In 2014, Hewlett-Packard estimated that as much as 70% of IoT devices were easily hackable. While the number has gone down a bit since then, it hasn’t dropped sufficiently enough the IoT to ignore network security as a concern. While the standard security solution would be an on-system password, this is no longer enough to stop dedicated hackers from gaining access to a network of IoT devices. The IoT‘s existence and reliability as a corporate entity depends on its ability to deal with security. The only way businesses would truly start adopting the technology on a wide scale for more sensitive applications is if the security issues are worked out. But what is the best way for an IoT network to deal with security?
The Need for Reconfigurable Security
The IEEE released a paper in September 2017 regarding the use of a reconfigurable security system to be used across a large number of IoT devices without needing to modify any physical elements of the devices themselves. According to the paper, the standard security solution of authenticated key exchange isn’t enough, but that these devices ought to contain anonymous protection as well as an ability to stave off attacks from malicious IoT devices. The issue that faces IoT‘s in this case is the problem with all devices this small – they just don’t have the processing power nor the transmission energy to develop sophisticated security architecture. The proposed applications of IoT make it necessary to include this level of protection in these devices going forward in order to protect things like details of individuals collected and stored on the IoT network.
Edge Computing Offers a Solution
General Electric Digital notes that edge computing sources have a lot of processing capability now, and can be utilized for processing and filtering of data at component locations. This is what the IEEE paper proposes, utilizing these edge systems to perform the processing necessary to develop a robust security architecture that can aid in bringing a secure IoT to us all, including those distributing hosting coupons for cheap hosting. By using edge systems to generate cryptographic keys and manage the security of the network, the IoT systems become a lot more secure through the simple adoption of edge computing. In order to do this, the edge system would need to have security agents on each of the IoT‘s that perform the dedicated task of managing the security and communicating with the edge server.
Flexibility, Cost Effectiveness and Scalability
This solution of using Security Agents is attractive for a number of reasons. The system is flexible, enabling already deployed IoT devices to use the feature by simply pushing a Security Agent to their architecture from the edge servers. This also means that the cost would be the same since no new features or hardware needs to be added to the IoT device, thereby simplifying the security system. Because it’s based on edge server control, the methodology is immensely scalable, and can be used in as many locations as necessary, once there’s an edge server to support the IoT devices in that location.
A Theoretical Solution
While the idea of implementing these edge computing solutions sounds great in theory, we must remember that theory does not always translate well into practice. By including these security protocols in IoT devices, we will potentially increase the processing time for IoT data, especially on legacy servers. While there would be gains to the security, there is the possibility that it would slow down the IoT data transfer significantly, possibly making it unusable for real-time application. The paper itself states that if authentication isn’t fast enough (like for example on heavy-use networks or for devices too far from the server) the devices will fail to report data, leaving holes in the incoming data and possibly causing anomalies in the processing of that data for gain meaningful insights. As with all technological advances, this one will need some tweaking before it’s ready for general usage.