<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Kévin Guérin, Auteur</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/author/kevin-guerin/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/author/kevin-guerin/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Mon, 12 Jul 2021 08:54:56 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>Kévin Guérin, Auteur</title>
	<link>https://www.riskinsight-wavestone.com/author/kevin-guerin/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>IAM of Things, un marché émergeant mais un besoin déjà présent</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/02/iam-of-things-un-marche-emergeant-mais-un-besoin-deja-present/</link>
		
		<dc:creator><![CDATA[Kévin Guérin]]></dc:creator>
		<pubDate>Mon, 17 Feb 2020 13:28:16 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[IoT & smart products]]></category>
		<category><![CDATA[CIAM]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[IAMoT]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[SI]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=12648</guid>

					<description><![CDATA[<p>Dans un précédent article, nous avons pu découvrir l’IAM of Things (IAMoT) et souligner les très fortes interactions avec les domaines de l’IAM et du Customer IAM (CIAM). Dans ce nouvel article, nous allons maintenant mettre en évidence les lacunes...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/02/iam-of-things-un-marche-emergeant-mais-un-besoin-deja-present/">IAM of Things, un marché émergeant mais un besoin déjà présent</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Dans <a href="https://www.riskinsight-wavestone.com/en/2019/01/what-is-iam-of-things/">un précédent article</a>, nous avons pu découvrir l’IAM <em>of Things</em> (IAMoT) et souligner les très fortes interactions avec les domaines de l’IAM et du <em>Customer</em> IAM (CIAM). Dans ce nouvel article, nous allons maintenant mettre en évidence les lacunes actuelles du marché à couvrir les besoins de l’IAMoT.</p>
<p>&nbsp;</p>
<h2>Quels besoins pour l’IAMoT ?</h2>
<p>Il est possible de définir l’IAM comme une discipline permettant de « <strong>donner les bons droits, aux bonnes personnes, aux bons moments</strong> ». L’IAMoT vient ajouter une composante à cette définition pour permettre de « donner les bons droits, <strong>aux bonnes personnes et aux bons objets</strong>, aux bons moments ».</p>
<p>Mettre en œuvre des solutions pour permettre une gestion adaptée des identités des objets connectés se traduit donc par le besoin de prendre en compte :</p>
<ul>
<li>La gestion des identités des objets et de leur état (<a href="https://www.riskinsight-wavestone.com/en/2019/09/life-cycle-iot-security/">voir l’article</a> détaillant le cycle de vie des objets) ;</li>
<li>La gestion du contrôle d’accès et des habilitations :
<ul>
<li>des objets sur le SI et sur ses données ;</li>
<li>des objets sur les autres objets et leurs données ;</li>
<li>des employés/partenaires de l’entreprise sur l’objet et ses données ;</li>
<li>des clients finaux sur l’objet et ses données ;</li>
</ul>
</li>
<li>La gouvernance des identités des objets et la pertinence des droits associés dans le temps.</li>
</ul>
<p>Tout comme pour l’IAM, pour chacun de ces domaines, il va être nécessaire de définir des processus, une organisation associée et des outils adaptés aux contraintes technologiques du projet.</p>
<p>La question est donc maintenant : vers quelles solutions s’orienter pour répondre à mes besoins ?</p>
<p>&nbsp;</p>
<h2>Des plates-formes IoT orientées connectivité et gestion de flotte</h2>
<p>Le premier réflexe est de se tourner vers les services que peuvent fournir les plates-formes de gestion d’objets connectés.</p>
<p>En étudiant ces plates-formes plus en détail, nous avons fait le constat que leur priorité est déjà de couvrir les services essentiels pour la gestion de la flotte des objets connectés :</p>
<ul>
<li>gérer la connectivité multi-protocolaire des objets avec le SI de l’entreprise (SigFox, LoRa, 3/4/5G…) ;</li>
<li>maîtriser l’inventaire des objets déployés et en assurer la configuration ou la mise à jour via un module de « Device Management » (LWM2M, OMA-DM, TR-069/CWMP…) ;</li>
<li>permettre la remontée et la mise à disposition des données générées par l’objets (DTLS, CoAP, MQTT, AMQP…).</li>
</ul>
<p>Ces fonctions s’accompagnent de solutions techniques d’authentification de l’objet sur les plates-formes mais celle-ci n’offrent aucune opportunité de couverture des besoins métier.</p>
<p>Dans ce cas, que font les acteurs traditionnels de l’IAM et du CIAM ? Puis-je me tourner vers leurs solutions qui sont aujourd’hui orientées sur la couverture des besoins des utilisateurs ?</p>
<p>&nbsp;</p>
<h2>Des marchés IAM et CIAM en mutation pour couvrir une infime partie du besoin IoT</h2>
<p>Les éditeurs historiques de solutions IAM et CIAM ont compris l’énorme opportunité que représente l’IAMoT et orientent progressivement leurs offres et le discours associé sur ce marché. Néanmoins, nous constatons qu’ils ne couvrent encore que très partiellement les besoins identifiés ci-dessus et que selon leur capacité à innover le délai de mise en œuvre des nouveautés pourra être important.</p>
