We believe that we are on the verge of the Internet of Things - - PowerPoint PPT Presentation

we believe that we are on the verge of the internet of
SMART_READER_LITE
LIVE PREVIEW

We believe that we are on the verge of the Internet of Things - - PowerPoint PPT Presentation

We believe that we are on the verge of the Internet of Things explosion. Now is the time to make sure that IoT incorporates everything weve learned about digital security and infrastructure resiliency over the last 20 years of the Internet.


slide-1
SLIDE 1

We believe that we are on the verge of the Internet of Things explosion. Now is the time to make sure that IoT incorporates everything we’ve learned about digital security and infrastructure resiliency over the last 20 years of the Internet.

1

slide-2
SLIDE 2

IDENTITY

SECURITY BEGINS WITH

slide-3
SLIDE 3

IDENTITY

User name and password

slide-4
SLIDE 4

IDENTITY

Smartcard

slide-5
SLIDE 5

IDENTITY

Biometrics

slide-6
SLIDE 6

IDENTITY

Certificate

slide-7
SLIDE 7

IDENTITY

API KEY AE5021 B3209A FEA409

slide-8
SLIDE 8

IDENTITY

TRUST

slide-9
SLIDE 9

IDENTITY

TRUST

slide-10
SLIDE 10

IDENTITY

APPLYING THESE MECHANISMS TO IOT AND M2M

slide-11
SLIDE 11

AE5021 B3209A FEA409

IDENTITY

PROGRAMMATIC PHYSICAL

slide-12
SLIDE 12

AE5021 B3209A FEA409

IDENTITY

PROGRAMMATIC PHYSICAL

slide-13
SLIDE 13

CERTIFICATES

PUBLIC KEY INFRASTRUCTURE (PKI)

l Trusted and well established technology l Allows for mutual authentication l Can be used for message signing
slide-14
SLIDE 14

CERTIFICATES

slide-15
SLIDE 15

CERTIFICATES

slide-16
SLIDE 16

CERTIFICATES

slide-17
SLIDE 17

CERTIFICATES

COST

$$$$$ $$$$$ $$$$$

slide-18
SLIDE 18

CERTIFICATES

COST

$$$$$ $$$$$ $$$$$

slide-19
SLIDE 19

CERTIFICATES

SECURITY

slide-20
SLIDE 20

CERTIFICATES

SECURITY

  • Revocation

Certificate Revocation List Online Certificate Status Protocol

CERTIFICATE AUTHORITY

slide-21
SLIDE 21

CERTIFICATES

SECURITY

  • Revocation

Certificate Revocation List Online Certificate Status Protocol

CERTIFICATE AUTHORITY

slide-22
SLIDE 22

CERTIFICATES

SECURITY

  • Revocation

Certificate Revocation List Online Certificate Status Protocol

CERTIFICATE AUTHORITY

slide-23
SLIDE 23

CERTIFICATES

SECURITY

  • TRUST

CERTIFICATE AUTHORITY

slide-24
SLIDE 24

CERTIFICATES

SECURITY

  • TRUST

CERTIFICATE AUTHORITIES

slide-25
SLIDE 25

CERTIFICATES

SECURITY

  • TRUST

CERTIFICATE AUTHORITIES

device123.example.com device123.example.com Certificate Authority A Certificate Authority B

slide-26
SLIDE 26

CERTIFICATES

MANAGEMENT

slide-27
SLIDE 27

CERTIFICATES

INTEROPERABILITY

FOO.COM CERTIFICATE AUTHORITY BAR.COM CERTIFICATE AUTHORITY

slide-28
SLIDE 28

CERTIFICATES

INTEROPERABILITY

FOO.COM CERTIFICATE AUTHORITY BAR.COM CERTIFICATE AUTHORITY

slide-29
SLIDE 29

CHALLENGES

How do we deploy PKI at Internet of Things scale.

l Keep cost low l Be interoperable l Deploy at scale l Improve security
slide-30
SLIDE 30

