Sustainable Security: Exploring Longevity Challenges and Solutions for IoT

Conner Bradley · 2023

The Internet of Things (IoT) has become increasingly integrated with our everyday lives providing physical and direct value to societies across the world.While small embedded devices are increasingly becoming integrated into products by IoT device vendors, so do our concerns about the longevity of these integrations.Unlike generalpurpose computers, IoT devices are expected to be in service for long periods of time.While an IoT device may only need to perform simple tasks over its lifespan, the surrounding networked environment and potential threats will evolve.To ensure that IoT devices remain secure over extended periods and are not compromised by adversaries, they need to be supported throughout their entire lifespan.This places a significant burden on device vendors who are reluctant, and sometimes technically unable to maintain software for decades after deployment.In this thesis, we examine IoT device longevity through the lens of security.Specifically, we are interested in the aspects of IoT device security that limits device longevity.To begin, we focus on understanding the current landscape of software updates in IoT.To our knowledge, software update practices in current IoT devices i are not yet well understood, despite a large body of research aiming to create new methodologies for keeping IoT devices up to date.We then discuss a major shortcoming of current software update systems for IoT, which is characterized by a single point of failure: the IoT device vendor.Without support and updates from the device vendor, the software for the IoT device will become outdated and may experience negative consequences due to the constantly evolving security landscape.To overcome this challenge, we propose a new vendor agility approach for IoT device longevity.This approach would allow devices to receive support from sources beyond their first-party vendors.Finally, we implement part of our vendor agility model to demonstrate feasibility on embedded devices.Our aim is to demonstrate how cross-platform embedded code can be created without the need for proprietary tools.Our proof of concept serves as a starting point for future research and work to break the dependency between devices and vendors, enabling long-term support and security for embedded systems.Finally, I would like to thank my friends and family for their support and encouragement -this milestone would not have been possible without your support.

Read the paper · More papers on PaperTik