<p>Forts de leurs savoir-faire technologiques, ils se concentrent aujourd’hui quasi-exclusivement sur le volet contrôle d’accès. Ils offrent ainsi des solutions pertinentes pour permettre l’authentification applicative des objets sur le SI et la délivrance de jetons d’autorisation dont la gestion du contenu relève encore d’un défi propre à chaque projet. Sur les autres volets de l’IAMoT tels que la gestion de l’identité et de l’état des objets, la gestion du modèle de rôles liant objets / utilisateurs / identités internes / identités externes, ou la gouvernance des droits dans le temps, il est urgent que leur offre s’étoffe.</p>
<p>Dès lors, comment peut-on couvrir des besoins IAMoT bien présents malgré les lacunes du marché ?</p>
<p>&nbsp;</p>
<h2>Une hétérogénéité des usages rendant complexe la normalisation des pratiques et la standardisation des solutions</h2>
<p>La diversité des usages et donc des modes de fonctionnement des objets connectés est évidemment à l’origine de la difficulté des éditeurs à proposer une offre générique adaptée à ses clients. Mais les projets IoT sont là et il n’est pas envisageable d’attendre que le marché prenne forme.</p>
<p>Mais si l’harmonisation est actuellement impossible au niveau global du marché, un effort peut être consenti au niveau de l’entreprise afin d’essayer d’harmoniser les réponses pour l’ensemble de ses usages IoT. Ainsi tout en cherchant à tirer parti de ce que propose le marché IAMoT, il est nécessaire d’envisager le développement modulaire des briques manquantes et en priorité celles ayant trait à la gestion des relations « objets / utilisateurs / identités internes / identités externes ». Attention toutefois à ne pas succomber aveuglement à l’utilisation des <em>frameworks</em> bas-niveau propriétaires proposés par les plates-formes IoT. Chacun devra être vigilant à conserver un niveau d’abstraction et d&#8217;autonomie suffisant pour ne pas être lié <em>ad vitam æternam</em> à un éditeur unique. Ce point d’attention est d’autant plus important dans un marché peu mature et en explosion où les bonnes idées se font et se défont.</p>
<p>&nbsp;</p>
<h2>Que faut-il retenir ?</h2>
<p>Aucune solution du marché ne couvre l’intégralité des besoins fondamentaux de l’<em>IAM of Things</em>. Les plates-formes IoT se limitent aux fonctions de connectivité des objets, de gestion de flotte et de remontée de données. Les plates-formes IAM et CIAM n’offrent quant à elles que des réponses technologiques aux besoins d’authentification et d’autorisation.</p>
<p>Afin de combler les manques, chaque entreprise devra évaluer le besoin de se lancer dans le développement de ses propres modules applicatifs. Un effort tout particulier devra être entrepris pour atteindre un niveau adapté de généricité des modules pour l’ensemble de leurs usages et d’indépendance vis-à-vis des solutions éditeur.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/02/iam-of-things-un-marche-emergeant-mais-un-besoin-deja-present/">IAM of Things, un marché émergeant mais un besoin déjà présent</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>A life cycle approach for IoT security</title>
		<link>https://www.riskinsight-wavestone.com/en/2019/09/life-cycle-iot-security/</link>
		
		<dc:creator><![CDATA[Kévin Guérin]]></dc:creator>
		<pubDate>Tue, 17 Sep 2019 20:59:03 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[IoT & Consumer goods]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[Life cycle]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=12089</guid>

					<description><![CDATA[<p>As with employee or customer identity management, the life cycle approach of connected objects within the Internet of Things (IoT) makes it possible to address all security issues. This article presents the key elements of this methodology and the major...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2019/09/life-cycle-iot-security/">A life cycle approach for IoT security</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>As with employee or customer identity management, the life cycle approach of connected objects within the Internet of Things (IoT) makes it possible to address all security issues. This article presents the key elements of this methodology and the major points to be addressed at each event in the life of a connected object.</p>
<h2>What are the risks in the iot world?</h2>
<p>The IoT advent has enabled millions of new potential technological advantages for consumers and companies. However, with <strong>these new advantages</strong>, certain risks are higher in the field of connected devices.</p>
<p>&nbsp;</p>
<figure id="post-12098 media-12098" class="align-none"><img fetchpriority="high" decoding="async" class="aligncenter wp-image-12098 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image1.png" alt="" width="1441" height="977" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image1.png 1441w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image1-282x191.png 282w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image1-768x521.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image1-58x39.png 58w" sizes="(max-width: 1441px) 100vw, 1441px" /></figure>
