错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Trusted IoT and Testing

  • Gianmarco Baldini,
  • Sara Nieves Matheu Garcia,
  • Jose L. Hernández-Ramos,
  • Elizabeta Fourneret,
  • Cedric Adjih,
  • Bruno Legeard

摘要

Cybersecurity certification has a long history in the ICT domain, and it originated in the defense domain with the Orange BookOrange Book. However, the IoT context has different requirements and lifecycle compared to ICT defense products, which are designed and tested with a timeframe and a budget much more substantial than the one that can be applied to IoT devices. Therefore, cybersecurity certification concepts and processes must be adapted to the IoT context. In this book chapter, we analyze the challenges associated with the development of a security evaluation and certification framework in the IoT context, as well as the main current certification schemes and initiatives of regulatory bodies and cybersecurity groups, with a special emphasis in Europe. We propose a Cybersecurity Certification methodology specifically designed for IoT products, which takes in consideration the specific deployment lifecycle of IoT devices, their market features and their relationship with the user. The proposed methodology is based on well-recognized ETSI standards, and it introduces additional elements to address the identified challenges for cybersecurity certification.