Towards Trusted Apps for the Internet of Things



Similar documents
Enterprise Application Enablement for the Internet of Things

Mobile App Testing Process INFLECTICA TECHNOLOGIES (P) LTD

Seedling Internet of Things (IoT) and Wearables Platform

An Advanced Performance Architecture for Salesforce Native Applications

Principles of a Vehicle Infotainment Platform

KURA M2M/IoT Gateway. reducing the distance between embedded and enterprise technologies. Tiziano Modotti, October 28 th, 2014

Dr. Dimitar Valtchev. 24 June 2010, Stuttgart, Eclipse Embedded Day

The Internet of Things: Opportunities & Challenges

ARTIK TM. MyungKoo Kang (VP) The Ultimate Platform Solution for IoT. Samsung Electronics

GETTING STARTED WITH ANDROID DEVELOPMENT FOR EMBEDDED SYSTEMS

IoT R&I on IoT integration and platforms INTERNET OF THINGS FOCUS AREA

Adaptive Intelligent Firewall - der nächste Entwicklungssprung der NGFW. Jürgen Seitz Systems Engineering Manager

Connect for new business opportunities

Cloud Computing Technology

Beschleunigen Sie die Entwicklung Ihrer Embedded Software mit Dienstleistungen von Vector

Hardware in the Loop (HIL) Testing VU 2.0, , WS 2008/09

A Systems of Systems. The Internet of Things. perspective on. Johan Lukkien. Eindhoven University

Delivering secure, real-time business insights for the Industrial world

Software Defined Security Mechanisms for Critical Infrastructure Management

Image Area. White Paper. Best Practices in Mobile Application Testing. - Mohan Kumar, Manish Chauhan.

2015 MicroDoc GmbH, München Java and IoT from a MicroDoc perspective

Cloud-Security: Show-Stopper or Enabling Technology?

Essential Elements of an IoT Core Platform

Key Challenges in Cloud Computing to Enable Future Internet of Things

CHANCES AND RISKS FOR SECURITY IN MULTICORE PROCESSORS

SEACW DELIVERABLE D.1.6

Customer Experience. Silicon. Support & Professional Eng. Services. Freescale Provided SW & Solutions

Java and the Internet of Things

Moderne Sicherheit. Fokussiert auf Business Continuity, Mobilität & Application Control. Marc Mathys Country Manager Switzerland

Reducing Configuration Complexity with Next Gen IoT Networks

Systems Manager Cloud Based Mobile Device Management

NanopowerCommunications: Enabling the Internet of Things OBJECTS TALK

Cisco Solutions for Big Data and Analytics

FWD. What the Internet of Things will mean for business

Dell Wyse Cloud Connect

Application Framework: Apertis Hands-on

In the pursuit of becoming smart

IoT in Production. Dr. Verena Majuntke, Bosch Software Innovations. Bosch Software Innovations

Microsoft in Automotive and the Future of Connected Vehicle Consumer Experiences

Multi Vendor Software in the Self-Service environment. Arindam Laha Vice President Professional Services, Asia Pacific Diebold

How can the Future Internet enable Smart Energy?

Internet of Things. Key Enabler for the Digital Economy. Luis Jaraquemada VP Technology Huawei Chile

Internet of Things Michael Björkman, Technical Director, Marketing, Vacon Plc

Reimagining Business with SAP HANA Cloud Platform for the Internet of Things

CHECK POINT Mobile Security Revolutionized. [Restricted] ONLY for designated groups and individuals

From a World-Wide Web of Pages to a World-Wide Web of Things

Mobile Device and Application Strategy. Right Technology, Right Design, Right Price

IaaS Cloud Architectures: Virtualized Data Centers to Federated Cloud Infrastructures

Do AUTOSAR and functional safety rule each other out?

