<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Michel Girier, Auteur</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/author/michel-girier/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/author/michel-girier/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Mon, 21 Apr 2025 13:26:59 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>Michel Girier, Auteur</title>
	<link>https://www.riskinsight-wavestone.com/en/author/michel-girier/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Radar 2025 of Post Quantum Migration Solutions</title>
		<link>https://www.riskinsight-wavestone.com/en/2025/01/2025-radar-of-post-quantum-safety-solutions/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2025/01/2025-radar-of-post-quantum-safety-solutions/#respond</comments>
		
		<dc:creator><![CDATA[Michel Girier]]></dc:creator>
		<pubDate>Tue, 21 Jan 2025 08:32:04 +0000</pubDate>
				<category><![CDATA[Cloud & Next-Gen IT Security]]></category>
		<category><![CDATA[Focus]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=25176</guid>

					<description><![CDATA[<p>Quantum computing threatens today’s asymmetric cryptography and would render current algorithms obsolete, both RSA and ECC. As for symmetric cryptography, (AES, hash functions) doubling the key size ensures maintained security guarantees. To address the threat, the NIST has standardized three...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2025/01/2025-radar-of-post-quantum-safety-solutions/">Radar 2025 of Post Quantum Migration Solutions</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;">Quantum computing threatens today’s asymmetric cryptography and would render current algorithms obsolete, both RSA and ECC. As for symmetric cryptography, (AES, hash functions) doubling the key size ensures maintained security guarantees. To address the threat, the NIST has standardized three post-quantum (resistant to quantum computers) asymmetric algorithms in August 2024.</p>
<p style="text-align: justify;">Fortunately, quantum computers are not performant enough yet to conduct such attacks. Estimates vary as to when this will be a reality, though most expect it between <a href="https://blog.cloudflare.com/pq-2024/">2033 and 2037</a>. Furthermore, regulators have begun outlining end-of-life timelines for existing algorithms, with Australia’s ASD <a href="https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism/cyber-security-guidelines/guidelines-cryptography">planning</a> to designate them as obsolete by 2030 and the NIST <a href="https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf">drafting</a> its own retirement schedule for 2035. We expect such announcements to pick up during the coming months from other nations.</p>
<p style="text-align: justify;">As such, regardless of the exact date of emergence of quantum computers capable of breaking current cryptographic algorithms, a transition will be obligatory from a regulation standpoint.</p>
<p style="text-align: justify;">Migrating a complicated IT infrastructure is no trivial feat: in a 2022 <a href="https://www.whitehouse.gov/briefing-room/statements-releases/2022/05/04/national-security-memorandum-on-promoting-united-states-leadership-in-quantum-computing-while-mitigating-risks-to-vulnerable-cryptographic-systems/">memorandum</a>, the Biden administration expected the migration of all U.S. Federal Agencies to cost more than $7 billion. Such a complex endeavor entails a plethora of aspects from assessing risks, to executing the technical migration, with many intermediary steps. Solutions exist to accompany or accelerate those stages.</p>
<p style="text-align: justify;">Wavestone’s 2025 Post-Quantum Migration Migrations radar offers a first visual panorama of market leading cybersecurity solutions for this migration. This radar has been and will continue to be updated in the coming months. Any company that feels it should be part of the radar is encouraged to reach out.</p>
<p style="text-align: justify;">The goal of the radar is not to inventory solutions that completed their PQC migration, but rather solutions that help and accelerate the PQC migration.</p>
<p style="text-align: justify;"><span data-ccp-props="{}"> </span></p>
<p style="text-align: justify;"><img fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-25862" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/01/radar.png" alt="Radar 2025 Post Quantum Migration Solutions" width="1295" height="785" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2025/01/radar.png 1295w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/01/radar-315x191.png 315w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/01/radar-64x39.png 64w, https://www.riskinsight-wavestone.com/wp-content/uploads/2025/01/radar-768x466.png 768w" sizes="(max-width: 1295px) 100vw, 1295px" /></p>
<h2 style="text-align: justify;">Categories </h2>
<ul style="text-align: justify;">
<li><b><span data-contrast="auto">Inventory</span></b><span data-contrast="auto">:</span> <span data-contrast="auto">Automatically inventory the type and locations of all cryptography in use</span><span data-ccp-props="{}"> </span></li>
<li><b><span data-contrast="auto">Migration Management</span></b><span data-contrast="auto">:</span> <span data-contrast="auto">Provide the big picture view of the post quantum transition, often based on inventory outputs</span><span data-ccp-props="{}"> </span></li>
<li><b><span data-contrast="auto">PQC Compliant HSM / PKI /CLM</span></b><span data-contrast="auto">:</span> <span data-contrast="auto">Provide quantum resistant core trust components necessary for most company services</span><span data-ccp-props="{}"> </span></li>
<li><b><span data-contrast="auto">Libraries / Embedded Services</span></b><span data-contrast="auto">:</span> <span data-contrast="auto">Encrypt and sign data with polyvalent libraries or directly integrated cloud solutions</span><span data-ccp-props="{}"> </span></li>
<li><b><span data-contrast="auto">Edge Protection</span></b><span data-contrast="auto">:</span> <span data-contrast="auto">Protect against quantum computing attack by providing an extra layer of security, be it at network or application level</span><span data-ccp-props="{}"> </span></li>
<li><b><span data-contrast="auto">Network Analysis:</span></b> <span data-contrast="auto">Detect network flows which use obsolete cryptography with probes</span><span data-ccp-props="{}"> </span></li>
</ul>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">Key Market Trends </h2>
<h3 style="text-align: justify;"> </h3>
<h3 style="text-align: justify;">Size disparities</h3>
