Secure Registration and Remote Attestation of IoT Devices Joining the Cloud: The Stack4Things Case of Study
Antonio Celesti, Maria Carolina Fazio, Francesco Longo, Giovanni Merlino, Antonio Puliafito · 2017
In recent years, the Internet of Things (IoT) has emerged as one of the hottest trends in information and communication technology (ICT) thanks to the proliferation of field-deployed, dispersed, and heterogeneous sensor- and actuator-hosting platforms. One of the main problems in deploying IoT devices is their secure registration and remote attestation (RA) that is necessary to interconnect them over the Cloud in a secure way. This chapter discusses a reference architecture for secure registration and RA services to join an IoT Cloud provider taking into consideration the aforementioned security capabilities and applying them to an embedded device running Stack4Things (S4T). It also discusses several hardware/software security capabilities that allow an IoT device, such as Arduino YUN, to enforce advanced security mechanisms. The chapter focuses on capabilities such as trusted computing (TC), additional security keys, cryptographic algorithms, and hidden IDs that are useful in developing the security services. It analyzes both board-side and Cloud-side security extensions.