FTP-Stream Data Sheet

Opportunities and Challenges in Software Engineering for the Next Generation Automotive

December, 7th, 2015, Assises de l Embarqué

Stephen Miles. Transform IT assets to Drive Business Service Innovation. CA Expo Hong Kong. Vice President - Service Assurance Asia Pacific & Japan

Building the Internet of Things Jim Green - CTO, Data & Analytics Business Group, Cisco Systems

EVITA-Project.org: E-Safety Vehicle Intrusion Protected Applications

Datencenterlösungen Neues aus dem Bereich Security

Internet of Things. Reply Platform

Is Cloud relevant for SOA? Corsin Decurtins

SPICE auf der Überholspur. Vergleich von ISO (TR) und Automotive SPICE

White Paper. Anywhere, Any Device File Access with IT in Control. Enterprise File Serving 2.0

Industrie 4.0 and Digital Transformation in NRW: Challenges, Opportunities and Potential for Cooperation Seoul,

The promise of SDN. EU Future Internet Assembly March 18, Yanick Pouffary Chief Technologist HP Network Services

GEMALTO M2M KEY TECHNOLOGY TRENDS OF M2M

Management of Security Information and Events in Future Internet

Bring the cloud to your datacenter

Samsung SDS. Enterprise Mobility Management

Big Data in Internet of Things (IoT): Key Trends, Opportunities and Market Forecasts

Design for Success: Designing for the Internet of Things with TiWiConnect

Roles of Smart TV in Internet of Things

VMware vsphere Data Protection 6.1

3 rd Young Researcher s Day 2013

INTRODUCTION TO CLOUD COMPUTING CEN483 PARALLEL AND DISTRIBUTED SYSTEMS

Cyber Security Compliance

Fast Feedback: Jenkins + Functional and Non-Functional Mobile App Testing Without Pulling Your Hair

Software as a Service Business Model (Introducing SOA and Web Service)

Internet of Things The EU research agenda Information Day. Thibaut KLEINER European Commission - DG CONNECT Head of Unit E1: Network Technologies

Solution Brief. Aerohive and OpenDNS. Advanced Network Security for Retail Stores

Key & Data Storage on Mobile Devices

IBM MobileFirst Launch David Lee Heyman

Getting Started with Tizen SDK : How to develop a Web app. Hong Gyungpyo 洪 競 杓 Samsung Electronics Co., Ltd

UPnP Internet of Things Dec 2014

European developer & provider ensuring data protection User console: Simile Fingerprint Filter Policies and content filtering rules

OT PRODUCTS AND SOLUTIONS MACHINE TO MACHINE

Enhance Your SAP Portal Experience Using SAP Mobile Documents. Matt Carrier, SAP SESSION CODE: PO358

HOW SDN AND (NFV) WILL RADICALLY CHANGE DATA CENTRE ARCHITECTURES AND ENABLE NEXT GENERATION CLOUD SERVICES

OpenMTC. M2M Solutions for Smart Cities and the Internet of Things.

Accenture and Oracle: Leading the IoT Revolution

Microcontrollers Deserve Protection Too

Chapter 2: Transparent Computing and Cloud Computing. Contents of the lecture

Total Cloud Control with Oracle Enterprise Manager 12c. Kevin Patterson, Principal Sales Consultant, Enterprise Manager Oracle

How To Use Softxpand (A Thin Client) On A Pc Or Laptop Or Mac Or Macbook Or Ipad (For A Powerbook)

Transcription:

Towards Trusted Apps for the Internet of Things Christian Prehofer fortiss GmbH An-Institut Technische Universität München 1 IoT & S C. Prehofer

Internet of Things Motivation Internet of Things Nabaztag 2 2

Contents Internet of Things and mobile Apps From Mobile IoT Apps to Apps for Things Trusted Apps Project 3 IoT & S C. Prehofer

Mobile Apps and the Internet of Things Currently, many smart IoT device are used from a mobile app Examples TV Kitchen devices Lights Cars... For each device, we get an App like a remote control Simple way to outsource the UI http://www.wsj.de/nachrichten/sb11401573521024413408604580290843167502192 4 IoT & S C. Prehofer

