Report: W3C IG on Web-of-Things Security and Privacy Oliver Pfaff
Coordinates Abbreviation: SP Mailing list prefix: [IG-SP] Landing page: (linked on the Wiki page of the W3C WoT IG)
Working Hypotheses There will be no one-size-fits-all solution for security and privacy Given constraints do vary too much across WoT scenarios/use cases Corresponding work does not start on an empty page Patterns, (standard) protocols, mechanisms, components that can be re-used (with or without adaptation) do exit But it can not assume to find re-usables for every requirement The set of available offerings will have white spots There will be a suite of security and privacy artifacts from which WoT products/projects will serve themselves according given needs Think of this suite as a chocolate box ;-)
Planned Deliverables 1.Security&Privacy ChallengesSecurity&Privacy Challenges 2.Security&Privacy RequirementsSecurity&Privacy Requirements 3.Landscape of Security&Privacy MeansLandscape of Security&Privacy Means 4.Security&Privacy Advanced ConceptsSecurity&Privacy Advanced Concepts 5.Security&Privacy GlossarySecurity&Privacy Glossary 6.Security&Privacy ReferencesSecurity&Privacy References
Security&Privacy ChallengesSecurity&Privacy Challenges Status Objective: explain the drivers behind adaptation and innovation needs State: draft Open points: Reflect opinions/positions of other member organizations (the current draft presents the view of Siemens)
Security&Privacy RequirementsSecurity&Privacy Requirements Status Objective: identify the security and privacy requirements for the use cases considered in the WoT IG State: draft (already considered use cases), not yet stated (others) Open points (joined effort between [IG-SP] and [TF-*]): Already considered use cases: revisit/refine Others: add coverage
Landscape of Security&Privacy MeansLandscape of Security&Privacy Means Status Objective: assess the fitness of existing/emerging security and privacy means State: late draft (design-time means), not yet stated (runtime means) Open points: Design-time means: review, update to latest IETF drafts, consider to add graphics Runtime means: elaborate
Security&Privacy Advanced ConceptsSecurity&Privacy Advanced Concepts Status Objective: address more complex or specific situations (e.g. requiring compositions of single security and privacy means) State: brainstorming (things discovery authorization), not yet stated (others e.g. end-to-end security) Open points: Things discovery authorization: elaborate (joined effort between [IG-SP] and [TF-TD] with interested parties at IRTF T2TRG) Others: identify and elaborate
Security&Privacy GlossarySecurity&Privacy Glossary Status Objective: housekeeping State: late draft Open points: n.a.
Security&Privacy ReferencesSecurity&Privacy References Status Objective: housekeeping State: draft Open points: n.a.
Further Open Points Address resilience Augment (next) plugfest with security and privacy functionality