<p style="text-align: center;"><em>Figure 1 – Most significant risks in the IoT world</em></p>
<p>&nbsp;</p>
<p>These business and technological risks which could cause significant potential impacts for consumers and companies, should be identified <strong>from the upstream phases of an IoT project.</strong></p>
<p>&nbsp;</p>
<h2>Which project methodology to choose in order to ensure security of connected devices?</h2>
<p>Even though security issues to address in IoT project are common for all project, we think necessary <strong>to structure reflections regarding the life cycle of the connected device</strong>.</p>
<p>The diagram below highlights all the stages of their life cycle.</p>
<p>&nbsp;</p>
<p><img decoding="async" class="aligncenter wp-image-12096 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image2.png" alt="" width="1479" height="755" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image2.png 1479w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image2-374x191.png 374w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image2-768x392.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image2-71x36.png 71w" sizes="(max-width: 1479px) 100vw, 1479px" /></p>
<p style="text-align: center;"><em>Figure 2- A life cycle enabling to address all the security issues</em></p>
<p>&nbsp;</p>
<p>Let us review  some important issues raised by this approach:</p>
<ol>
<li><strong>Design, manufacturing, and distribution phases</strong></li>
</ol>
<p>This first phase addresses issues related to the design of the object, regarding business stakes, targeted users (B2B, B2C, B2E), deployment environment (controlled or not) and criticality of the use:</p>
<ul>
<li>What are the regulatory constraints related to the use of the object?</li>
<li>What identity should be labeled and how is this identity created?</li>
<li>How is the security related to object’s hardware and software secrets and data stored in the object?</li>
<li>How is the state of a device on the management platform initialized, ensuring it has no right on the IS before the initialization step?</li>
</ul>
<p>The determined choices during the manufacturing phases are crucial because they determine characteristics and capacities of the device. Some of them will therefore be immutable throughout the life of the device and will impose strong constraints in the following steps.</p>
<p>Furthermore, although the end of the manufacturing phase marks the beginning of the existence of the device on the device management platform, there is still no reason to consider an interaction with the IS.</p>
<p>Any interaction before the device’s association to a user (physical or moral) would mean that it has been diverted in the distribution phase. <strong>Any access to the IS before the initialization phase must be strictly limited</strong> to the firmware update (version N installed at the factory and version N+1 available when unpacking) or to the pre-customization of the object (operating settings or injection of secrets not related to the user). Beyond IS security, an object that is unused before any pairing phase will reduce the risk of theft of that object in the factory or during distribution<em>.</em></p>
<ol start="2">
<li><strong>Initialization phase</strong></li>
</ol>
<p>Initialization phase materializes the association phase (also named pairing) between a device and its owner. Any data generated by the device (or realized action) is then declared as belonging or attributed to its owner..</p>
<p>Therefore, the main challenge is to <strong>ensure a reliable level of user / object association corresponding to the following business stakes:</strong></p>
<ul>
<li>Low level of association required (low-risk situation): An employee declares the usage of an attendance identification system in the meeting room;</li>
<li>Strong level of association required (high-risk situation): when purchasing a connected lock, a consumer provides a serial number and a one-time secret code to allow his mobile application to unlock the door of his home.</li>
</ul>
<p>It is very important to find a balance between the user experience and security.</p>
<p>The robustness of the expected association will <strong>vary according to the nature of the services to which the customer has subscribed.</strong></p>
<ol start="3">
<li><strong>Use phase</strong></li>
</ol>
<p>The definition of the use cases of connected devices is the most anticipated step by companies, however <strong>many aspects of security remain neglected</strong>.</p>
<p>Besides business use cases, additional questions must be raised:</p>
<ul>
<li>How can regular updates of the connected device be implemented?</li>
<li>What are the different actors of the company roles regarding the maintenance of the device operating system layer: the application layer, and the network module?</li>
<li>What is the detection and response requirements for a compromised device?</li>
