首页> 外文会议>International conference on enterprise information systems >Security Requirements and Tests for Smart Toys
【24h】

Security Requirements and Tests for Smart Toys

机译:智能玩具的安全性要求和测试

获取原文
获取外文期刊封面目录资料

摘要

The Internet of Things creates an environment to allow the integration of physical objects into computer-based systems. More recently, smart toys have been introduced in the market as conventional toys equipped with electronic components that enable wireless network communication with mobile devices, which provide services to enhance the toy's functionalities and data transmission over Internet. Smart toys provide users with a more sophisticated and personalised experience. To do so, they need to collect lots of personal and context data by means of mobile applications, web applications, camera, microphone and sensors, for instance. All data are processed and stored locally or in cloud servers. Naturally, it raises concerns around information security and child safety because unauthorised access to confidential information may bring many consequences. In fact, several security flaws in smart toys have been recently reported in the news. In this context, this paper presents an analysis of the toy computing environment based on the threat modelling process from Microsoft Security Development Lifecycle with the aim of identifying a minimum set of security requirements a smart toy should meet, and propose a general set of security tests in order to validate the implementation of the security requirements. As result, we have identified 16 issues to be addressed, 15 threats and 22 security requirements for smart toys. We also propose using source code analysis tools to validate seven of the security requirements; three test classes to validate seven security requirements; and specific alpha and beta tests to validate the remaining requirements.
机译:物联网创建了一个允许将物理对象集成到基于计算机的系统中的环境。最近,智能玩具已被引入市场,作为配备有能够与移动设备进行无线网络通信的电子组件的常规玩具,该电子组件提供了增强玩具功能性和通过Internet进行数据传输的服务。智能玩具为用户提供了更复杂和个性化的体验。为此,他们需要通过例如移动应用程序,Web应用程序,相机,麦克风和传感器收集大量的个人和上下文数据。所有数据都在本地或云服务器中处理和存储。自然,这引起了对信息安全和儿童安全的担忧,因为未经授权访问机密信息可能会带来许多后果。实际上,最近有新闻报道了智能玩具中的一些安全漏洞。在这种情况下,本文基于Microsoft安全开发生命周期中的威胁建模过程,对玩具计算环境进行了分析,目的是确定智能玩具应满足的最低安全要求集,并提出了一组通用的安全测试为了验证安全要求的执行。结果,我们确定了要解决的16个问题,15个威胁和22个安全性要求。我们还建议使用源代码分析工具来验证其中的七个安全要求。三个测试类别,以验证七个安全要求;以及特定的alpha和beta测试以验证其余要求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号