IEEE Technology and Society Magazine - Winter 2014 - 77
individually controlled and tailored
options, namely personal deliberate choices in design, can represent
a step forward in achieving a higher
level of trust. The presentation of a
potential framework to achieve this
goal is the focus of the next section
of this paper.
A Model-Based Framework
to Build Trust in IoT
Our proposal to enable trustworthy
deployment, adoption, and acceptance of IoT systems by citizens is to
use a framework called SecKit, which
is Model-based Security Toolkit to
address security aspects of distributed
systems [16]. With the support of
SecKit, citizens can adopt a collaborative approach to address issues such
as privacy, agency and data protection, where each one is able to manage security relevant aspects. This
scenario is depicted in Fig. 1.
Citizens are able to specify trust
relations with a set of known identities, analyze their risks, and adopt
enforceable context-based policy
rules. From a citizen's perspective,
rules derived from policies can act
as automated reasons of trust levels
to combine or assess trust in specific
situations or as direct enforceable
self-protection countermeasures to
address risky situations. All these
issues enable building of general trust
and confidence on the safe use of the
IoT systems. In our approach, citizens/users share not only recommendations of trust relationships, but also
templates for policy rules and risk
models for common threat scenarios.
SecKit supports integrated
modeling of the IoT system design
and runtime viewpoints in order
to specify security aspects including risks and requirements, trust
issues, and enforceable security
policy rules with complex conditions. Using SecKit trust relationships can be specified, managed,
and exchanged between citizens
using a flexible aspect-based trust
model. The final goal is to build
citizens confidence with respect to
the protection of their data, safety
and above all their autonomy and
agency with respect to any types
of operations performed by the
devices or any other objects with
which they interact in the IoT.
Trust is specified in SecKit considering measurable direct and indirect trust relations from a trustor
perspective with respect to a trustee
scope [4]. Direct trust relations may
be simply arbitrary or based on
previous experiences or evidence,
which can be calculated using a
formally defined logic or algorithm
encoded in a policy. Indirect trust
relations may be based on recommendations from one entity, or on
the reputation considering recommendations from a pre-defined number of other entities using a specific
combination strategy (e.g. weighted
consensus). Trust relations can also
be specified considering a particular trustee scope and trust aspect.
A trustee scope can be an intrinsic
dispositional belief without considering a particular entity or context,
system trust on a set of other entities
that represent a particular system
(i.e. a composite entity), or situational trust focusing on a particular
identifiable entity taking into consideration all context situations or
only a specific situation.
Assessing these different types
of trust relationships helps with
the decision process and on the
consideration of different intrinsic
human behaviors. For example,
IEEE TECHNOLOGY AND SOCIETY MAGAZINE
Known
Identities
citizens with an optimistic dispositional trust belief may choose to
adopt a more risky behavior in the
absence of any evidence. However,
it is important to provide adequate
guidance and to make sure the
risks are understood.
Trust aspects represent the specific behavior or feature of the trustee
that is considered. A restaurant may
be trusted at a high level to serve good
food but at a low level for the care on
the customer relationships. Measuring these levels of trust can be done
using different approaches; in our
model we adopt a belief approach
from Subjective Logic [17] where
trust relations represent a combined
measurement of belief, disbelief,
and a level of uncertainty. This is the
most natural approach for humans
since in many situations it is impossible to be completely certain about
the possible outcomes. SecKit takes
all these nuances of trust modeling
into consideration, and provides an
integrated framework implementation to support the specification and
reasoning about trust.
Fig. 2 shows the Graphical User
Interface (GUI) of SecKit that list
all the known identities and the
associated trust relationships for
each identity, considering the target trust aspect. In this example the
target trustee is the "Weather Station (Indoor)," which is considered
untrustworthy with respect to the
enforcement of privacy preferences
Trust
Relations
Knowledge
Exchange
Citizen
Risks
Policy
Rules
Community
Fig.1. Crowd-source citizen security.