<p style="text-align: justify;">The market landscape for post-quantum security solutions exhibits significant disparities in the size and maturity of players. On one end of the spectrum, tech giants and established cybersecurity firms leverage extensive resources to develop and promote robust solutions. On the other end, niche start-ups and pure players are driving rapid advancements in specialized areas. We expect this diversity to foster:</p>
<ol style="text-align: justify;">
<li><strong>Innovation</strong>: Diversity in the market landscape, with contributions from both tech giants and pure players which enhances the pace and quality of innovation.</li>
<li><strong>Fragmentation</strong>: smaller players may struggle to achieve the scale required to implement their solutions broadly</li>
<li><strong>Partnerships</strong>: we are already witnessing how Thales and IBM are leveraging innovation in specific areas of pure players with their own resources and expertise.</li>
</ol>
<p style="text-align: justify;">As the market matures, it will be exciting to follow how its landscape evolves.</p>
<p style="text-align: justify;"> </p>
<h3 style="text-align: justify;">Several open-source libraries… with Big Tech support</h3>
<p style="text-align: justify;">Already, several open-source libraries propose post-quantum cryptograph. The most high-profile libraries, such as OpenSSL, are not the most advanced on this, with their own implementations currently ongoing, while Open Quantum Safe’s liboq is already ready. Nevertheless, it is a promising sight for the cybersecurity ecosystem that a topic as crucial as post-quantum security has solutions deeply rooted in open-source principles.</p>
<p style="text-align: justify;">Yet, Big Tech companies play a pivotal role in supporting open-source libraries for post-quantum cryptography, recognizing their potential to accelerate adoption and innovation. Initiatives like Open Quantum Safe’s liboq has supporters that include Microsoft, Amazon and IBM; Bouncy Castle’s PQC was developed with Keyfactor’s sizeable participation, and Tink, Google’s open-source library offer PQC as well. However, most of the implementation has not been fully formally verified, though the process is underway.</p>
<p style="text-align: justify;"><span style="font-size: revert; color: initial;"> </span></p>
<h3 style="text-align: justify;">A lack of certification for HSMs…</h3>
<p style="text-align: justify;">Hardware Security Modules (HSMs) play a crucial role in the digital trust chain, but the market for these hardware solutions is not yet ready. Initially, providers resorted to software implementations for experimental purposes while waiting for the new standard to be published by NIST. However, hardware implementations have advanced since then, even though their certification is not expected until Q3 or Q4 2025.</p>
<p style="text-align: justify;">Furthermore, although HSMs are designed to resist tampering and reduce the risks of key exposure, they will have to face challenges related to side-channel attacks due to the still limited maturity of current implementations of these new algorithms.</p>
<p style="text-align: justify;"> </p>
<h3 style="text-align: justify;">And a lack of hardware for IoT, embedded devices, and smart cards</h3>
<p style="text-align: justify;">The lack of hardware is particularly problematic for connected objects (IoT), embedded devices, and smart cards, which operate under severe constraints – limited power, reduced computing capacity, and restricted storage space – thus requiring efficient algorithms and specialized dedicated hardware for cryptographic operations. Unfortunately, the current absence of dedicated processors remains a major obstacle.</p>
<p style="text-align: justify;">Moreover, the decentralized nature of embedded devices will represent a considerable challenge to overcome, as upgrading legacy equipment will be complex and costly.</p>
<p style="text-align: justify;"> </p>
<h3 style="text-align: justify;">A strong market dynamism</h3>
<p style="text-align: justify;"><span style="font-size: revert; color: initial;">Post-quantum security is very much an emerging topic. Yet, today’s market for solutions is extremely dynamic, Companies, governments, and institutions are mobilizing to address emerging risks, fueling a surge in innovative and specialized technological offerings. This momentum will be further accelerated by expected regulatory pressures, such as those from NIST, ASD, and ENISA, compelling organizations to adopt robust and compliant solutions.</span></p>
<p style="text-align: justify;"> </p>
<h3 style="text-align: justify;">An international and sovereign Market: digital sovereignty at stake</h3>
<p style="text-align: justify;">The quantum computing market is both global and deeply intertwined with questions of national sovereignty. Quantum computers are considered a strategic issue by the world’s leading nations, which invest hundreds of billions to ensure their sovereignty in that emergent field.</p>
<p style="text-align: justify;">On the other hand, the market for post-quantum security is framed in a much more international prism. Companies in our radar span many nations, with the U.S. being nevertheless the uncontested leader. Moreover, international partnerships have also taken place such as Thales, which partners with IBM, CryptoNext and many more to combine their respective expertise and provide clients with advanced solutions.</p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">A promising but incomplete market coverage</h2>
<p style="text-align: justify;">As we have covered, the market is extremely dynamic. The question remains whether the ecosystem’s needs for a post quantum transition are currently met. Currently, there is a lack of true hardware post-quantum solutions, as most of what exists is only a post-quantum layer. Nevertheless, our understanding of the market is very much that it is under development and should be more and more available this year already. Based on how we advise clients in planning and implementing their migration, the market solutions address or will address shortly most of our client’s needs.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">Our evolving radar constitutes the first edition in this field. In that sense, we strongly encourage any absent company to contact us to remedy the situation.<span data-ccp-props="{}"> </span></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2025/01/2025-radar-of-post-quantum-safety-solutions/">Radar 2025 of Post Quantum Migration Solutions</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2025/01/2025-radar-of-post-quantum-safety-solutions/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>2024 CIdO Radar</title>
		<link>https://www.riskinsight-wavestone.com/en/2024/04/2024-cido-radar/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2024/04/2024-cido-radar/#respond</comments>
		
		<dc:creator><![CDATA[Michel Girier]]></dc:creator>
		<pubDate>Fri, 05 Apr 2024 14:11:11 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[2024 CIdO radar]]></category>
