Source-linked AI summary
Internet of Things: Survey on Security and Privacy
Diego M. Mendez, Ioannis Papapanagiotou, Baijian Yang
TL;DR
The IoT’s scale, heterogeneity, ad-hoc operation, and pervasive data collection create unresolved security and privacy challenges. This survey synthesizes vulnerabilities and protections across IoT architectures, technologies, protocols, layers, and the confidentiality-integrity-availability triad. It concludes that security improvements and solutions have not kept pace with device growth and data exposure, requiring stronger analysis, standards, and security practices.
Problem
IoT security and privacy remain challenging because connected devices and networks are heterogeneous, distributed, scalable, and increasingly handle sensitive personal data.
Method
The paper surveys IoT architectures, enabling technologies, protocols, intrinsic vulnerabilities, layer-specific threats, security-triad concerns, privacy issues, and proposed solutions.
Results
The survey finds that security solutions and improvements have not kept pace with the growth of IoT devices, publications, vulnerabilities, and handled data.
Takeaways & Limitations
IoT security requires analysis across the full security spectrum, with objectives incorporated early in design and standardized solutions applied during production.
Takeaways & Limitations
Recent efforts have not covered the entire IoT security spectrum, leaving research opportunities in areas including smart-object hardening and detection capabilities.
Abstract
from arXiv · showhide
The Internet of Things (IoT) is intended for ubiquitous connectivity among different entities or "things". While its purpose is to provide effective and efficient solutions, security of the devices and network is a challenging issue. The number of devices connected along with the ad-hoc nature of the system further exacerbates the situation. Therefore, security and privacy has emerged as a significant challenge for the IoT. In this paper,we aim to provide a thorough survey related to the privacy and security challenges of the IoT. This document addresses these challenges from the perspective of technologies and architecture used. This work focuses also in IoT intrinsic vulnerabilities as well as the security challenges of various layers based on the security principles of data confidentiality, integrity and availability. This survey analyzes articles published for the IoT at the time and relates it to the security conjuncture of the field and its projection to the future.
I. INTRODUCTION
IoT integrates heterogeneous connected devices, communication technologies, software, and standards with minimal human intervention, but its complexity and undefined perimeters create substantial security risks. The survey organizes these concerns across architectures, technologies, protocols, and security objectives.
- I. INTRODUCTION: IoT connects surrounding devices that exchange data and trigger actions with minimal human intervention.The envisioned ecosystem blends device operation with human activities and requires communication technologies, protocols, standards, hardware, software, and compatible operating systems.
- I. INTRODUCTION: The survey examines IoT security and privacy across architectures, enabling technologies, protocols, and the confidentiality, integrity, and availability triad.It also reviews privacy issues from multiple perspectives and summarizes ongoing challenges and proposed solutions.
- I. INTRODUCTION: IoT’s heterogeneous, dynamic, intelligent, mobile, and undefined-perimeter nature makes comprehensive security solutions difficult to develop.Multiple platforms and system properties increase the difficulty of understanding and securing the IoT foundation and components.
- II. STRUCTURE OF IOT SYSTEMS: IoT architecture is commonly described through perception, network, and application layers that gather, transmit, process, and present data.The perception layer gathers environmental data, the network layer transmits it, and the application layer provides abstracted solutions for users.
- II. STRUCTURE OF IOT SYSTEMS: No unified IoT framework exists, although IEEE and ETSI standards and models such as RAMI 4.0, IIRA, and IoT-A support architectural structuring.These initiatives include technology-specific security guidelines and reference architectures.
III. VULNERABLE LANDSCAPE
IoT security requirements span secure communication, data protection, authentication, access control, privacy, and resilience. Existing technologies remain insufficiently comprehensive for the IoT’s scalable and distributed properties.
- III. VULNERABLE LANDSCAPE: The 2016 Dyn DDoS attack demonstrated how IoT-infected devices and weak protections can produce large-scale consequences.The incident increased attention to the need for additional research on IoT security.
- III. VULNERABLE LANDSCAPE: Required protections include secure bootstrapping and data transmission, data security, authorized data access, attack resiliency, authentication, access control, and client privacy.Additional requirements include key management, secret-key algorithms, secure routing, intrusion detection, and physical security design.
- III. VULNERABLE LANDSCAPE: Current IoT technologies do not provide feasible, comprehensive security and privacy solutions for the system’s scalable and distributed properties.The survey identifies the need for flexible and innovative approaches to address these requirements.
- III. VULNERABLE LANDSCAPE: Security concerns are framed around data integrity and authentication alongside confidentiality, availability, and privacy protections.These concerns reflect the broad security requirements identified for IoT systems.
IV. ENABLING TECHNOLOGIES AND PROTOCOLS
IoT enabling technologies combine constrained sensing, communication, middleware, and aggregation components, creating vulnerabilities across layers and attack classes. Wireless sensor networks require protection against attacks on secrecy, integrity, authentication, and availability.