Mobile Apps for the IoT Some Views Proprietary Apps Will Halt IoT Market Growth Samsung Vice President Dr. Alan Messer: "Most of those solutions require their app.. in order to use them, "app-for-that" model to asking end users to buy a different electric plug and socket for every electric appliance http://www.crn.com/news/networking/video/300075925/samsungproprietary-apps-will-halt-iot-market-growth.htm http://hackaday.com/2013/07/09/ hack-it-in-refrigerator-egg-monitoring/ 5 IoT & S C. Prehofer

Example: Download the App for your recipe Example recipe app downloaded on demand So stellt sich ein traditionsreicher Hausgerätekonzern wie Miele die Zukunft vor: Ein junges Pärchen verfolgt im Fernsehen eine Kochsendung. Die macht ihnen Appetit, und sie beschließen, das Menü nachzukochen. Über eine App ihres Geräteherstellers laden sie das nötige Backprogramm für den Braten herunter, beim Sender gibt es die Zutatenliste im Download. Der Kühlschrank vergleicht und stellt fest, was noch einzukaufen ist. Bestellt wird natürlich auch online, und nach der Lieferung kann es dann losgehen: Zutaten vorbereiten, alles kleinschneiden und die Gerichte vorbereiten. Den Rest erledigt der Backofen selbstständig http://www.wsj.de/nachrichten/sb11401573521024413408604580290843167502192 6 IoT & S C. Prehofer

So what about your recipe App... So, take the recipe App example... What happens with your food if... you leave the house? your phone crashes? there is a virus on your phone? Just consider malicous Apps: In a dataset of 22500+ Android apps, 26% of their samples are identified as malicious A. Gorla et al., Checking App Behavior Against App Descriptions 7 IoT & S C. Prehofer

From mobile Apps to (trusted) Apps for Things Main requirements Apps for (critical) devices need to be highly trusted Apps and open interfaces to devices create security risks Apps must not loose connection to the IoT device Loss of connection is loss of control Usability, easy of deployment,... Approach here: put apps on things! Apps should be on the thing the IoT device Maybe on (home) gateway Mobile Apps in addition to this Already happening for Cameras, Cars,... Cloud Services Mobile App IoT App IoT Device 8 IoT & S C. Prehofer

Plattform for Apps for Things We need a platform for highly trusted Apps on IoT devices No loss of connection Local processing (e.g. important for multimedia processing) Higher security possible (e.g. no man-in-the-middle) Challenges for real IoT Apps IoT platforms not designed for platform security Simple operating systems/hw No virtualization or even memory protection Limited UI and configuration Cloud Services Mobile App Current work at fortiss on Secure Apps for Contiki OS (not focus today) Trusted Application Platform TAPPS See next slides IoT App Trusted IoT Pla.orm 9 IoT & S C. Prehofer

Smart Grid Example: Energy Control for a Fridge Motivation: Use a fridge for energy storage e.g. introduce low, normal and high modes wrt energy consumption Problem: Large number of manufacturers and energy providers Large number of business relationships & target devices App-based Approach 1. Fridge manufacturer provides App platform 2. Energy provider provides app to control energy 3. App is checked by some trusted party (may be (1) ) Fridge Manufacturer Deployment Trusted party Energy Provider IoT App Local APIs Control depending on network status / pricing 10 IoT & S C. Prehofer

IoT Service Ecosytems Open eco-systems can spark innovation Examples: Windows, mobile apps (iphone, Android), SAP,... Secure R&D investment Enables new value chains and scalable revenue models IoT connects to the Internet with fast innovation cycles Requires quick innovation and update cycles Large number of different devices Closed & vertical systems for IoT hinder IoT adoption Slow development and deployment Solutions specific to platforms and not portable 11

Trusted Apps for open CPS (TAPPS) Goal: open platform for trusted Apps Adding features by downloading apps Apps may interfere with safety critical functions Main innovation: Trusted App Platform Incl. trusted HW, OS, Tool Chain, App Store TAPPS partners EU Horizon2020 Project tapps-project.eu

Partners of TAPPS (Third party) Contact Presenter name // Organisation Email (phone number) Co-funded by the Horizon 2020 Framework Programme of the European Union under grant agreement no 645119