		<category><![CDATA[Chief Identity Officer]]></category>
		<category><![CDATA[CIdO]]></category>
		<category><![CDATA[DIgital Identity]]></category>
		<category><![CDATA[IAM]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=22904</guid>

					<description><![CDATA[<p>Chief Identity Officer (CIdO). That&#8217;s the new term introduced by Gartner to define the role of an identity manager within an organization. While this term is still relatively new, upcoming challenges regarding digital identity could well elevate the CIdO to...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2024/04/2024-cido-radar/">2024 CIdO Radar</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Chief Identity Officer (CIdO). That&#8217;s the new term introduced by Gartner to define the role of an identity manager within an organization. While this term is still relatively new, upcoming challenges regarding digital identity could well elevate the CIdO to the same level as its counterparts, the CISO and CIO (respectively Chief Information Security Officer and Chief Information Officer). In fact, Gartner estimates that by 2027, 45% of IAM (Identity and Access Management) leaders in organizations will be promoted to executive-level positions<a href="https://www.gartner.com/en/documents/4989731" name="_ftnref1">[1]</a>. However, there are many challenges that can arise, such as : the integration of IAM within a Zero Trust strategy, exponential growth of machine identities, hybrid work models, etc. and an IAM expertise who will be required to address them.</p>
<p>Drawing from its experience in the field of digital identity, Wavestone is publishing its first edition of the CIdO Radar in 2024. This radar follows the same methodology as the CISO Radar published by the firm for the past 10 years and offers an in-depth look at the underlying trends driving the digital identity ecosystem.</p>
<p>In this article, we invite you to explore some impactful and structuring topics for the IAM landscape, with two currently trending  subjects (passwordless and CLM) and moving towards the future topics they foreshadow in the emerging section of the radar (respectively predictive anti-fraud and post-quantum cryptography).</p>
<p><img decoding="async" class="size-full wp-image-22906 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/04/Picture1-EN.png" alt="2024 Chief Identity Officer radar" width="922" height="771" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/04/Picture1-EN.png 922w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/04/Picture1-EN-228x191.png 228w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/04/Picture1-EN-47x39.png 47w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/04/Picture1-EN-768x642.png 768w" sizes="(max-width: 922px) 100vw, 922px" /></p>
<p> </p>
<h2>Passwordless, a major evolution not so simple to achieve</h2>
<p>For decades, the password has been the central authentication factor for users (and often still is). Passwords have then been complemented into multi-factor authentication strategies to compensate for the inherent weaknesses of this authentication method (low complexity, reuse, phishing risks, etc.). New tools have thus been added to the user authentication process: OTP via SMS or email, push notifications, soft and hard tokens, etc. Despite the increased security level provided by the addition of these new authentication factors, the password remains both a weakness if discovered (it remains reusable on an account without MFA where it is enrolled) and a burden for the user&#8217;s experience, as they must remember it and securely store it.</p>
<p>All these reasons have led vendors to imagine secure authentication methods not relying on the use of a password. Eliminating the password allows companies to improve the user experience for their employees, enhance authentication security by reducing the attack surface, and benefit from a positive image in the market. The user finds themselves in an environment where they no longer need to remember a multitude of complex passwords and where they are no longer at risk of having their account stolen through phishing attacks. The use of FIDO2 (Fast Identity Online 2) technology is based on asymmetric cryptography which is currently the most widespread alternative to passwords. This technology is driven by the FIDO Alliance (Google, Microsoft, Amazon, Apple, etc.) and, relies on the use of physical security keys locally storing the private key associated with each service. Ultimately, this  allows a user to log into all their accounts without a password, their login, or email address (simply by using the physical key they possess and a second factor such as biometrics).</p>
<p>However, implementing passwordless authentication comes with significant organizational questions for a structure. How to manage account recovery if this account does not rely on a password? If an employee loses their security key, how can access to their account be restored without being able to use the associated private key? This major issue of &#8220;credentials recovery&#8221; is inseparable from any passwordless policy and assumes that an organization has anticipated each step of it,  such as: purchasing and distributing authentication media, managing their loss/theft/destruction, obsolete media rotation processes, account backup solutions, double enrolment for critical accounts and management of employee departures, etc.</p>
<p>Passwordless authentication is a trending topic and is being deployed in many organizations. For many, the next step involves establishing fraud detection capabilities before they occur (also called &#8220;predictive anti-fraud&#8221;).</p>
<p> </p>
<h2>Predictive anti-fraud, how to prevent fraud before it occurs?</h2>
<p>Predictive Anti-Fraud corresponds to proactive monitoring of systems aimed at identifying and stopping fraud before it occurs, rather than relying solely on post analysis of malicious activities that have already happened. These surveillance capabilities are particularly relevant for securing online business activities involving money transfers (such as pooling funds, loyalty accounts, online payments, etc.) in sectors like retail or luxury for instance (as they are often less mature on this subject than banks). We are currently witnessing an increase in phishing attacks aimed at stealing customer account data to misuse their contents (loyalty card fraud, for example, is a real concern for players in the retail sector).</p>
<p>Access management solutions are increasingly capable of detecting fraud patterns and halting illicit activities before completion. All these capabilities rely on machine learning (involving a training phase for the tools) and involve three key stages:</p>
<ul>
