An All-Round Secure IoT Network Architecture

Andrea Tulimiero · Repository for Publications and Research Data (ETH Zurich) · 2020

The adoption of the Internet of Things (IoT) is growing steadily and is increasingly becoming more and more widespread every day.As a consequence, we rely on IoT appliances to perform every kind of task: from turning on and off a light with a voice command, to remotely control medical equipment.On the one hand, IoT can hugely improve our lives, but on the other hand, its adoption opens up to a whole new class of threats.It is then paramount that companies and IoT producers consider security a top priority in the realization of their products.However, several recent IoT related security incidents revealed that the security of these devices is sometimes completely ignored.Further inspecting these incidents, we discover that the security of IoT devices shall be achieved first and foremost in the network, which is, at the same time, its major enabler and security weakness.There is a clear need for a system that offers high-security guarantees while posing the lowest effort possible on IoT manufacturers, so to help them adopt security best practices in their production processes.Instead of starting from the network, our analysis follows a bottom-up approach by first systematically defining what security capabilities an IoT environment should meet, as suggested in security guidelines and frameworks from both industry and academia.Then, we realize a network architecture that offers the required services to build a secure IoT environment.The resulting architecture is a combination of LaNeCa and SCION, an intra-and an inter-domain protocol, respectively.The solution, implemented with compatibility and performance in mind, can be integrated by vendors into their products with a minimum effort.iii

Read the paper · More papers on PaperTik