The Internet of Things (IoT) paradigm has become widespread, and only expected to increase in magnitude. The need for security and privacy measures adapted to this kind of environments has become apparent. This paper presents a comprehensive identity and trust architecture for managing the lifecycle of IoT devices, developed within the H2020 project ERATOSTHENES. The architecture focuses on secure device identity management, trust evaluations, and seamless interactions within multi-domain IoT environments. As part of the innovation, the solution includes the integration of self-sovereign identity principles and technologies such as Decentralized Identifiers, Verifiable Credentials and distributed ledger technologies. The proposed architecture leverages advanced cryptographic techniques and Physical Unclonable Functions to enhance security and privacy. The identity solution is complemented with a trust framework that continuously evaluates the domain’s participants, establishing a zero-trust approach. This is enhanced with cyberthreat monitoring, sharing and mitigating tools to provide security across different planes. Thus, the framework addresses critical security and privacy requirements withing the lifecycle of devices, ensuring robust and scalable IoT device management from their initial bootstrapping to their decommissioning.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Identity and Trust Architecture for Device Lifecycle Management

  • Agustín Marín Frutos,
  • Jesús García Rodríguez,
  • Antonio Skarmeta,
  • Konstantinos Loupos,
  • Sokratis Vavilis

摘要

The Internet of Things (IoT) paradigm has become widespread, and only expected to increase in magnitude. The need for security and privacy measures adapted to this kind of environments has become apparent. This paper presents a comprehensive identity and trust architecture for managing the lifecycle of IoT devices, developed within the H2020 project ERATOSTHENES. The architecture focuses on secure device identity management, trust evaluations, and seamless interactions within multi-domain IoT environments. As part of the innovation, the solution includes the integration of self-sovereign identity principles and technologies such as Decentralized Identifiers, Verifiable Credentials and distributed ledger technologies. The proposed architecture leverages advanced cryptographic techniques and Physical Unclonable Functions to enhance security and privacy. The identity solution is complemented with a trust framework that continuously evaluates the domain’s participants, establishing a zero-trust approach. This is enhanced with cyberthreat monitoring, sharing and mitigating tools to provide security across different planes. Thus, the framework addresses critical security and privacy requirements withing the lifecycle of devices, ensuring robust and scalable IoT device management from their initial bootstrapping to their decommissioning.