<li>Detection: Systems can detect behaviours deviating from typical user/customer journeys and as well as sequences of suspicious actions. Detection relies on the customer context (browser used, network, cookies, etc.), the dynamic context (IP address, device used, user behaviour, typing speed, strength of authentication performed, etc.), and the business context (type of requested transaction, amounts, modifications of sensitive information, etc.).</li>
<li>Analysis: Automatic analysis is conducted with the assignment of a confidence score to the current user profile.</li>
<li>Response: Response rules are defined to best address alert triggers, with automatic responses for obvious or critical situations (e.g., additional authentication factor, session termination), or manual responses for cases requiring human decision-making.</li>
</ul>
<p><img decoding="async" class="size-full wp-image-23019 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/04/Picture1-EN-FINAL.png" alt="" width="643" height="455" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/04/Picture1-EN-FINAL.png 643w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/04/Picture1-EN-FINAL-270x191.png 270w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/04/Picture1-EN-FINAL-55x39.png 55w" sizes="(max-width: 643px) 100vw, 643px" /></p>
<p>The main challenge of predictive anti-fraud is the correct  calibration of machine learning tools and their adaptation to the specific business context. Placing too much emphasis on security could cause a disproportionate amount of  negative impact on the service: a high number of false positives affecting user experience and an increase in service complexity and slowdowns (captcha, step-up authentication, significant network consumption, longer processing times). The definition of relevant security and detection rules must be accompanied by a model based on machine learning, as specific as possible to the use case. Given the increasing complexity of attacks, the key to an effective predictive anti-fraud strategy lies in the solutions&#8217; ability to detect and correlate weak signals. For example, some vendors are now capable of detecting fraud attempts during false customer service calls by correlating the users&#8217; actions with whether they are on a phone call.</p>
<p> </p>
<h2>Certificate Lifecycle Management (CLM), a new market for an old issue</h2>
<p>Many companies are currently facing an explosion in the number of electronic certificates within their IT systems. These certificates (and associated cryptographic keys) serve various purposes such as machine-to-machine authentication, user authentication, data signing and encryption, websites security, application micro-services, etc. This increase in the number of electronic certificates significantly increases the workload for the teams in charge of their management. The lifecycle of an electronic certificate includes several stages such as:</p>
<ol>
<li>Requesting the certificate from a PKI (Public Key Infrastructure)</li>
<li>Receiving the certificate and associated keys</li>
<li>Deploying the certificate within its scope (either as a replacement for an expiring certificate or on a new scope)</li>
<li>Decommissioning and revoking the old certificate (if applicable)</li>
<li>Continuously monitoring the certificate and its future expiration date</li>
<li>Reproducing this process for each certificate before its expiration.</li>
</ol>
<p>Manual management of tens (or even hundreds) of thousands of electronic certificates poses numerous challenges. This type of management is highly resource-intensive, relies on repetitive tasks, and is prone to human errors. It is not uncommon for certificates to slip through the cracks of teams and go unrenewed, or simply remain undeclared within the IT system (shadow IT). For all these reasons, an organization with a large fleet of electronic certificates should consider adopting a CLM solution.</p>
<p>CLM solutions offer many features to facilitate and ensure the reliability of certificate lifecycle management. Some of these features include:</p>
<ul>
<li>Certificate discovery tools, allowing a company to have a comprehensive view of its certificate fleet (even for undeclared certificates).</li>
<li>The use of protocols automating all certificate-related actions (mentioned above).</li>
<li>Numerous connectors enabling clients to seamlessly integrate these solutions within their IT systems.</li>
<li>Governance and rights management modules for certificates.</li>
<li>Alerting capabilities serving as a safety net for teams.</li>
</ul>
<p>The &#8220;Zero Trust&#8221; philosophy, often requiring securing communications between services through mutual authentication using electronic certificates (with the increasingly frequent use of microservices architectures, the explosion of non-human accounts, etc.), tends to increase the number of electronic certificates within organizations. Utilizing dedicated certificate lifecycle management tools rather than manual tracking can reduce certificate-related incidents by 90% and decrease incident processing time by 50%, according to Gartner<a href="https://www.gartner.com/en/documents/3969998" name="_ftnref2">[2]</a>.</p>
<p>For more details on CLM solutions, you can read Wavestone&#8217;s article dedicated to this subject <a href="https://www.riskinsight-wavestone.com/en/2023/03/lifecycle-management-of-digital-certificates-what-are-the-challenges-and-how-to-address-them/"><u>here</u></a>.</p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-22910 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/04/Picture3-EN.png" alt="CLM Certificate Lifecycle Management" width="795" height="614" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/04/Picture3-EN.png 795w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/04/Picture3-EN-247x191.png 247w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/04/Picture3-EN-50x39.png 50w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/04/Picture3-EN-768x593.png 768w" sizes="auto, (max-width: 795px) 100vw, 795px" /></p>
<p>The implementation of a CLM solution signifies a step forward in securing infrastructures, but more importantly, it can be leveraged towards crypto agility (the ability to quickly replace or update encryption algorithms or protocols to address evolving threats). Crypto agility is a theme that we should expect to encounter more and more frequently in the medium term, largely due to the development of quantum computers.</p>
<p> </p>
<h2>And what&#8217;s next? Technological challenges ahead, such as post-quantum cryptography</h2>
