By 2020, several tens of billions of connected objects are expected worldwide. The Internet of Things market, whose emergence is inevitable, promises to raise business productivity and make our lives easier, whether in urban planning, road safety, health (e-health or Quantified Self) or energy savings (home automation). Ambient intelligence is in fashion, but what about its security? A brief look at this transformation.
Announced by some as a genuine revolution, the Internet of Things (“IoT”) is not, strictly speaking, an entirely new technology. It would be better described as a “system of systems made up of recent technological innovations and of solutions that are already old”. The Internet will take in the physical world through exchanges of information “from devices present in the real world towards the Internet network”. The IoT is therefore a new way of interconnecting objects with one another (appliances, machines, cars, and so on), and the interoperability of systems will be an essential component of its proper functioning.
In Europe, some cities have already begun putting intelligent urban management systems in place. In Barcelona, connected bins fitted with sensors and a WiFi connection have been installed so that they are emptied only once they are full. The city also has an application that lets motorists check available parking spaces before setting out. Several other projects are also in development, to support the efficient management of public transport, energy and the road network.
Bringing the IoT to market nevertheless carries risks as numerous as the benefits being put forward. This new system has the capacity to absorb every existing insecurity associated with the Internet, in security and privacy as much as in civil liability. Given its capacity to interconnect RFID chips, video surveillance, nanotechnology, biometrics and artificial intelligence, it is easy to imagine the impacts there could be if the standards required for its security and governance are not defined quickly. The problem is that the risk of cyberattacks is liable to rise considerably, in that the reach of the network and the attack surface will both be larger. For a sense of the existing weaknesses in these systems, see this report on IoT security.
Before embarking on the development or acquisition of this technology, we have therefore set out a few points to check and, where appropriate, to provide for contractually:
- How does identification of the object take place?
- Who is responsible for assigning identifiers?
- Where can the information about the objects be found?
- How is the confidentiality of the information carried by the connected objects protected?
- Who is accountable for these objects?
- To whom are the responsibilities for the security of these objects assigned, and how often are they checked and maintained?