- 1) Wireless Sensor Networks:: WSNs face power, bandwidth, routing, coordination, information-processing, and security limitations because they rely on massive deployment and strict coordination.These constraints shape the security capabilities of the network.
- 1) Wireless Sensor Networks:: Wireless sensor networks use sensors, microcontrollers, memory, radio transceivers, batteries, and a centralized base station connected through multi-hop relays.Their network modules also include hardware, a communication stack, middleware, and secure data aggregation.
- 1) Wireless Sensor Networks:: WSN threats include DoS, traffic analysis, Sybil and node-replication attacks, black-hole routing, confidentiality breaches, and physical manipulation.Availability attacks can target the physical, link, network, transport, and application layers through mechanisms including jamming, collisions, flooding, spoofing, and selective forwarding.
- 1) Wireless Sensor Networks:: WSN attacks are categorized by properties including external or internal origin, passive or active behavior, attacker class, and effects such as interruption, interception, modification, or fabrication.The taxonomy also distinguishes host-based from network-based attacks.
2) Radio Frequency Identification:
RFID and Wi-Fi provide important IoT connectivity functions but expose data and communications to unauthorized reading, tracking, eavesdropping, and active attacks. The survey outlines security measures including access control, encryption, IPSec, and cryptographic protections.
- 2) Radio Frequency Identification:: RFID passive tags commonly transmit unprotected or read-only data, and default configurations permit compliant scanners to read them without authentication.These properties increase eavesdropping risks and confine passive RFID deployments to non-critical settings.
- 2) Radio Frequency Identification:: RFID vulnerabilities include unauthorized disabling, tag cloning, tracking, and replay attacks affecting authenticity, integrity, confidentiality, and availability.The survey also identifies corporate espionage, location, and personal privacy concerns.
- 2) Radio Frequency Identification:: Proposed RFID protections include access control, data encryption, IPSec, and cryptographic schemes against side-channel attacks such as differential power analysis.The measures aim to restrict reading, protect communications, and obscure encryption-related power-consumption dependencies.
- 2) Radio Frequency Identification:: IEEE 802.11 Wi-Fi connects devices within roughly 100 m but remains vulnerable to passive eavesdropping and active jamming or scrambling attacks.The IEEE 802.11ah task group targets capability and capacity gaps for IoT systems.
4) Long Term Evolution (LTE)/LTE-Advanced:
The surveyed wireless technologies support IoT connectivity but expose distinct security weaknesses across encryption, authentication, physical-layer protection, and service availability.
- 4) Long Term Evolution (LTE)/LTE-Advanced:: LTE gateways connect IoT systems to cellular networks where wired gateways are unavailable, using bandwidth, coverage, and spectrum efficiency as selection factors.LTE Femtocells provide low-range, low-power radio bases for small-scale users or systems and connect them to the core cellular network.
- 4) Long Term Evolution (LTE)/LTE-Advanced:: WiMAX protects primarily at the MAC-layer security sublayer, leaving the physical layer mainly unprotected against threats such as jamming.Reported concerns also include service downgrades from flawed authentication and resource limitations.
- 4) Long Term Evolution (LTE)/LTE-Advanced:: NFC supports payments, authentication, and data exchange but remains vulnerable to denial of service and information leakage, especially when communication is unencrypted.Unencrypted wireless signals can be captured by antennas, partly because of backward compatibility with RFID.
- 4) Long Term Evolution (LTE)/LTE-Advanced:: Bluetooth provides security through frequency hopping, restricted authentication, and encryption, while BLE broadcasts small one-way packets that may carry private user data.The supplied passage identifies BLE privacy exposure but does not state the full encryption or authentication details.
8) ZigBee:
ZigBee organizes security around a Trust Center and differentiated keys, while related IoT communication standards require lightweight protections suited to constrained devices and networks.
- 8) ZigBee:: ZigBee’s Trust Center architecture assigns device authentication, network-key distribution, and end-to-end security to separate manager roles.The trust manager authenticates joining devices, the network manager distributes network keys, and the configuration manager provides end-to-end protection.
- 8) ZigBee:: ZigBee uses Master, Link, and Network Keys for long-term, device-pair, and network-wide protection, with AES-128 in CCM mode for encryption and authentication.The passage states that these keys support freshness and integrity of data.
- 8) ZigBee:: ZigBee’s commercial mode provides centralized key management and freshness counters, whereas its residential mode offers no security.Centralized control also permits key updates in commercial operation.
- 8) ZigBee:: Z-Wave vulnerabilities include hard-coded chip encryption keys and insufficient validation of key-exchange handlers, while mandatory S2 adoption strengthens new-device pairing.A one-meter setup requirement can limit the attack ratio during device addition.
- 8) ZigBee:: 6LoWPAN security should combine secure bootstrapping, ECC-enabled Secure Neighbor Discovery, and key management designed for small packets and constrained networks.The passage presents these mechanisms as requirements for a secure 6LoWPAN protocol.