<li>How to take advantage of the company SIEM (<strong><em>S</em></strong><em>ecurity <strong>I</strong>nformation and <strong>E</strong>vent <strong>M</strong>anagement</em>) and SOC (<strong><em>S</em></strong><em>ecurity <strong>O</strong>peration <strong>C</strong>enter</em>) for technical security incidents (software compromise of the device) and for business security incidents (misuse or theft of a device)?</li>
<li>How can backward compatibility of protocols and APIs used by different versions of the same type of device be maintained?</li>
<li>What are the models of roles and interactions between different populations acting on the object?</li>
</ul>
<p>Concerning this last question, and as an example, the scheme below illustrates the potential complexity stemming from the interactions and roles model such as a connected vehicle.</p>
<p>&nbsp;</p>
<p><img decoding="async" class="aligncenter wp-image-12094 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image3.png" alt="" width="1464" height="725" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image3.png 1464w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image3-386x191.png 386w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image3-768x380.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image3-71x35.png 71w" sizes="(max-width: 1464px) 100vw, 1464px" /></p>
<p style="text-align: center;"><em>Figure 3- Example of a roles and interactions model with a connected vehicle (research carried out with IMT Atlantique)</em></p>
<p>&nbsp;</p>
<ol start="4">
<li><strong>Resale phase</strong></li>
</ol>
<p>Today, the resale is <strong>the most neglected</strong> phase during the device design. This event essentially concerns devices for B2C markets and raises very specific issues:</p>
<ul>
<li>How to detect and handle the resale of a device between individuals?</li>
<li>What privacy-by-design principles should be implemented to protect secrets and data from the former owner while resetting a device?</li>
<li>How can access rights of the former owner of the device be removed?</li>
<li>What are the ways to reset a device in a stable and clean state before re-pairing?</li>
</ul>
<p>The major difficulty involves <strong>the detection of the resale event</strong> which triggers the device/user unpairing processes, reset the state of the object, etc.</p>
<p>Our experience allows us to identify some circumstances that could indicate a change of ownership.</p>
<p>&nbsp;</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-12092 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image4.png" alt="" width="1463" height="509" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image4.png 1463w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image4-437x152.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image4-768x267.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image4-71x25.png 71w" sizes="auto, (max-width: 1463px) 100vw, 1463px" /></p>
<p style="text-align: center;"><em>Figure 4 – Examples of events that could indicate the change of ownership</em></p>
<p>&nbsp;</p>
<p>Despite such examples, we witness that resale remains a complex event to identify. Thus, some companies choose <strong>not to authorize the device resale</strong> via a lease contract. The device must therefore be returned when the service is terminated; otherwise it must be made unusable. This model is comparable to renting an Internet box with an ISP (<strong>I</strong>nternet <strong>S</strong>ervice <strong>P</strong>rovider).</p>
<ol start="5">
<li><strong>End-of-life and recycling</strong></li>
</ol>
<p>Although<strong> essential</strong>, we currently have little perspective on this step, however there are multiple stakes:</p>
<ul>
<li>Revoke access rights on the Information System of an end-of-life device;</li>
<li>Renew the identity of a recycled device;</li>
<li>Ensure the replacement of a defective object by re-associating a new one with the same owner and the same data;</li>
<li>Detect the inactivity of a device to trigger a replacement.</li>
</ul>
<p>The main risks are <strong>the loss of access control over the company IS</strong> via identifiers associated with recycled devices, <strong>the disclosure of personal data</strong> of the former owner or <strong>the additional cost of license</strong> for data generated by devices considered out of the scope.</p>
<p>&nbsp;</p>
<h2>A variable capacity of action in response to the risks according to the nature of the project</h2>
<p>At this stage of your reading, you probably think that this article is not your concern because you purchase pre-conceived connected modules or devices.</p>
<p>Unfortunately this mindset is wrong –  you are still exposed to the same risks! Even though you only purchase or welcome connected devices in your IS, by addressing all the issues above you will be able to feed the contents of requirement specifications to suppliers.</p>
