Architectural considerations for IoT device security in the home

Request for comments

As part of our efforts to improve the security of the Internet of Things, we have been working, with a number of other experts from the RIPE community (Sandoche Balakrichenan, Eliott Lear, Jim Reid, Michael Richardson, Phil Stanhope, Peter Steinhäuser and Jan Zorz), on a draft version of the report "Architectural Considerations for IoT Device Security in the Home". The report is intended for internet service providers (ISPs). The goal of the report is to provide practical advice on currently available technologies that can be used to protect home networks, and that can be included when ISPs specify requirements for customer-provided equipment ('CPE devices').

Guidance for ISPs on IoT security

While there are many publications about secure design principles for IoT devices themselves, there is little guidance regarding features and technologies that can be used on CPE devices to protect home networks. Our report focuses on that topic, discussing several key aspects of IoT devices, from secure deployment in home networks to the detection and mitigation of malicious activity. Topics explored include:

  1. Securely introducing the device to the network

  2. Seeing that it gets the access it needs (and no more)

  3. Retrospective assessment of whether the device is behaving appropriately

  4. Some principles device manufacturers should follow to ensure user safety and privacy

  5. Putting it all together

The RIPE IoT Working Group

We have submitted an early version of the report to the RIPE IoT Working Group, with the request that it is accepted this as a (draft) RIPE BCOP document. A decision on acceptance has not yet been made, but it will be discussed at the RIPE IoT Working Group meeting at RIPE 81. RIPE is a community where operators, manufacturers and researchers meet to discuss operational aspects of the Internet. The RIPE IoT Working Group was formed to discuss operational challenges and opportunities presented by the Internet of Things, and we believe that it is the best forum for further discussion of the report. You can find the request, as well as the draft itself, in the mailing list archives.

Request for comments

If you wish to see the report adopted as a Working Group document, or if you have comments about the document itself, please join the RIPE IoT Working Group mailing list and post your comments there, or join us at next week's RIPE session. The IoT Working Group meets on 29 October at 14:00 CET.