<p>While organizations strive to adopt robust IAM strategies, considering current technological threats is no longer sufficient. The impending topic of quantum computing (even if it seems still a few years away from now) is set to disrupt all our encryption practices, necessitating early anticipation of measures to be implemented for the 2030 decade. The use of quantum computers and their famous qubits (which can simultaneously take on values of 0 or 1) already allows for much more efficient cryptographic calculations than traditional computers.</p>
<p>It is important to note that symmetric cryptography is not as much at risk from quantum threats, and increasing the size of encryption keys will allow this encryption mode to resist quite effectively. However, classic RSA and Elliptic Curve asymmetric cryptography is truly threatened: key exchange, authentication, and digital signature which rely on that classic asymmetric cryptography are already at risk for specific use cases. The Shor&#8217;s algorithm could enable a quantum computer to break RSA 2048-based encryption in a matter of hours.</p>
<p>Post-quantum cryptography is currently focusing on solutions to adapt encryption to the future capabilities of quantum computers. ‘Store Now, Decrypt Later’ which means that we can decrypt in 10 years what is captured now, even encrypted, or the capability to modify (in 10 years) the author or the content of a digital signature are risks that should already be considered today, especially with the time needed to handle the migration to post-quantum algorithm. In 2022,  NIST published a list of 4 such encryption algorithms, resistant to quantum computers: CRYSTALS-Kyber for general encryption, CRYSTALS-Dilithium, FALCON, and SPHINCS+ for electronic signature. These algorithm should be confirmed during 2024.</p>
<p>The main current recommendation to ensure the transition to post-quantum encryption is to perform hybrid encryption, i.e., to use both classical and post-quantum encryption algorithms to secure communications. While this issue is not yet at the heart of current IAM challenges, it is important to monitor its evolution, especially since some major vendors are already entering the market and introducing a new term: QCaaS (Quantum Computing as a Service).</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2024/04/2024-cido-radar/">2024 CIdO Radar</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2024/04/2024-cido-radar/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>&#8220;Security Twins&#8221;: A new security &#038; trust guarantee for connected devices (2/2)</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/08/security-twins-a-new-security-trust-guarantee-for-connected-devices-2-2-2/</link>
		
		<dc:creator><![CDATA[Michel Girier]]></dc:creator>
		<pubDate>Fri, 28 Aug 2020 13:07:38 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[IoT & Consumer goods]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[Jitsuin]]></category>
		<category><![CDATA[POC]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Smart House]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=14147</guid>

					<description><![CDATA[<p>In a previous article, we discovered how &#8220;Security Twins&#8221; could improve the security and trust of connected devices. In this new article we will now look at how the “Security Twins” can improve the security of physical accesses to a building...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/08/security-twins-a-new-security-trust-guarantee-for-connected-devices-2-2-2/">&#8220;Security Twins&#8221;: A new security &#038; trust guarantee for connected devices (2/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;">In a <a href="https://www.riskinsight-wavestone.com/en/2020/07/security-twins-a-new-security-trust-guarantee-for-connected-devices-2-2/">previous article</a>, we discovered how &#8220;Security Twins&#8221; could improve the security and trust of connected devices. In this new article we will now look at how the “Security Twins” can improve the security of physical accesses to a building through a PoC made by Wavestone in collaboration with the start-up Jitsuin using their tool: “Jitsuin Archivist”.</p>
<p>&nbsp;</p>
<h2>What does “Jitsuin Archivist” look like?</h2>
<p style="text-align: justify;">The start-up Jitsuin has developed a tool called &#8220;Jitsuin Archivist&#8221; based on Distributed Ledger Technology (DLT). The purpose of this tool is to know &#8220;Who did what to a Thing and When”.</p>
<p style="text-align: justify;">As of today, 5 types of users can interact with the tool: Archivist Administrator, System Administrator, Maintenance Operator, Auditor, Custom (currently in beta version).</p>
<p>&nbsp;</p>
<figure id="post-14148 media-14148" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-14148 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/1.png" alt="" width="1277" height="275" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/1.png 1277w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/1-437x94.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/1-71x15.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/1-768x165.png 768w" sizes="auto, (max-width: 1277px) 100vw, 1277px" /></figure>
<p style="text-align: center;">Figure 1 – The 5 user roles of “Jitsuin Archivist”</p>
<p>&nbsp;</p>
<p style="text-align: justify;">On this tool the user has access to the &#8220;Security Twins&#8221; of the connected devices. Indeed, after logging in, the user accesses a dashboard through which he has a global view of all the connected devices linked to the tool. He can see relevant statistics related to his IoT deployment, such as the number of critical incidents, the activity of connected objects, etc.</p>
<p style="text-align: justify;">The user can also access the &#8220;Manage Assets&#8221; page where he will find a map with the location of all the connected objects linked to the tool and a list of them (where he can also see in more detail the events linked to a particular connected device).</p>
<p>&nbsp;</p>
<figure id="post-14150 media-14150" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-14150 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/2.png" alt="" width="1339" height="653" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/2.png 1339w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/2-392x191.png 392w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/2-71x35.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/2-768x375.png 768w" sizes="auto, (max-width: 1339px) 100vw, 1339px" /></figure>
<p style="text-align: center;">Figure 2 &#8211; The different views of the tool &#8220;Jitsuin Archivist&#8221;: 1. dashboard with a global view, 2. all the objects and their location, 3. detailed view of an object, 4. all the actions of the object useful during security audits</p>
<p>&nbsp;</p>
<h2>The PoC: A House with a digital lock</h2>
<p style="text-align: justify;">Wavestone used Jitsuin&#8217;s tool to first address the issue of identity and access management in buildings in at the dawn of digital transformation and the to illustrate the usefulness of &#8220;Security Twins&#8221;.</p>
