Securing the Identity of Things (IDoT) for the Internet of Things

Neil Chapman of ForgeRock

In its recent report, The Identity of Things (IDoT) for the Internet of Things, Gartner lays out how it believes the Internet of Things (IoT), or what is often now referred to as the Internet of Everything (IoE), cannot and will not prosper unless organisations knuckle down and come to grips with how to manage multiple identities.

The report then goes on to detail how today’s identity and access management technologies cannot provide the scale or manage the complexity that IoT brings to these organisations, further complicating the problem.

A strikingly common misconception I come across in the industry, says Neil Chapman of ForgeRock, is that IoT is just about introducing different types of devices into business scenarios. It’s not.

Businesses looking to harness IoT in fact require a completely different approach to viewing and implementing processing, analytics, storage, and communications. Certainly, identifying ‘who’s who, what’s what, and who gets access to what’ is one aspect. But how this is processed, managed, protected, stored, and communicated is a whole new kettle of fish for businesses.

Identity management

Identity management is not just about securing IoT devices; it must rationally secure and make sense of the entire environment, from customers to partners, websites to webpages, to mobile devices, apps, and the cloud. This is by no means a comprehensive list – just one that will hopefully give you an idea of the number of links in the chain.

Static and portable devices need to communicate. Human-to-Machine (H2M) and Machine-to-Machine (M2M) identification and interaction must also take place. Without the right model, organisations make data vulnerable to security breaches.

Securing the Identity of Things in the Internet of Things demands a new way of thinking about connectivity and security.

Back in an age where companies only connected computers to other trusted computers, life was far simpler. Legacy systems were created to maximise internal security, keeping threats well outside. Security was perimeter-based. Firewalls protected organisations. Identity was about internal stakeholders, creating identities for employees to access the right information and services securely. Businesses used to have to cope with, on average, 20-40,000 identities.

However, the dawning of the IoE has turned this on its head. Organisations everywhere need systems that provide secure access externally, to customers, partners, and other important stakeholders. This means systems have to cope with millions of identities, and most of them outside any firewall. Static and portable devices need to talk to each other, and then there’s H2M and M2M identification and interaction on top of that.

Customers need to access company systems via multiple devices or objects and expect a bespoke user experience based on how, when, and where they access services. This requires a single, secure platform to unify the entire company ecosystem and enable a straightforward, repeatable way of securing an increasing number of devices. Building a platform that supports and unifies the entire ecosystem is challenging enough, but organisations also need to be able to support new services, new devices, and new infrastructure on the back end.

So how do businesses protect data they can’t see as it’s communicated between machines and other parts of the ecosystem?

Contextual knowledge is power

Contextual intelligence and awareness can add significant value to digital services. For instance, a connected car can remember the personal preferences of every driver or the Sony Smart B Trainer can offer personalisation to support the user’s individual fitness goals. This new data enables companies to better understand their customers, as well as protect them. Devices come to know what to expect from you as a typical user — and notice abnormal behaviour that triggers enhanced security measures. This kind of contextual intelligence also opens up revenue opportunities for cross-selling, upselling, and delivering personalised services.

Encrypting and authenticating this data is essential; however, it is also imperative to understand who accesses data and how, as well as where and when they access it. Knowing this information will help authenticate the user and confirm that their behaviour is in-line with past behaviour.

Real-time contextual clues, in addition to credentials, provide organisations with the tools needed to decide whether to grant access and how much access to allow. For instance, if a system detects a login attempt with correct credentials, but from an unrecognised IP address or at an uncharacteristic time of day, it can activate additional security measures such as requesting personal security questions or sending verification codes to a user’s mobile phone.

The speed at which organisations get to reap the rewards of IoT lies firmly in their hands. The Internet of Things requires oganisations to understand and manage an external-facing identity management platform effectively. Unless organisations can link objects, devices, and new mobile and social apps to a single security platform, they won’t be able to truly harness the enormous growth potential offered by IoT. At the dawn of IDoT, that’s one quick way for an IDioT to watch the sun set on their business.

The author is Neil Chapman, senior vice president & managing director EMEA, ForgeRock

You can comment on this article here or on Twitter:     @m2mnow     OR      @jcm2m

RECENT ARTICLES

5th Edition Connected Africa announces Telecom Innovation & Excellence Awards 2024

Posted on: April 19, 2024

The International Center for Strategic Alliances (ICSA) has announced the 5th Edition Connected Africa- Telecom Innovation & Excellence Awards 2024, set to be held on 22 May 2024 in Johannesburg, South Africa. Under the theme “Building a Connected Global Economy,” the summit aims to influence the telecom in Africa. With a focus on fostering forward-thinking

Read more

Facilio launches refrigerant tracking and leak detection software

Posted on: April 19, 2024

Property operations software firm Facilio has announced the launch of its ready-to-deploy refrigerant tracking and leak detection software solution. This is meant for all grocery and convenience store operators who want to implement an automatic leak detection system to identify and mitigate potential refrigerant leaks to achieve 100% compliance.

Read more
FEATURED IoT STORIES

What is IoT? A Beginner’s Guide

Posted on: April 5, 2023

What is IoT? IoT, or the Internet of Things, refers to the connection of everyday objects, or “things,” to the internet, allowing them to collect, transmit, and share data. This interconnected network of devices transforms previously “dumb” objects, such as toasters or security cameras, into smart devices that can interact with each other and their

Read more

The IoT Adoption Boom – Everything You Need to Know

Posted on: September 28, 2022

In an age when we seem to go through technology boom after technology boom, it’s hard to imagine one sticking out. However, IoT adoption, or the Internet of Things adoption, is leading the charge to dominate the next decade’s discussion around business IT. Below, we’ll discuss the current boom, what’s driving it, where it’s going,

Read more

9 IoT applications that will change everything

Posted on: September 1, 2021

Whether you are a future-minded CEO, tech-driven CEO or IT leader, you’ve come across the term IoT before. It’s often used alongside superlatives regarding how it will revolutionize the way you work, play, and live. But is it just another buzzword, or is it the as-promised technological holy grail? The truth is that Internet of

Read more

Which IoT Platform 2021? IoT Now Enterprise Buyers’ Guide

Posted on: August 30, 2021

There are several different parts in a complete IoT solution, all of which must work together to get the result needed, write IoT Now Enterprise Buyers’ Guide – Which IoT Platform 2021? authors Robin Duke-Woolley, the CEO and Bill Ingle, a senior analyst, at Beecham Research. Figure 1 shows these parts and, although not all

Read more

CAT-M1 vs NB-IoT – examining the real differences

Posted on: June 21, 2021

As industry players look to provide the next generation of IoT connectivity, two different standards have emerged under release 13 of 3GPP – CAT-M1 and NB-IoT.

Read more

IoT and home automation: What does the future hold?

Posted on: June 10, 2020

Once a dream, home automation using iot is slowly but steadily becoming a part of daily lives around the world. In fact, it is believed that the global market for smart home automation will reach $40 billion by 2020.

Read more

5 challenges still facing the Internet of Things

Posted on: June 3, 2020

The Internet of Things (IoT) has quickly become a huge part of how people live, communicate and do business. All around the world, web-enabled devices are turning our world into a more switched-on place to live.

Read more