Baseline Requirements for Establishing Trust in Consumable IoT Devices to Achieve Common Criteria Certification

Mohsen Moazen, Sasan Karamizadeh · Research Square · 2023

Abstract The Internet of Things paradigm offers a significant opportunity to improve our lives. Powered by connected applications, consumable IoT devices which are now ubiquitous in businesses, industries, smart homes/cities, traffic monitoring, surveillance, etc. present significant security and privacy risks since they frequently lack robust security features. In this paper, we focused on defining Security Functional Requirements (SFRs) for a final IoT device supplied to end users for an intended use case based on part 2 of the Common Criteria SFRs catalog. A consumable IoT device consists of an end-user connected application running on top of generic hardware, firmware, and/or system software. Thus, we tried to address security requirements not only for the IoT computing platform but also for connected applications of an IoT device. Finally, the proposed requirements can also constitute a framework for security evaluation of consumable IoT devices under the Common Criteria evaluation methodology.

Read the paper · More papers on PaperTik