European Commission logo
español español
CORDIS - Resultados de investigaciones de la UE
CORDIS

aCtive sEcurity foR connecTed devIces liFecYcles

Descripción del proyecto

Un alto nivel de seguridad para los interesados en el internet de las cosas

El internet de las cosas (IdC) brinda numerosas oportunidades empresariales. Sin embargo, también conlleva nuevos retos, como una seguridad comprometida, lo que aumenta la importancia de la gestión de la seguridad de la infraestructura del IdC. En este sentido, el equipo del proyecto financiado con fondos europeos CERTIFY definirá un enfoque metodológico, tecnológico y organizativo para la gestión del ciclo de vida de la seguridad del IdC. Además, diseñará e implementará un marco de gestión del ciclo de vida de la ciberseguridad para los dispositivos del IdC que funcionará recopilando y compartiendo información tanto de forma interna como externa. El trabajo del proyecto allanará el camino hacia planteamientos innovadores sobre la privacidad y la seguridad en un amplio espectro de entornos del IdC.

Objetivo

Cyber-attacks get more sophisticated every day, thus affecting a large number of IoT-related infrastructures and raising security and privacy concerns of consumers and businesses. Security management of IoT infrastructures encompassing full lifecycle of products and continuous certification are fundamental tools to guarantee a high-level of security, as emphasized by the European Union Agency for Cybersecurity (ENISA) Cybersecurity Act (CSA).
CERTIFY defines a methodological, technological, and organizational approach towards IoT security lifecycle management based on (i) security by design support, (ii) continuous security assessment and monitoring (iii) timely detection, mitigation, and reconfiguration, (iv) secure IoT Over-The-Air (OTA) updating, and (v) continuous security information sharing.
To ensure the security compliance throughout the lifetime of the device, we propose the design and implementation of a cybersecurity lifecycle management framework for IoT devices. The framework is intended to support the device security management by collecting and sharing relevant security information both internally (via monitoring and self-assessment services) and externally, e.g. by interacting with device manufacturers, threat databases, certification authorities, Information Sharing and Analysis Centres (ISACs), and more. The received information is meant to support the local decision making with respect to the security, monitoring, updating and configuration of the device. Moreover, this information sharing will enable a continuous risk assessment, gathering evidence that could agile future certifications.
CERTIFY's provides IoT stakeholders with mechanisms achieving high-level of security. CERTIFY will detect and respond to a wide spectrum of attack, in a collaborative/decentralized fashion. CERTIFY will validate the architecture through cutting-edge use-cases and pave the way towards innovative security in a broad spectrum of IoT environments.

Palabras clave

Coordinador

UNIVERSIDAD DE MURCIA
Aportación neta de la UEn
€ 648 937,50
Dirección
AVENIDA TENIENTE FLOMESTA S/N - EDIFICIO CONVALECENCIA
30003 Murcia
España

Ver en el mapa

Región
Sur Región de Murcia Murcia
Tipo de actividad
Higher or Secondary Education Establishments
Enlaces
Coste total
€ 648 937,50

Participantes (10)

Socios (2)