Javascript must be enabled to continue!
On Privacy and Security in Smart Connected Homes
View through CrossRef
The growth and presence of heterogeneous sensor-equipped Internet-connected devices inside the home can increase efficiency and quality of life for the residents. Simultaneously, these devices continuously collect, process, and transmit data about the residents and their daily lifestyle activities to unknown parties outside the home. Such data can be sensitive and personal, leading to increasingly intimate insights into private lives. This data allows for the implementation of services, personalization support, and benefits offered by smart home technologies. Alas, there has been a surge of cyberattacks on connected home devices that essentially compromise privacy and security of the residents. Providing privacy and security is a critical issue in smart connected homes. Many residents are concerned about unauthorized access into their homes and about the privacy of their data. However, it is typically challenging to implement privacy and security in a smart connected home because of its heterogeneity of devices, the dynamic nature of the home network, and the fact that it is always connected to the Internet, amongst other things. As the numbers and types of smart home devices are increasing rapidly, so are the risks with these devices. Concurrently, it is also becoming increasingly challenging to gain a deeper understand- ing of the smart home. Such understanding is necessary to build a more privacy-preserving and secure smart connected home. Likewise, it is needed as a precursor to perform a comprehensive privacy and security analysis of the smart home. In this dissertation, we render a comprehensive description and account of the smart connected home that can be used for conducting risk analysis. In doing so, we organize the underlying smart home devices ac- cording to their functionality, identify their data-collecting capabilities, and survey the data types being collected by them. Such is done using the technical specification of commercial devices, including their privacy policies. This description is then leveraged for identifying threats and for analyzing risks present in smart connected homes. Such is done by analyzing both scholarly literature and examples from the industry, and leveraging formal modeling. Additionally, we identify malicious threat agents and mitigations that are relevant to smart connected homes. This is performed without limiting the research and results to a particular configuration and type of smart home. This research led to three main findings. First, the majority of the surveyed commercial devices are collecting instances of sensitive and personal data but are prone to critical vulnerabilities. Second, there is a shortage of scientific models that capture the complexity and heterogeneity of real-world smart home deployments, especially those intended for privacy risk analysis. Finally, despite the increasing regulations and attention to privacy and security, there is a lack of proactive and integrative approaches intended to safeguard privacy and security of the residents. We contributed to addressing these three findings by developing a framework and models that enable early identification of threats, better planning for risk management scenarios, and mitigation of potential impacts caused by attacks before they reach the homes and compromise the lives of the residents. Overall, the scientific contributions presented in this dissertation help deepen the understanding and reasoning about privacy and security concerns affecting smart connected homes, and contributes to advancing the research in the area of risk analysis as applied to such systems.
Title: On Privacy and Security in Smart Connected Homes
Description:
The growth and presence of heterogeneous sensor-equipped Internet-connected devices inside the home can increase efficiency and quality of life for the residents.
Simultaneously, these devices continuously collect, process, and transmit data about the residents and their daily lifestyle activities to unknown parties outside the home.
Such data can be sensitive and personal, leading to increasingly intimate insights into private lives.
This data allows for the implementation of services, personalization support, and benefits offered by smart home technologies.
Alas, there has been a surge of cyberattacks on connected home devices that essentially compromise privacy and security of the residents.
Providing privacy and security is a critical issue in smart connected homes.
Many residents are concerned about unauthorized access into their homes and about the privacy of their data.
However, it is typically challenging to implement privacy and security in a smart connected home because of its heterogeneity of devices, the dynamic nature of the home network, and the fact that it is always connected to the Internet, amongst other things.
As the numbers and types of smart home devices are increasing rapidly, so are the risks with these devices.
Concurrently, it is also becoming increasingly challenging to gain a deeper understand- ing of the smart home.
Such understanding is necessary to build a more privacy-preserving and secure smart connected home.
Likewise, it is needed as a precursor to perform a comprehensive privacy and security analysis of the smart home.
In this dissertation, we render a comprehensive description and account of the smart connected home that can be used for conducting risk analysis.
