Identity and Trust Architecture for Device Lifecycle Management
摘要
The Internet of Things (IoT) paradigm has become widespread, and only expected to increase in magnitude. The need for security and privacy measures adapted to this kind of environments has become apparent. This paper presents a comprehensive identity and trust architecture for managing the lifecycle of IoT devices, developed within the H2020 project ERATOSTHENES. The architecture focuses on secure device identity management, trust evaluations, and seamless interactions within multi-domain IoT environments. As part of the innovation, the solution includes the integration of self-sovereign identity principles and technologies such as Decentralized Identifiers, Verifiable Credentials and distributed ledger technologies. The proposed architecture leverages advanced cryptographic techniques and Physical Unclonable Functions to enhance security and privacy. The identity solution is complemented with a trust framework that continuously evaluates the domain’s participants, establishing a zero-trust approach. This is enhanced with cyberthreat monitoring, sharing and mitigating tools to provide security across different planes. Thus, the framework addresses critical security and privacy requirements withing the lifecycle of devices, ensuring robust and scalable IoT device management from their initial bootstrapping to their decommissioning.