Sunday, June 29, 2014

Security and IoT : A reality check!

Ok ,a lot of data is transferred from my devices to servers or my other devices. You know exactly what I am doing, how many steps I walked , when I leave home, whats the temperature of my AC and what not! SO my entire life is out there.  Is this data actually secure? Is it ok to use all nthese fancy devices and gadgets ?

You , your things, your places, your home, your health everything is connected and what if someone has access to it? What if your neighbor plays with your AC settings (:P)
What if it just gets chaotic!!





I have no intentions to scare you. The intention is that we all should be aware of the security concerns threats and definitely what are people working on to prevent those

One thing for sure id  with more and more connected devices, along with convinience comes security issues!

There is always a price to be paid for all the luxuries and comforts you get.. Unfortunately security is the price here...


Lets look at the system architecture here


The architecture is simple, the connected device/thing is connected through a phone, tablet or computer.


Phone or tablet acts as a gateway.
The gateway is connected to cloud.
Where all the processing happens.


The challenges for IoT security is we are looking at multiple protocols or combinations of wireless protocols for data transfer.

Another major hurdle is too many devices communicating at the same time.
Think of it in this way, if you put some grains over a surface area of 10 sq meters, may be 50 pigeons can attack the food. Now you have grains spread over an acre of land, just imagine how many pigeons can compete for food!!

The concept of "exposed surface area" remains the same in the field of IT security too.

In order to secure data, we also cant make the poor small device consume a lot of power and can add limited  processing power on the device

From the device booting up , sending the data to the gateway , authentication during commands and actions, authorization etc all need to be taken into account. Data encryption, secured channels, VPNs  are not going to be sufficient. Its very very complicated field and the pace at which IoT is growing , the security is definitely the biggest challenge ahead