Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
AutoPKI: public key infrastructure for IoT with automated trust transfer
RISE Research Institutes of Sweden, Digital Systems, Data Science.ORCID iD: 0000-0002-9491-8183
RISE Research Institutes of Sweden, Digital Systems, Data Science.ORCID iD: 0000-0002-5165-2100
Nexus Group, Sweden.
Ericsson, Sweden.
Show others and affiliations
2024 (English)In: International Journal of Information Security, ISSN 1615-5262, E-ISSN 1615-5270, Vol. 23, no 3, p. 1859-Article in journal (Refereed) Published
Abstract [en]

IoT deployments grow in numbers and size, which makes questions of long-term support and maintainability increasingly important. Without scalable and standard-compliant capabilities to transfer the control of IoT devices between service providers, IoT system owners cannot ensure long-term maintainability, and risk vendor lock-in. The manual overhead must be kept low for large-scale IoT installations to be economically feasible. We propose AutoPKI, a lightweight protocol to update the IoT PKI credentials and shift the trusted domains, enabling the transfer of control between IoT service providers, building upon the latest IoT standards for secure communication and efficient encodings. We show that the overhead for the involved IoT devices is small and that the overall required manual overhead can be minimized. We analyse the fulfilment of the security requirements, and for a subset of them, we demonstrate that the desired security properties hold through formal verification using the Tamarin prover. 

Place, publisher, year, edition, pages
Springer Science and Business Media Deutschland GmbH , 2024. Vol. 23, no 3, p. 1859-
Keywords [en]
Internet of things; Maintainability; Public key cryptography; Digital certificates; Embedded-system; Enrollment; IoT; Lock-in; Number and size; PKI; Public key infrastructure; Service provider; Trust transfer; Embedded systems
National Category
Electrical Engineering, Electronic Engineering, Information Engineering
Identifiers
URN: urn:nbn:se:ri:diva-72880DOI: 10.1007/s10207-024-00825-zScopus ID: 2-s2.0-85186450576OAI: oai:DiVA.org:ri-72880DiVA, id: diva2:1854696
Funder
Swedish Foundation for Strategic ResearchEU, Horizon 2020, 101020259EU, Horizon 2020, 957197
Note

This research is partially funded by the Swedish SSF Institute PhD grant and by the EU H2020 projects ARCADIAN-IoT (Grant ID. 101020259) and VEDLIoT (Grant ID: 957197)

Available from: 2024-04-26 Created: 2024-04-26 Last updated: 2025-09-23Bibliographically approved

Open Access in DiVA

fulltext(739 kB)139 downloads
File information
File name FULLTEXT01.pdfFile size 739 kBChecksum SHA-512
dc3116ce48b2bc5407693bbd692fa400d1ada4c875f2e734031db3cb1297513f96a27310203d2ffc48c0d7e80dc97b6bca734d2d63f5f524cfaf58dd8a8df916
Type fulltextMimetype application/pdf

Other links

Publisher's full textScopus

Authority records

Höglund, JoelBouget, SimonRaza, Shahid

Search in DiVA

By author/editor
Höglund, JoelBouget, SimonRaza, Shahid
By organisation
Data Science
In the same journal
International Journal of Information Security
Electrical Engineering, Electronic Engineering, Information Engineering

Search outside of DiVA

GoogleGoogle Scholar
Total: 139 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 402 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf