the pervasiveness of the collected data, raises privacy and security concerns. There is a need to verify which data is being sent to the 3rd-party, as well as preventing those channels from becoming an exploitation avenue. We propose to use existing API definition languages to create contracts which define the data that can be transmitted, in what format, and with which constraints. To verify the compliance with these contracts, we propose a converging "Multi-Access Edge Computing" architecture which validates RESTalike API requests/responses against a Swagger schema. We deal with encrypted traffic using an SFC-enabled Man-in-the-Middle, allowing us to do verifications in "real-time". We devised a Proof of Concept and shown that we were able to detect (and stop) contract violations.
更多
查看译文
关键词
safeguarding,IoT vendors,cloud-assisted equipment,IoT solutions,collected data,security concerns,exploitation avenue,privacy concerns,API definition languages,multiaccess edge computing,RESTalike API requests-responses,edge messages verification,encrypted traffic,SFC-enabled man-in-the-middle,Swagger schema,contract violations
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要