<p style="text-align: justify;">To do this Wavestone used the lego house &#8220;SmartHouse&#8221; :</p>
<p>&nbsp;</p>
<figure id="post-14152 media-14152" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-14152 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/3.jpg" alt="" width="1085" height="955" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/3.jpg 1085w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/3-217x191.jpg 217w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/3-44x39.jpg 44w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/3-768x676.jpg 768w" sizes="auto, (max-width: 1085px) 100vw, 1085px" /></figure>
<p style="text-align: center;">Figure 3 – The “SmartHouse”</p>
<p>&nbsp;</p>
<p style="text-align: justify;">Equipped with an RFID card reader, a Raspberry Pi microcontroller and a servomotor, the entrance door of the &#8220;SmartHouse&#8221; only opens to users who have an authorized access card. All actions related to opening, closing, granting of entry rights, etc. are recorded on &#8220;Jitsuin Archivist&#8221; (see figure 4).</p>
<p>&nbsp;</p>
<figure id="post-14154 media-14154" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-14154 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/4.png" alt="" width="1037" height="474" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/4.png 1037w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/4-418x191.png 418w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/4-71x32.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/4-768x351.png 768w" sizes="auto, (max-width: 1037px) 100vw, 1037px" /></figure>
<p style="text-align: center;">Figure 4 – The functional diagram of the “SmartHouse”</p>
<p>&nbsp;</p>
<p style="text-align: justify;">In order to facilitate the interaction with the digital lock of the “SmartHouse”, a platform allowing the simulation of different operations made by different peopled involved in the life cycle of connected devices has been created using the Django web framework and Bootstrap. This platform allows, among other things, to:</p>
<ul style="text-align: justify;">
<li>Send security patches to the connected lock (using Azure IoTHub)</li>
<li>Assign access rights to the “SmartHouse”</li>
<li>View the history of access rights requests made and those awaiting validation, etc.</li>
</ul>
<p style="text-align: justify;">This is what the platform looks like:</p>
<p>&nbsp;</p>
<figure id="post-14156 media-14156" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-14156 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/5.png" alt="" width="1426" height="729" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/5.png 1426w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/5-374x191.png 374w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/5-71x36.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/5-768x393.png 768w" sizes="auto, (max-width: 1426px) 100vw, 1426px" /></figure>
<p style="text-align: center;">Figure 5 &#8211; SmartHouse&#8217;s management platform</p>
<p>&nbsp;</p>
<p style="text-align: justify;">The use of “Jitsuin Archivist” in this PoC is very interesting when regards to security audits of connected devices. Indeed, as “Jitsuin Archivist” is based on Distributed Ledger Technology (DLT), this system can be considered as &#8220;secure by design&#8221; since an auditor has a technical guarantee on the non-compromise of data (provided that the sending of this data is secure).</p>
<p style="text-align: justify;">Here is the &#8220;Auditor View&#8221; on “Jitsuin Archivist” where it is possible to see all the information regarding the connected devices linked to the platform and to know who has done what to the connected device:</p>
<p>&nbsp;</p>
<figure id="post-14158 media-14158" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-14158 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/6.png" alt="" width="1804" height="884" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/6.png 1804w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/6-390x191.png 390w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/6-71x35.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/6-768x376.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/6-1536x753.png 1536w" sizes="auto, (max-width: 1804px) 100vw, 1804px" /></figure>
<p style="text-align: center;">Figure 6 &#8211; The &#8220;Auditor View&#8221; of “Jitsuin Archivist”</p>
<p>&nbsp;</p>
<h2>The PoC scenario: WaveHouse rents “SmartHouses” in France &#8230;</h2>
<figure id="post-14160 media-14160" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-14160 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/7.png" alt="" width="1246" height="566" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/7.png 1246w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/7-420x191.png 420w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/7-71x32.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/7-768x349.png 768w" sizes="auto, (max-width: 1246px) 100vw, 1246px" /></figure>
<p>Here is the general architecture of the PoC:</p>
<p>&nbsp;</p>
<figure id="post-14162 media-14162" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-14162 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/8.png" alt="" width="1326" height="831" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/8.png 1326w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/8-305x191.png 305w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/8-62x39.png 62w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/8-768x481.png 768w" sizes="auto, (max-width: 1326px) 100vw, 1326px" /></figure>
<p style="text-align: center;">Figure 7 &#8211; The general architecture of the PoC</p>
<p>&nbsp;</p>
<p style="text-align: justify;">As one can see, the digital lock (represented by the RFID card reader, the Raspberry Pi microcontroller and the servomotor) interacts with Azure IoTHub as well to facilitate the management of its firmware updates.</p>
<p>&nbsp;</p>
<h2 style="text-align: justify;">The main use cases studied by Wavestone and Jitsuin</h2>
<p>The main use cases studied by Wavestone and Jitsuin are explained in the video below:</p>
<p><div style="width: 640px;" class="wp-video"><video class="wp-video-shortcode" id="video-14147-1" width="640" height="360" preload="metadata" controls="controls"><source type="video/mp4" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/video-article-720p-mp4.mp4?_=1" /><a href="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/video-article-720p-mp4.mp4">https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/video-article-720p-mp4.mp4</a></video></div></p>
<p>&nbsp;</p>
<h2>Conclusion</h2>
