...
首页> 外文期刊>Elektor electronics worldwide >A Big Challenge Safe products in the IoT era
【24h】

A Big Challenge Safe products in the IoT era

机译:IOT时代的一个大挑战安全产品

获取原文
获取原文并翻译 | 示例
           

摘要

Professor Ross Anderson and his colleagues have investigated which measures are necessary to combine traditional product safety with the advent of the IoT. They did this on behalf of the European Commission. The EU is working on new legislation to ensure product safety in the future. They asked Anderson to identify what is necessary for this. Anderson, a professor of security engineering at Cambridge University, carried out the study with his colleagues Eirann Leverett, Senior Risk Researcher, and Richard Clayton, Security Researcher. The report with their findings was published in 2017 [1]. Anderson and his colleagues concluded that we still have a long way to go. The crux of the issue is that the way we ensure the safety of physical products is fundamentally different from how we ensure the safety of digital technologies. Products are tested and inspected before they are put on the market, and this is assured by a safety certificate or an approval mark. If there are significant changes to the product, it must be certified again. By contrast, the safety of software is essentially dependent on changes. Software is constantly monitored and regularly revised with patches and updates. Anderson addressed this in more detail in a presentation on their study at the Chaos Communication Congress (CCC) in December 2019 [2]. He called this the ‘trilemma’ of IoT products. If you stick to pre-market certification, you cannot modify your software, which means your product is unsafe. If you modify your software, you lose your certification. And if you combine certification with updating, which means going through the certification process again after each software update, the costs go through the roof.
机译:Ross Anderson教授和他的同事们调查了将传统产品安全与IOT的出现结合起来的措施。他们代表欧盟委员会做到这一点。欧盟正在致力于新的立法,以确保未来的产品安全。他们要求安德森确定这是必要的。剑桥大学安全工程教授安德森开展了他的同事Eirann Leverett,高级风险研究员,以及保安研究员的高级风险研究员和Richard Clayton。与他们的调查结果报告发表于2017年[1]。安德森和他的同事得出结论,我们还有很长的路要走。问题的关键是我们确保物理产品安全的方式根本与我们如何确保数字技术的安全性不同。产品在投入市场之前进行测试和检查,这是安全证书或批准标记的保证。如果产品有重大更改,则必须再次认证。相比之下,软件的安全基本上取决于变化。软件不断监控并定期使用修补程序和更新修改。安德森在2019年12月在混乱通信大会(CCC)的研究中有更多细节讨论了这一点[2]。他称这是IoT产品的“Trilemma”。如果您坚持出市前的认证,则无法修改您的软件,这意味着您的产品不安全。如果修改软件,则丢失您的认证。如果您将认证与更新相结合,这意味着在每个软件更新后再次通过认证过程,费用通过屋顶。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号