DANE

slide-31
SLIDE 31

DNS-BASED AUTHENTICATION OF NAMED ENTITIES

slide-32
SLIDE 32

DNSSEC

Provides a secure global registry

l Highly scalable
slide-33
SLIDE 33

DNSSEC

Provides a secure global registry

l Highly scalable l Globally distributed
slide-34
SLIDE 34

DNSSEC

Provides a secure global registry

l Highly scalable l Globally distributed l Resilient
slide-35
SLIDE 35

DNSSEC

Provides a secure global registry

l Highly scalable l Globally distributed l Resilient l Standards based
slide-36
SLIDE 36

DNSSEC

Provides a secure global registry

l Highly scalable l Globally distributed l Resilient l Standards based l Ubiquitous
slide-37
SLIDE 37

DNSSEC

Provides a secure global registry

l Highly scalable l Globally distributed l Resilient l Standards based l Ubiquitous l Secure
slide-38
SLIDE 38

DNSSEC

Provides a secure global registry

l Secure l Cryptographically signed l Supports delegation

. root key .com key .example.com key

zone.example.com

….... ….... …....

slide-39
SLIDE 39

DANE

RFC 6698 - establishes new record types for DNS Allows publishing of certificate data in DNS Data integrity validated by cryptographic signature

zone.example.com ….... ….... …....

slide-40
SLIDE 40

DANE

RFC 6698 - establishes new record types for DNS

l Effectively replaces local CA store as means of validating certificates l Allows records to be queried in real time l Allows records to be cached for specific amount of time l Removes the need for CRLs and OCSP l Can work with CA issued certificates or self signed certificates
slide-41
SLIDE 41

Sensor

Keys

DNS Registry

device1.example.com device2.example.com device3.example.com device4.example.com device5.example.com deviceX.example.com …....

Device provisioning

Public key is published in DNS Device creates public/private keypair

slide-42
SLIDE 42

Sensor

Keys

DNS Registry

device1.example.com device2.example.com device3.example.com device4.example.com device5.example.com deviceX.example.com …....

DNS “TLSA” record maps device name to public key Device only needs name does not need published IP address

slide-43
SLIDE 43

Sensor

Keys

DNS Registry

device1.example.com device2.example.com device3.example.com device4.example.com device5.example.com deviceX.example.com …....

IoT Platform

Sensor initiates TLS connection to IoT Platform

slide-44
SLIDE 44

Sensor

Keys

DNS Registry

device1.example.com device2.example.com device3.example.com device4.example.com device5.example.com deviceX.example.com …....

IoT Platform

TLS handshake includes device name and public key

slide-45
SLIDE 45

Sensor

Keys

IoT Platform DNS Registry

device1.example.com device2.example.com device3.example.com device4.example.com device5.example.com deviceX.example.com …....

Recursive DNS Server IoT Platform queries secure DNS for public key for device

slide-46
SLIDE 46

Sensor

Keys

IoT Platform DNS Registry

device1.example.com device2.example.com device3.example.com device4.example.com device5.example.com deviceX.example.com …....

Recursive DNS Server IoT Platform retrieves public key from secure DNS Server

slide-47
SLIDE 47

Sensor

Keys

DNS Registry

device1.example.com device2.example.com device3.example.com device4.example.com device5.example.com deviceX.example.com …....

IoT Platform compares device's published key with the key used during negotiation

= ?

slide-48
SLIDE 48

Sensor

Keys

DNS Registry

device1.example.com device2.example.com device3.example.com device4.example.com device5.example.com deviceX.example.com …....

The keys match so the client certificate is validated

slide-49
SLIDE 49

DANE

Advantages of DANE

l Highly scalable l Economically viable l Highly secure l Limited scope of trust l Instant revocation l Transparency
slide-50
SLIDE 50

WHAT NOW ?

50

COMMUNITY ENGAGEMENT

Working with the community on DANE enablement across the stack including crypto libraries and common runtime frameworks.

FEEDBACK

We'd love to talk! email us at iot@verisign.com