<p style="text-align: justify;">Wavestone and Jitsuin were able to demonstrate &#8211; with the different use cases illustrated above in the video &#8211; how to improve the security of connected devices:</p>
<ul style="text-align: justify;">
<li>First of all, all of the people involved in the life cycle of the digital lock of the “SmartHouse” had access to its &#8220;Security Twin&#8221;. Indeed, each of them had access to a decentralized and unchangeable register provided by “Jitsuin Archivist” with all the information regarding the security of the digital lock.</li>
<li>Then, as mentioned above, this architecture is &#8220;secure by design&#8221; because as “Jitsuin Archivist” is based on Distributed Ledger Technology (DLT), one has a technical guarantee on the non-compromising of data.</li>
<li>The &#8220;Security Twin&#8221; of the digital lock ensured physical security since it had the rights management information, allowing all the people involved to know who had access to the &#8220;SmartHouse&#8221;.</li>
<li>Finally, since the “Security Twin” also had firmware information, the different people involved could easily know which connected devices had vulnerabilities and quickly plan the distribution of security patches.</li>
</ul>
<p style="text-align: justify;">The &#8220;Security Twins&#8221; would therefore ultimately improve the security of the connected devices, since it would be easy to know which objects are secure and which are not.</p>
<p>&nbsp;</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/08/security-twins-a-new-security-trust-guarantee-for-connected-devices-2-2-2/">&#8220;Security Twins&#8221;: A new security &#038; trust guarantee for connected devices (2/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>&#8220;Security Twins&#8221;: A new security &#038; trust guarantee for connected devices (1/2)</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/07/security-twins-a-new-security-trust-guarantee-for-connected-devices-2-2/</link>
		
		<dc:creator><![CDATA[Michel Girier]]></dc:creator>
		<pubDate>Fri, 24 Jul 2020 12:55:38 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[IoT & Consumer goods]]></category>
		<category><![CDATA[connected device]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[NIST]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=13959</guid>

					<description><![CDATA[<p>In 2010, the early hype-cycle of IoT (Ericsson and Cisco) predicted 50 billion devices by 2020. In reality, that figure was highly overestimated. Today, Gartner states that approximately 5.8 billion IoT terminals will be in use in 20201. Even if...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/07/security-twins-a-new-security-trust-guarantee-for-connected-devices-2-2/">&#8220;Security Twins&#8221;: A new security &#038; trust guarantee for connected devices (1/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>In 2010, the early hype-cycle of IoT (Ericsson and Cisco) predicted 50 billion devices by 2020. In reality, that figure was highly overestimated. Today, Gartner states that approximately 5.8 billion IoT terminals will be in use in 2020<sup>1</sup>. Even if the market is not as developed as it was first predicted, it is still growing: those 5.8 billion of IoT devices represent <strong>an increase of 21%</strong> over 2019.</p>
<p>Despite their usefulness, introducing connected devices unfortunately brings <strong>new risks</strong> for companies. Indeed, according to the Palo Alto Networks report<sup>2</sup> published in March 2020, <strong>57% of the connected devices analyzed were vulnerable to medium or high severity attacks</strong>. This is not surprising. Securing connected devices is proving to be an arduous task that explains why Beecham Research<sup>3</sup> finds 62% of Industrial IoT transformations fail to scale because of a lack of trust.</p>
<p>Therefore, with this article we will try to ask ourselves about the security and trust issues of connected devices and how companies can deal with them.</p>
<p>&nbsp;</p>
<h2>What are the security and trust issues of connected devices?</h2>
<p style="text-align: justify;">In order to mitigate the security risks on connected devices, NIST recommends in its report<sup>4</sup> published in 2019 to focus on 6 main areas:</p>
<ul>
<li style="text-align: justify;"><strong>Inventory</strong>: Maintain an accurate inventory of all connected devices and their most relevant characteristics throughout their lifecycle (<a href="https://www.riskinsight-wavestone.com/en/2019/09/life-cycle-iot-security/">see the article</a> detailing the lifecycle of connected devices).</li>
</ul>
<p>&nbsp;</p>
<figure id="post-13960 media-13960" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-13960 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-1-1.png" alt="" width="1479" height="755" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-1-1.png 1479w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-1-1-374x191.png 374w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-1-1-71x36.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-1-1-768x392.png 768w" sizes="auto, (max-width: 1479px) 100vw, 1479px" /></figure>
<p style="text-align: center;">Figure 1 &#8211; Connected device lifecycle</p>
<ul>
<li style="text-align: justify;"><strong>Vulnerabilities</strong>: Identify and eliminate known vulnerabilities in the software and firmware of connected devices to reduce the likelihood and ease of exploitation and compromise.</li>
<li style="text-align: justify;"><strong>Access</strong>: Prevent unauthorized and inappropriate physical and logical access, use and administration of connected devices by people, processes and other computing devices.</li>
<li style="text-align: justify;"><strong>Detect security incidents of connected devices</strong>: Monitor and analyze connected device activity for signs of incidents involving the security of the device.</li>
<li style="text-align: justify;"><strong>Detect data security incidents</strong>: Monitor and analyze the activity of the connected device for signs of data security incidents.</li>
<li style="text-align: justify;"><strong>Protect data</strong>: Prevent access and alteration of data that could expose sensitive information or allow manipulation or disruption of the operation of connected devices.</li>
</ul>
<p style="text-align: justify;">However, current IoT platforms only partially meet these security requirements (<a href="https://www.wavestone.com/en/insight/iot-platforms-cornerstone-successful-iot-strategy/">see the article</a> detailing the usefulness of IoT platforms).</p>
<p>&nbsp;</p>