In doing so, we organize the underlying smart home devices ac- cording to their functionality, identify their data-collecting capabilities, and survey the data types being collected by them.
Such is done using the technical specification of commercial devices, including their privacy policies.
This description is then leveraged for identifying threats and for analyzing risks present in smart connected homes.
Such is done by analyzing both scholarly literature and examples from the industry, and leveraging formal modeling.
Additionally, we identify malicious threat agents and mitigations that are relevant to smart connected homes.
This is performed without limiting the research and results to a particular configuration and type of smart home.
This research led to three main findings.
First, the majority of the surveyed commercial devices are collecting instances of sensitive and personal data but are prone to critical vulnerabilities.
Second, there is a shortage of scientific models that capture the complexity and heterogeneity of real-world smart home deployments, especially those intended for privacy risk analysis.
Finally, despite the increasing regulations and attention to privacy and security, there is a lack of proactive and integrative approaches intended to safeguard privacy and security of the residents.
We contributed to addressing these three findings by developing a framework and models that enable early identification of threats, better planning for risk management scenarios, and mitigation of potential impacts caused by attacks before they reach the homes and compromise the lives of the residents.
Overall, the scientific contributions presented in this dissertation help deepen the understanding and reasoning about privacy and security concerns affecting smart connected homes, and contributes to advancing the research in the area of risk analysis as applied to such systems.
Related Results
On Privacy and Security in Smart Connected Homes
On Privacy and Security in Smart Connected Homes
The growth and presence of heterogeneous sensor-equipped Internet-connected devices inside the home can increase efficiency and quality of life for the residents. Simultaneously, t...
THE SECURITY AND PRIVACY MEASURING SYSTEM FOR THE INTERNET OF THINGS DEVICES
THE SECURITY AND PRIVACY MEASURING SYSTEM FOR THE INTERNET OF THINGS DEVICES
The purpose of the article: elimination of the gap in existing need in the set of clear and objective security and privacy metrics for the IoT devices users and manufacturers and a...
Augmented Differential Privacy Framework for Data Analytics
Augmented Differential Privacy Framework for Data Analytics
Abstract
Differential privacy has emerged as a popular privacy framework for providing privacy preserving noisy query answers based on statistical properties of databases. ...
Privacy Risk in Recommender Systems
Privacy Risk in Recommender Systems
Nowadays, recommender systems are mostly used in many online applications to filter information and help users in selecting their relevant requirements. It avoids users to become o...
Generative AI-Driven Smart Contract Optimization for Secure and Scalable Smart City Services
Generative AI-Driven Smart Contract Optimization for Secure and Scalable Smart City Services
Smart cities use advanced infrastructure and technology to improve the quality of life for their citizens. Collaborative services in smart cities are making the smart city ecosyste...
INVESTIGATING THE ROLE OF DATA ANALYTICS IN MONITORING AND MANAGING ENERGY CONSUMPTION IN SMART HOMES, AIMING TO ENHANCE EFFICIENCY AND REDUCE COSTS
INVESTIGATING THE ROLE OF DATA ANALYTICS IN MONITORING AND MANAGING ENERGY CONSUMPTION IN SMART HOMES, AIMING TO ENHANCE EFFICIENCY AND REDUCE COSTS
Smart home technology is progressing rapidly due to the need for better energy management and resulting new potentials for controlling energy. While smart homes use different conne...
Reinventing Smart Water Management System through ICT and IoT Driven Solution for Smart Cities
Reinventing Smart Water Management System through ICT and IoT Driven Solution for Smart Cities
Purpose: Worldwide water scarcity is one of the major problems to deal with. Smart Cities also faces this challenging problem due to its ever-increasing population and limited sour...
Kajian Pembangunan Smart Society Kota Bandung
Kajian Pembangunan Smart Society Kota Bandung
Abstract. Rancasari sub-district which is included in the Gedebage SWK with the theme of the technopolis area has a strong position in smart development because of the interest of ...


