Security and Privacy Requirements for the Internet of Things

Security and Privacy Requirements for the Internet of Things
复制标题

物联网的安全和隐私要求

DOI:
--
复制
发表时间:
2021
期刊:
ACM Trans. Internet Things
影响因子:
--
通讯作者:
Charith Perera
Charith Perera
中科院分区:
--
文献类型:
--
作者:
Nada Alhirabi;O. Rana;Charith Perera

文献摘要

被引文献

相似文献

物联网 (IoT) 应用程序的设计和开发过程比桌面、移动或 Web 应用程序更为复杂。首先,物联网应用需要软件和硬件在不同类型、不同条件下具有不同功能的节点上协同工作。其次,物联网应用程序开发涉及桌面、Web、嵌入式和移动等不同类型的软件工程师一起工作。此外,业务分析师等非软件工程人员也参与设计过程。除了让多个软件工程专家合作将不同的硬件和软件组件合并在一起的复杂性之外,开发过程还需要将不同的软件和硬件堆栈集成在一起(例如,来自不同公司的不同堆栈,例如 Microsoft Azure 和 IBM Bluemix)。由于上述复杂性,非功能性需求(例如安全性和隐私性,在物联网环境中非常重要)往往会被忽略或被视为在物联网应用程序开发过程中不太重要。本文回顾了支持现有非物联网应用程序设计中的安全和隐私要求的技术、方法和工具,使其能够使用并集成到物联网应用程序中。本文主要关注有助于捕获非功能性需求(即安全性和隐私)的设计符号、模型和语言。我们的目标不仅是分析、比较和巩固实证研究,还要欣赏他们的研究结果并讨论它们对物联网的适用性。
The design and development process for internet of things (IoT) applications is more complicated than that for desktop, mobile, or web applications. First, IoT applications require both software and hardware to work together across many different types of nodes with different capabilities under different conditions. Second, IoT application development involves different types of software engineers such as desktop, web, embedded, and mobile to work together. Furthermore, non-software engineering personnel such as business analysts are also involved in the design process. In addition to the complexity of having multiple software engineering specialists cooperating to merge different hardware and software components together, the development process requires different software and hardware stacks to be integrated together (e.g., different stacks from different companies such as Microsoft Azure and IBM Bluemix). Due to the above complexities, non-functional requirements (such as security and privacy, which are highly important in the context of the IoT) tend to be ignored or treated as though they are less important in the IoT application development process. This article reviews techniques, methods, and tools to support security and privacy requirements in existing non-IoT application designs, enabling their use and integration into IoT applications. This article primarily focuses on design notations, models, and languages that facilitate capturing non-functional requirements (i.e., security and privacy). Our goal is not only to analyse, compare, and consolidate the empirical research but also to appreciate their findings and discuss their applicability for the IoT.