<p id="post-13962 media-13962" class="align-none" style="text-align: center;"><img loading="lazy" decoding="async" class="aligncenter wp-image-13962 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-2-1.png" alt="" width="1073" height="329" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-2-1.png 1073w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-2-1-437x134.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-2-1-71x22.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-2-1-768x235.png 768w" sizes="auto, (max-width: 1073px) 100vw, 1073px" />Figure 2 &#8211; The usefulness of IoT platforms</p>
<p>&nbsp;</p>
<p style="text-align: justify;">Indeed, traditional IoT architectures rely on a <strong>centralized cloud platform</strong>, operated by a third-party company and where most often the rules for data collection and storage are opaque. <strong>This is not the best solution to ensure the security of connected devices since</strong>:</p>
<ul>
<li>The use of a centralized cloud platform introduces the risk of &#8220;<strong>single point of failure</strong>&#8221; on the <strong>IoT architecture</strong> (although today this risk is mitigated with the implementation of a redundant architecture and backups).</li>
<li>It is entirely possible for an attacker to <strong>change the data stored in the cloud database</strong>. The decision making of the different stakeholders is therefore impacted.</li>
<li><strong>Collaboration</strong> between the different stakeholders of the IoT deployment (manufacturers, maintenance operators, &#8230;) becomes more <strong>difficult</strong> because access to the platform can be restricted to them.</li>
</ul>
<p style="text-align: justify;">The use of a <strong>decentralized management system</strong> for connected devices where all stakeholders would have the possibility to <strong>reliably consult or contribute information</strong> regarding connected devices (firmware version, maintenance operations, etc.) becomes essential to guarantee the security of those devices and the integrity of data they produce.</p>
<p>&nbsp;</p>
<h2 style="text-align: justify;">How do &#8220;Security Twins&#8221; help meet the security challenges of connected devices?</h2>
<p>In order to support IoT platforms and improve the security of IoT deployments, the notion of  <strong>&#8220;Security Twin&#8221; should be introduced in IoT deployments.</strong></p>
<p>The principle of a &#8220;Security Twin&#8221; is simple. It is a <strong>virtual representation</strong> of the connected device that <strong>contains all its security information</strong>, such as firmware version, vulnerabilities, etc. upon which all stakeholders involved in its upkeep can reach consensus (see figure 3).</p>
<p>&nbsp;</p>
<figure id="post-13966 media-13966" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-13966 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-3-1.png" alt="" width="1012" height="459" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-3-1.png 1012w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-3-1-421x191.png 421w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-3-1-71x32.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-3-1-768x348.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-3-1-730x330.png 730w" sizes="auto, (max-width: 1012px) 100vw, 1012px" /></figure>
<p style="text-align: center;">Figure 3 &#8211; The &#8220;Security Twin&#8221; mechanism (from: Jitsuin)</p>
<p>&nbsp;</p>
<p>A &#8220;Security Twin&#8221; gains effectiveness when more <strong>stakeholders</strong> of the deployment <strong>can interact with it</strong> and reach consensus that the<strong> information provided/recorded is correct</strong>.</p>
<p>Therefore, solutions based on <strong>Distributed Ledger Technology (DLT)</strong> represent a logical first step in the creation of Security Twins, as they would allow the security information of the connected device to be gathered in <strong>a decentralized and immutable registry</strong> that would be accessible by all authorized stakeholders in the IoT deployment. The best well known distributed registry solution is the Blockchain (<a href="https://www.wavestone.com/en/insight/blockchain-practice/">see the article</a> on Blockchain’s uses and limitations).</p>
<p>Taking up the points raised earlier in the NIST report, one could say that the use of a &#8220;Security Twin&#8221; would therefore improve:</p>
<ul>
<li><strong>Device and access management</strong>: all stakeholders of the IoT deployment would have access to a decentralized and immutable register of all the connected devices with the corresponding security and trust information.</li>
<li><strong>Vulnerability management and the detection of device security incidents</strong>: the different stakeholders could share device security information and take the necessary actions (e.g. the manufacturer of a connected device could notify the other stakeholders of the availability of a new firmware update thanks to the &#8220;Security Twin&#8221;).</li>
<li><strong>Data protection and the detection of data related security incidents</strong>: The very foundation of a &#8220;Security Twin&#8221; is based on the use of a decentralized and immutable register to record data related to the security of connected devices. This makes it more difficult for attackers to change the data, which reduces the risk of a security incident.</li>
</ul>
<p>The use of &#8220;Security Twins&#8221; therefore offers the possibility of strengthening the security, integrity, trust and resilience of connected devices.</p>
<p>The start-up Jitsuin has developed &#8220;Jitsuin Archivist&#8221; a tool based on Distributed Ledger Technology (DLT) to overcome the lack of collaborative tools to secure connected devices. The purpose of this tool is not to replace IoT platforms but to allow the creation of &#8220;Security Twins&#8221;.</p>
<p>Together, Wavestone and <a href="https://jitsuin.com/">Jitsuin</a> sought to demonstrate the benefits of using a decentralized architecture with “Security Twins”. The two companies have therefore collaborated on the construction of a PoC (Proof of Concept) to tackle identity and access management of buildings using connected devices, which will be introduced in a future article.</p>
<p>&nbsp;</p>
<p>1 Gartner, 29th August 2019 : https://www.gartner.com/en/newsroom/press-releases/2019-08-29-gartner-says-5-8-billion-enterprise-and-automotive-io<br />
2 Palo Alto Networks, 10th March 2020, “Unit 42 IoT threat report”: https://unit42.paloaltonetworks.com/iot-threat-report-2020/<br />
3 Why IoT projects fail https://www.whyiotprojectsfail.com/?cs=br2<br />
4 NIST – “Considerations for Managing Internet of Things (IoT) Cybersecurity and Privacy Risks” : https://csrc.nist.gov/publications/detail/nistir/8228/final</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/07/security-twins-a-new-security-trust-guarantee-for-connected-devices-2-2/">&#8220;Security Twins&#8221;: A new security &#038; trust guarantee for connected devices (1/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