TAPPS Motivation Trend towards open systems, which can be extended during operation. Add features by downloading apps Apps may interact or interfere with safety critical functions Not possible today due to security and safety 14 C. Prehofer Munich, 2013-07-23

TAPPS: Trusted Apps Eco-Systems Apps in vehicles or other critical devices to add new functionality To add new features and customization Apps as a key differentiating feature Goal is build an eco-system of apps Invite 3rd parties to innovate on top of existing plaforms E.g. open car as a SW platform Also considering health and other domains Main challenge is trust Trust includes security, safety, management and contol, privacy A main challenge is to ensure safety of the devices

Apps in Smart Devices (Vehicles, Health) Categories of Apps (in case of vehicles) 1. Pure infotainment, external services Safety relevance is low 2. Apps which access internal information E.g. address book, sensors, location,... Privacy issues, little safety issues 3. Integrated Apps which modify internals E.g. customize vehicle dynamics (traction, esp,...) based on weather conditions E.g. customize assistance systems Focus here is on class (3): apps which have access to internal APIs High demands on safety and security. Requires a dedicated, secure execution environement Note: may be complemented by an app for less critical tasks (e.g. UI, external interfaces) in a less trusted execution environment

Safety and Security Issues for Apps Resource issues: Apps may use considerable system resources Other apps and functions may suffer Concerns network, CPU and others (e.g. HW interfaces, storage,..) Need of virtualization of resources Needs to go beyond single ECU include NW etc Management of these resources is needed Fine grained access control E.g. application may get the position once or continously E.g. app may get one entry from the phone book, but not the full phone book Safety critical 3rd party apps may need verification Simple testing or static checking not always sufficient Need proper verification e.g. by model checking

TAPPS: Trusted Execution Environment Challenge: Realtime Trusted Execution Environment (TEE) for highly-trusted Apps. Main Approach: Multiple layers of security 1. Trusted hardware with security mechanisms 2. Computing and network virtualization 3. Fine-grained access control to resources of the smart device to ensure safety and privacy. 4. Verified Apps to ensure correct and secure behavior.

TAPPS Approach and main Goals Trusted End2End App Solutions & App Development App Store, Apps development tool chain and verification App Store Trusted App Tool Chain and Deploment Realtme Trusted Exection Environment Apps APIs / Execution environment, Virtualization, Trusted Hardware IoT Device (Controller) Rich Execution Environment (User interface) Trusted App Trusted Execution Environment (TEE) Other Controlles in device Trusted Core Framework Rich OS Trusted Hardware Platform Trusted OS Trusted Peripherals

End-to-end Solution End-to-end solution for development and deployment of trusted Apps An application store for management of CPS Apps and for deployment, supporting both the rich execution environment and the separate TEE. A model-based development tool chain for designing and implementing trusted apps including APIs and verification tools.

Research challenges Integrated management of security User profile, credentials, API access rights, device capabilities throughout the complete solution, including App Store, deployment and Apps configuration and access control. Tight integration of HW security with computing and network virtualization, including real-time support and APIs for apps. Tool support for the development of apps in a small, trusted execution environment. Verification of trusted apps by new verification tools.

TAPPS High-level System Architecture Valida<on & Verifika<on App Development Env. Cloud Services (opt), e.g. from app provider, manufacturer,... Compila3on of Apps to different IoT Systems, check verifica3on Trusted party Deployment Local Services (opt) e.g. gateway, mobile devices,... IoT App IoT Device... IoT App IoT Device 22 IoT & S C. Prehofer

Validation Goals Validated in health and automotive application domains Munich, 2013-07-23

Summary Many great IoT applications, but also too many vertical silos Trusted apps can be the basis for open, flexible IoT ecosystems Trust as needed for sensitive and/or safety-relevant applications Need an open platform for trusted apps on IoT devices TAPPS project works on a trusted platform for Apps Multiple layers of security (HW, virtualization, APIs, verification) End-to-end solution for deployment and apps management 24 IoT & S C. Prehofer