<p>To conclude, <strong>whatever the nature of your IoT project</strong>, it is essential to design your object by structuring the reflections around its life cycle: from its manufacturing to its disposal. It is therefore necessary, at each stage, to address all the relevant security themes: Network / application / hardware security, standards, detection and reaction, governance, maintenance in security condition&#8230;</p>
<p>&nbsp;</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-12090 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image5.png" alt="" width="807" height="589" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image5.png 807w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image5-262x191.png 262w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image5-768x561.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/09/image5-53x39.png 53w" sizes="auto, (max-width: 807px) 100vw, 807px" /></p>
<p style="text-align: center;"><em>Figure 5 – Main security themes for an IoT project</em></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2019/09/life-cycle-iot-security/">A life cycle approach for IoT security</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>What is IAM of Things?</title>
		<link>https://www.riskinsight-wavestone.com/en/2019/01/what-is-iam-of-things/</link>
		
		<dc:creator><![CDATA[Kévin Guérin]]></dc:creator>
		<pubDate>Mon, 14 Jan 2019 08:55:54 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[CIAM]]></category>
		<category><![CDATA[customer IAM]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[IAM of Things]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[IoT]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=11499/</guid>

					<description><![CDATA[<p>Identity and IoT, what stakes? Connected objects bring a whole range of new perspectives for the evolution of processes and working methods for businesses and users. Indeed, they are now able to interact with their environment to exchange information or...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2019/01/what-is-iam-of-things/">What is IAM of Things?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h2>Identity and IoT, what stakes?</h2>
<p>Connected objects bring a whole range of new perspectives for the evolution of processes and working methods for businesses and users. Indeed, they are now able to interact with their environment to exchange information or perform actions. These interactions are characterized by relationships between corporate information systems, employees, end users and even other objects. To ensure the security of such exchanges, it is absolutely necessary to implement access control mechanisms which implies<strong> knowing and managing the identities of all connected objects of a fleet as well as their users.</strong></p>
<p>This identity management discipline is well known within companies and linked to the IAM field (Identity &amp; Access Management), that means the lifecycle management of the identities of employees and partners (traditional IAM) or end clients (<a href="https://www.riskinsight-wavestone.com/en/2017/01/ciam-pilier-de-transformation-business/">Customer IAM</a>). It must now be applied to the fleets of connected objects: it is the <strong>IAM <em>of Things</em></strong> (IAMoT).</p>
<figure id="post-11493 media-11493" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-11493 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/01/image-1.png" alt="" width="1924" height="1009" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/01/image-1.png 1924w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/01/image-1-364x191.png 364w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/01/image-1-768x403.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/01/image-1-71x37.png 71w" sizes="auto, (max-width: 1924px) 100vw, 1924px" /></figure>
<figure id="post-11497 media-11497" class="align-none"></figure>
<p style="text-align: center;"><em>Figure 1 – Traditional IAM, Customer IAM and IAMoT: three strongly related fields</em></p>
<p>&nbsp;</p>
<h2>A connected object, yes&#8230; but to WHAT?</h2>
<p>The interactions between a connected object and its environment can be grouped into 3 main categories.</p>
<p>&nbsp;</p>
<h3>1 &#8211; An object connected to the company’s IS</h3>
<p>This is the first use case that comes to mind. Each object communicates with the IS via <strong>a unique identity that represents it and is associated to its access rights</strong>. This implies the implementation of principles for the creation, referencing, management, control and piloting of theses identities. We must <strong>know the condition of an object or the identity of its owner at any time.</strong></p>
<p>In a standard technological chain such as “objects – relays – IoT platform – applications”, <strong>the IoT platform offers a central point for managing all objects identities.</strong></p>
<p>In this context, it is also essential to manage the authentication of objects to applications, and therefore to define the principles of creating the secrets that will be used.</p>
