What’sallthisIhearabouttheInternetofThings?(ArecentvisittoCESinLasVegas)
• BSorNotBS?
• Doesitma/er?
• Wheredo“WE”fitin?
A picture is worth 1001 words (but I am no ar7st)
Numbers, Iden7fiers, Protocols • Spectrum..13.56MHz,900MHz,2.4/5GHz,24GHz…(GOVTs/ITU)• ModulaSon,MediaAccessControl,e.g.bluetooth,wifi,zigbee,..(IG/IEEE)• MACaddresses,e.g.,00:20:68:XX:XX:XX/ISDYNE(IEEE)• Othernumbers:ports:80/HTTP,161/SNMP,OID/PEN:1.3.6.1.4.1.2011/Huawei(IETF/ICANN)• IPv4,IPv6:199.7.83.42,2001:500:9f::42(RIR/ICANN)• ASN:AS2706/WharfTT…(RIR/ICANN)• DomainNames:www.co./…(ICANN)• HTTP,SMTP,SIP,XMPP,RTP,appspecific…(IETF/ITU/IG)• Security:SSL/TLS,RSA,ECC,AES,…(Academia/IG/IETF/GOVTs)
• ObviouslyweneeddomainnamestolayclaimtoourpresenceontheInternet• …andtoprovideamechanismforcustomerstolocateourservices• ButwheremightdomainnamesfitintheIoTdiscussion?
DNS: The first Cloud service?
• DNShasbeenpartoftheInternetsince1983• Faithfullymanagedby100sofoperatorsand1000sofenSSes• Alreadybuiltintosoeware• CurrentlymostlyonewayfromstaScDNSserverstoclients• Whynotbothways?
DNS
• Sure,this“channel”isslowbutmostIoTapplicaSonsarelowdatarate(e.g.,dooropen,doorclosed)• ExamplesofDNSdatachanneluse:• Botnetcommandandcontrol• InternetaccessesoverDNS(e.g.,iodine)• WebanalyScs
• Cachingdelayscanbecontrolledoreliminated• RelaSvelyeasytowrite/modifynameservertoactonspecificqueries,e.g.,• set-light-on-<changing-string>.my.iot.domain• get-alarm-state-<changing-string>.my.iot.domain
DNSSEC: Solu7on to IoT’s Security Headache?
• SecurityisawellknownmissingpieceforIoT• ManyIoTapplicaSonshavephysicalsafetyimplicaSons• DNSwithDNSSECcansolvethisproblem• Examples:• DANE:publishpublickeysintheDNS.EnduservalidatesusingDNSSEC.• SmartGrid
• Result:asecure,global,cross-organizaSonal,trans-naSonalcommunicaSonchannelbetweendevices
Athought:ScalableSecurityforIoT
com
za
root
co.za
iotdevices.co.za
window.rickshome.security.co.za
security.co.za electric.co.za
water.rickshome.security.co.za
door.rickshome.security.co.za meter.rickshome.electric.co.za
aircond.rickshome.electric.co.za car.rickshome.iotdevices.co.za
refrigerator.rickshome.iotdevices.co.za
thermostat.rickshome.iotdevices.co.za
google.com
DNS is already there DNSSEC adds security
and crosses organizational boundaries.
Animatedslide
LetstakeadvantageofthehardwonexperienceandcooperaIveenvironmenttodevelopthesoluIonsfor“tomorrow’s”IoT!
?
Ideas ?
• DomainNamesasaubiquitous,scalable,decentralized(cloud)communicaSonchannelforIoTinfrastructure• LockeddownwithDNSSECtosecurethechannelandbootstrapapplicaSonspecificsecuritymechanisms