|
WINTER 2014
|
77
Table of Contents for the Digital Edition of IEEE Technology and Society Magazine - Winter 2014
IEEE Technology and Society Magazine - Winter 2014 - Cover1
IEEE Technology and Society Magazine - Winter 2014 - Cover2
IEEE Technology and Society Magazine - Winter 2014 - 1
IEEE Technology and Society Magazine - Winter 2014 - 2
IEEE Technology and Society Magazine - Winter 2014 - 3
IEEE Technology and Society Magazine - Winter 2014 - 4
IEEE Technology and Society Magazine - Winter 2014 - 5
IEEE Technology and Society Magazine - Winter 2014 - 6
IEEE Technology and Society Magazine - Winter 2014 - 7
IEEE Technology and Society Magazine - Winter 2014 - 8
IEEE Technology and Society Magazine - Winter 2014 - 9
IEEE Technology and Society Magazine - Winter 2014 - 10
IEEE Technology and Society Magazine - Winter 2014 - 11
IEEE Technology and Society Magazine - Winter 2014 - 12
IEEE Technology and Society Magazine - Winter 2014 - 13
IEEE Technology and Society Magazine - Winter 2014 - 14
IEEE Technology and Society Magazine - Winter 2014 - 15
IEEE Technology and Society Magazine - Winter 2014 - 16
IEEE Technology and Society Magazine - Winter 2014 - 17
IEEE Technology and Society Magazine - Winter 2014 - 18
IEEE Technology and Society Magazine - Winter 2014 - 19
IEEE Technology and Society Magazine - Winter 2014 - 20
IEEE Technology and Society Magazine - Winter 2014 - 21
IEEE Technology and Society Magazine - Winter 2014 - 22
IEEE Technology and Society Magazine - Winter 2014 - 23
IEEE Technology and Society Magazine - Winter 2014 - 24
IEEE Technology and Society Magazine - Winter 2014 - 25
IEEE Technology and Society Magazine - Winter 2014 - 26
IEEE Technology and Society Magazine - Winter 2014 - 27
IEEE Technology and Society Magazine - Winter 2014 - 28
IEEE Technology and Society Magazine - Winter 2014 - 29
IEEE Technology and Society Magazine - Winter 2014 - 30
IEEE Technology and Society Magazine - Winter 2014 - 31
IEEE Technology and Society Magazine - Winter 2014 - 32
IEEE Technology and Society Magazine - Winter 2014 - 33
IEEE Technology and Society Magazine - Winter 2014 - 34
IEEE Technology and Society Magazine - Winter 2014 - 35
IEEE Technology and Society Magazine - Winter 2014 - 36
IEEE Technology and Society Magazine - Winter 2014 - 37
IEEE Technology and Society Magazine - Winter 2014 - 38
IEEE Technology and Society Magazine - Winter 2014 - 39
IEEE Technology and Society Magazine - Winter 2014 - 40
IEEE Technology and Society Magazine - Winter 2014 - 41
IEEE Technology and Society Magazine - Winter 2014 - 42
IEEE Technology and Society Magazine - Winter 2014 - 43
IEEE Technology and Society Magazine - Winter 2014 - 44
IEEE Technology and Society Magazine - Winter 2014 - 45
IEEE Technology and Society Magazine - Winter 2014 - 46
IEEE Technology and Society Magazine - Winter 2014 - 47
IEEE Technology and Society Magazine - Winter 2014 - 48
IEEE Technology and Society Magazine - Winter 2014 - 49
IEEE Technology and Society Magazine - Winter 2014 - 50
IEEE Technology and Society Magazine - Winter 2014 - 51
IEEE Technology and Society Magazine - Winter 2014 - 52
IEEE Technology and Society Magazine - Winter 2014 - 53
IEEE Technology and Society Magazine - Winter 2014 - 54
IEEE Technology and Society Magazine - Winter 2014 - 55
IEEE Technology and Society Magazine - Winter 2014 - 56
IEEE Technology and Society Magazine - Winter 2014 - 57
IEEE Technology and Society Magazine - Winter 2014 - 58
IEEE Technology and Society Magazine - Winter 2014 - 59
IEEE Technology and Society Magazine - Winter 2014 - 60
IEEE Technology and Society Magazine - Winter 2014 - 61
IEEE Technology and Society Magazine - Winter 2014 - 62
IEEE Technology and Society Magazine - Winter 2014 - 63
IEEE Technology and Society Magazine - Winter 2014 - 64
IEEE Technology and Society Magazine - Winter 2014 - 65
IEEE Technology and Society Magazine - Winter 2014 - 66
IEEE Technology and Society Magazine - Winter 2014 - 67
IEEE Technology and Society Magazine - Winter 2014 - 68
IEEE Technology and Society Magazine - Winter 2014 - 69
IEEE Technology and Society Magazine - Winter 2014 - 70
IEEE Technology and Society Magazine - Winter 2014 - 71
IEEE Technology and Society Magazine - Winter 2014 - 72
IEEE Technology and Society Magazine - Winter 2014 - 73
IEEE Technology and Society Magazine - Winter 2014 - 74
IEEE Technology and Society Magazine - Winter 2014 - 75
IEEE Technology and Society Magazine - Winter 2014 - 76
IEEE Technology and Society Magazine - Winter 2014 - 77
IEEE Technology and Society Magazine - Winter 2014 - 78
IEEE Technology and Society Magazine - Winter 2014 - 79
IEEE Technology and Society Magazine - Winter 2014 - 80
IEEE Technology and Society Magazine - Winter 2014 - Cover3
IEEE Technology and Society Magazine - Winter 2014 - Cover4
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_september2023
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_june2023
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_march2023
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_december2022
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_september2022
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_june2022
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_march2022
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_december2021
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_september2021
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_june2021
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_march2021
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_december2020
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_september2020
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_june2020
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_march2020
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_december2019
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_september2019
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_june2019
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_march2019
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_december2018
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_september2018
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_june2018
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_march2018
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_winter2017
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_fall2017
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_summer2017
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_spring2017
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_winter2016
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_fall2016
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_summer2016
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_spring2016
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_winter2015
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_fall2015
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_summer2015
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_spring2015
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_winter2014
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_fall2014
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_summer2014
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_spring2014
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_winter2013
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_fall2013
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_summer2013
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_spring2013
https://www.nxtbookmedia.com