Making IoT Worthy of Human Trust

Making IoT Worthy of Human Trust
复制标题

DOI:
10.2139/ssrn.3426871
复制
发表时间:
2019-07
期刊:
SSRN Electronic Journal
影响因子:
--
通讯作者:
Hilda Hadan;Nicolás Serrano;Sanchari Das;L. Camp
Hilda Hadan;Nicolás Serrano;Sanchari Das;L. Camp
中科院分区:
其他
文献类型:
--
作者:
Hilda Hadan;Nicolás Serrano;Sanchari Das;L. Camp

文献摘要

相似文献

公钥基础设施(PKI)是在互联网上实现安全和可信交易的基础。PKI受到持续的攻击和定期的改进;例如,密码学的进步已经导致拒绝以前信任的算法(即,SHA1、MD5)。然而,也有组织失败和受信任方的恶意行为。在这项工作中,我们专注于当前X.509 PKI的社会技术组件,目标是更好地了解其漏洞,并为未来PKI的实施提供理想的信息。我们开始从长期的、灾难性的、高影响的或频繁的PKI故障的分类开始。这一分类是通过对PKI的非专家看法的调查和解决物联网安全未来的跨学科研讨会得出的。为了评估失败模式,我们对应用密码学的政策学者和专家进行了定性采访。我们总结了调查和研讨会的结果,并详细介绍了专家访谈。我们的研究结果表明,有重大的失败类型,无论是技术界还是政策界都没有深入参与。这些社区对失败率和严重性的基本假设不同。然而,人们普遍意识到最终用户的脆弱性:需要信任PKI才能与互联网交互和参与的人。我们确定了缓解这些关键问题的紧迫性,因为网络物理系统和物联网(IoT)的采用越来越多。我们的结论是,有必要进行综合的组织、政策和技术协调,以应对长期和潜在的灾难性风险。我们介绍了可能的经济和监管解决方案,并强调了奠定我们未来研究方向的关键要点。
The Public Key Infrastructure (PKI) is the foundation which enables secure and trusted transactions across the Internet. PKI is subject to both continuous attacks and regular improvements; for example, advances in cryptography have led to rejections of previously trusted algorithms (i.e., SHA1, MD5). Yet there have also been organizational failures and malicious acts by trusted parties. In this work, we focus on the sociotechnical components of the current X.509 PKI with the goals of better understanding its vulnerabilities, and ideally informing the implementation of future PKIs. We begin with a taxonomy of chronic, catastrophic, high impact, or frequent PKI failures. This categorization was informed by a survey of non-expert perceptions of PKI and an interdisciplinary workshop addressing the future of security in the Internet of Things. To evaluate the failure modes, we conducted qualitative interviews with policy scholars and experts in applied cryptography. We summarize the results of the survey and workshop, and detail the expert interviews. Our findings indicate that there are significant failure types which neither the technical nor policy community are deeply engaging. The underlying assumptions about rate and severity of failure differ between these communities. Yet there is a common awareness of the vulnerabilities of the end users: the people who are required to trust PKI to interact and engage with the Internet. We identify an urgency in mitigating such critical issues, because of the increasing adoption of cyberphysical systems and the Internet of Things (IoT). We concluded that there is a need for integrated organizational, policy, and technical coordination to address the chronic and potentially catastrophic risks. We introduce possible economic and regulatory solutions, and highlight the key takeaways which pave our future research directions.