160 likes | 171 Views
Explore the challenges, legal aspects, and security strategies related to data privacy in IoT-based smart cities worldwide. Learn about security frameworks, vulnerabilities, and best practices to safeguard sensitive data in the digital age.
E N D
فایل ارائه حاضر توسط مرکز تحقیقات فناوری «اینترنتی از اشیاء » در ایران برای استفاده در سایت قرار داده شده است.
Smart Cities around the world • Map of the 107 cities worldwide receiving ICF awards from 1999~2012 Source: Smart City Development Experience Research of Each Country –ICF Case Study Analysis, Lin Zi Xian (2012)
What is a Smart city? • “Smart” = efficient (time, resources) • Homes/buildings, Transportation, healthcare, schools, IT… • Energy, Environment • Economy, Governance • “Improved living” • Sensors’ [System] • People – use, share, crowdsource
Some questions- • Who owns the data in Internet of Things? • Who has control of it? • When it comes to privacy, how do I opt out if all these different devices collecting different data elements and how do I control where it goes? • What is more important - Efficiency or Privacy ; Usability or heterogeneity?
Expanded Attack Surface of an IoT System Legal Framework
Security Challenges in IoT • Shared data which has value – Big Data • Attacks on end point devices, quickly propagate • Open ecosystem • Wider and more prone communication channel; domino • No User Interface • Compatibility of devices in the system, No specific protocol • No specific OS for IoT devices • Security failures can be “life-threatening” • Product Reliability, Zero error • Not enough computing power
Securing an IoT System • IoT Product Security needs - Data Handling Framework • “Establish and manage trusted relationships between devices, and over the full lifecycle of these devices, ..(to) achieve greater control over the data and the sources and the consumers of that data.” • Access Control & Account Management (for devices w/o UI?) • Segregation of networks and accounts • Use of Secure protocols for data transmission • Firewall management & Antivirus updates • Providing remote updates for IoT devices
Security first approach • “Treat security as fundamental element of Product Value Proposition” • Prioritizing Security over Speed-to-market • Security consideration as part of product design • IoT security teams and experts • Collaborating with other vendors • Partnering with security firms • Privacy enhancing technologies – RnD • New models and the architectures
Framework changes • Needs: • Finer Privacy policy • Security standards • Privacy Regulations and Compliance • Legal Framework • Global Status: • US • Europe • ROW
ICT & Indian Governance • UID, ePanchayats • data.gov.in Open Government Data (OGD) Platform • Telecom Sector, Surveillance • Current State/Learnings: • Information Management • Access control & Network Protection • Data Security, Cyber Security • Policy & Regulation • “Privacy”? Sensitive data – Section 72 of Information Technology Act. 2000, IT Amendment Act 2008
Happenings • “Govtturns to private firms for ideas on smart city plan” • “Cisco to build Visakhapatnam as first ‘smart city’” • “Govtplans Wi-Fi hotspots in 25 cities by June” • “Noida expressway to get smart traffic management system” • “Solutions for Slum Areas in Smart Cities” • Draft Concept Note on Smart Cities – as on 10-09-2014 (link)
Draft Concept Note on Smart Cities Includes: • Physical & Social Infrastructure, Economy, • Social Services, ICT, Smart Governance, • Financing, PPP Model, Trusts etc., • Operational Procedures, Benchmarks, • Urbanisation Policy, Disaster Management • Case Study – Amanora Pune
Data Privacy for Smart Cities in India • Needs: • Improved Data Centers , Networks, Data handling, Security standards • Capacity building – Awareness of people • Finer Privacy policy • Practitioner code of ethics • Datensparsamkeit • Data value chain • Intelligent (context -aware) privacy mechanisms • Privacy Regulations and Compliance, City charters • Legal Framework • Prioritization – time vs ….