<figure id="post-11495 media-11495" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-11495" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/01/image-2.png" alt="" width="250" height="397" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/01/image-2.png 547w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/01/image-2-120x191.png 120w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/01/image-2-25x39.png 25w" sizes="auto, (max-width: 250px) 100vw, 250px" /></figure>
<p style="text-align: center;"><em>Figure 2 – Standard technological chain</em></p>
<p>&nbsp;</p>
<h3>2 &#8211; An object used by customers</h3>
<p>For this type of object, appears <strong>a strong relationship with the <em>Customer IAM</em> field</strong>. Indeed, the object must be able to <strong>verify the user’s identity</strong> against the CIAM and <strong>determine the services to which the customer has subscribed. </strong></p>
<p>In case of shared usage of the same object, <strong>a role and data model involving different types of end-users</strong> must also be considered.</p>
<p>Let’s take the example of a connected vehicle:</p>
<ul>
<li>The vehicle driver wants to use the GPS service. Before granting access to the service, the vehicle must answer many questions. What is the identity of the driver and what personal profile should I use (in order to load his previous rides for instance)? Is he the owner of the vehicle, the driver of a rental car, or has he borrowed it for a one-time use? Has the driver subscribed to the GPS services from the manufacturer and what is his level of service (routes calculation only, or also alerts for danger zones)?</li>
</ul>
<p>&nbsp;</p>
<h3>3 &#8211; An object in interaction with the company’s employees and partners</h3>
<p>Last use case, each object can interact with the company’s employees, service providers or partners. <strong>The relationship with the traditional IAM domain</strong> managing the authorizations and roles of the company’s partners and employees is therefore essential.</p>
<p><strong>The use cases</strong> of an object require the creation of <strong>a role model</strong> to answer the question: which rights for which populations of users on which functionalities of the object?</p>
<p>Let’s take again the example of a connected vehicle:</p>
<ul>
<li>If repairs are needed, the mechanic must be able to view the latest vehicle’s operating indicators before the breakdown for diagnostic purposes. Is this garage part of the manufacturer’s network or independent? Is the mechanic allowed to access all GPS information or only the technical indicators of the engine? Can the customer consent or at least be informed of such access to his vehicle’s data?</li>
</ul>
<p>This example also highlights that access rights may be closely linked <strong>to a time frame</strong> (only for the duration of the repair) or <strong>to the nature of the data</strong> (privacy protection of GPS data).</p>
<p>&nbsp;</p>
<h2>IAM of Things also means processes!</h2>
<p>All IAM experts will agree: there is no IAM without a thorough study of the lifecycle of the identities involved. Our conviction is that <strong>IAMoT must study all the processes involving the object over its entire life cycle.</strong> Indeed, throughout the life of an object, the nature of interactions with its environment is likely to evolve according to its condition. For example, a brand-new object should be associated with its main user via a pairing process that ensures a level of trust consistent with the issues at stake…</p>
<p>Let’s use for the last time the example of the connected vehicle:</p>
<ul>
<li><em>A person has just acquired a second-hand connected vehicle from a private owner. In the context of this resale, it is necessary for the new purchaser to ensure that all accesses to services will be properly revoked for the previous owner. The detection of the resale event must therefore trigger a process of un-pairing the former owner.</em></li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-11497 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/01/image3.png" alt="" width="1354" height="544" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/01/image3.png 1354w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/01/image3-437x176.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/01/image3-768x309.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/01/image3-71x29.png 71w" sizes="auto, (max-width: 1354px) 100vw, 1354px" /></p>
<p style="text-align: center;"><em>Figure </em><em>3</em><em> – Ingredients for the IAM of Things recipe</em></p>
<p>&nbsp;</p>
<h2>The IAM of Things, a new discipline based on mastered concepts</h2>
<p>This article highlights the identity management issue for the IoT and underlines the existing links with other fields of the IAM. It is important to keep in mind that even if <strong>the fundamental principles of the IAM also apply</strong> to the identity of connected objects, <strong>responses adapted to each project’s context</strong> must be carefully studied.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2019/01/what-is-iam-of-things/">What is IAM of Things?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