B. Middleware
IoT middleware connects heterogeneous devices and services but expands the attack surface, with security coverage varying substantially across middleware architectures and applications.
- B. Middleware: Middleware interconnects IoT architectural components and integrates cloud, centralized-overlay, and peer-to-peer systems, increasing the demand for comprehensive security.The paper also identifies a lack of standardized approaches for addressing all IoT security and privacy requirements.
- B. Middleware: Event-based middleware may provide access control and broker confidentiality, but other applications do not address security requirements at all.HERMES is cited as using access control, X.509 certificates, and role-based mechanisms.
- B. Middleware: Service-oriented middleware can distribute security and trust across inter-device connections, yet virtualization may introduce side-channel vulnerabilities and some systems provide only authentication.Examples include SOCRADES, UbiSOAP, Servilla, and related systems with differing security and privacy coverage.
- B. Middleware: VM-based middleware can dedicate components to blocking harmful program propagation, while agent-based middleware may add security policies or omit security and privacy demands.Maté is identified as having a security component, whereas several agent-based solutions lack stated security or privacy requirements.
5) Tuple-spaces:
Tuple-space and database-oriented middleware support shared or queryable sensor data, but many surveyed implementations lack security and privacy mechanisms; application-specific designs do not generalize well.
- 5) Tuple-spaces:: Tuple-space middleware gives each component a shared data repository that applications can access simultaneously, but surveyed examples provide no security or privacy mechanism.LIME, TinyLIME, and TS-Mid are identified as lacking such mechanisms.
- 5) Tuple-spaces:: Database-oriented middleware treats sensor networks as virtual relational databases queried with SQL-like languages, yet GSN, HyCache, and TinyDB lack analyzed security features.The supplied passage states that these solutions do not address security or privacy requirements.
- 5) Tuple-spaces:: Application-specific middleware cannot satisfy general IoT requirements across heterogeneous applications, so its security demands cannot be satisfied integrally.The limitation follows from its specialization for particular application or domain requirements.
- 5) Tuple-spaces:: MQTT is a lightweight protocol for constrained devices and unreliable, low-bandwidth networks, providing identity, authentication, and authorization policies.Its basic approaches include username/password credentials or server validation of client certificates through SSL.
2) Extensible Messaging and Presence Protocol (XMPP):
XMPP supports near-real-time IoT messaging, but confidentiality, integrity, and authentication require complementary security protocols and controls.
- XMPP enables near-real-time exchange of structured, extensible data between network entities through a distributed client-server architecture.
- TLS protects data in motion, while SCRAM supports authentication; together they provide confidentiality and authentication for XMPP deployments.
- XMPP does not provide end-to-end security because data is processed in cleartext on servers and remains exposed across several communication segments.
- IoT security must address confidentiality, integrity, and availability across vulnerable wireless networks and layered system components.
- IoT confidentiality and privacy solutions must account for large data volumes, dynamic access control, identity management, and constrained device resources.
B. Integrity
IoT integrity protection covers physical, data, process, and software failures, but constrained devices complicate the deployment of conventional safeguards.
- IoT integrity protection addresses sabotage, counterfeit components, physical damage, and failures affecting data and system operation.
- Integrity attacks can modify data in storage or transit, motivating read-write protections, authentication, password-based controls, and cryptographic mechanisms.
- Limited processing, power, and battery resources restrict typical cryptographic solutions and leave hardware-based attacks as an additional concern.
- Trusted Platform Modules use symmetric or asymmetric keys for challenge-based integrity solutions.
- Process and software integrity depend on device, communication, algorithm, and configuration protections, including hardware isolation and attestation.
C. Availability
IoT availability is threatened by overload and denial-of-service attacks, while existing protocols and defenses do not eliminate these risks.
- Availability must cover both software service provision and continuous hardware presence compatible with IoT functionality and protocols.
- Constrained devices can experience denial-of-service effects from large volumes of legitimate requests, and CoAP does not resolve this availability problem.
- DoS attacks obstruct device communication and access to network resources, while DDoS attacks combine concurrent DoS attacks.
- Proposed defenses include optimized random sampling, intrusion detection, service-oriented architectures, and distributed designs to improve detection or service uptime.
- No existing defense mechanism can rule out DoS risks, and detection is difficult because attack symptoms can resemble ordinary service unavailability.
D. Privacy
IoT privacy risks grow with pervasive data collection and interconnected devices, requiring protection across technical, governance, and user-control dimensions.
- Ubiquitous IoT data collection raises privacy concerns because devices may expose information about users’ movements, habits, and interactions.
- Privacy protection challenges include device self-awareness, data integrity, authentication, heterogeneity, encryption, cloud security, data ownership, governance, and policy management.
- Perception, network, and application layers provide modularity and scalability, but their segmentation also creates opportunities for malicious activity.
- The survey calls for integral standards, hardware-friendly security implementations, and policies protecting users while regulating manufacturers.
- Security improvements have not kept pace with IoT growth, while rising data volumes increase exposure of sensitive information and leave research opportunities in hardening and detection.