On the Security Aspects of Internet of Things: A Systematic Literature Review

Evandro L. C. Macedo, Egberto A. R. de Oliveira, Fabio H. Silva, Rui R. Mello Jr, Felipe M. G. França, Flavia C. Delicato, José F. de Rezende, and Luís F. M. de Moraes

10.1109/JCN.2019.000048

Abstract : Internet of Things (IoT) has gained increasing visibilityamong emerging technologies and undoubtedly changing our daily life. Its adoption is strengthened by the growth of connected de-vices (things) as shown in recent statistics. However, as the number of connected things grows, responsibility related to security aspectsalso needs to increase. For instance, cyberattacks might happenif simple authentication mechanisms are not implemented on IoTapplications, or if access control mechanisms are weakly defined. Considering the relevance of the subject, we performed a system-atic literature review (SLR) to identify and synthesize security is-sues in IoT discussed in scientific papers published within a period of 8 years. Our literature review focused on four main security as-pects, namely authentication, access control, data protection, and trust. We believe that a study considering these topics has the po-tential to reveal important opportunities and trends related to IoT security. In particular, we aim to identify open issues and tech-nological trends that might guide future studies in this field, thus providing useful material both to researchers and to managers anddevelopers of IoT systems. In this paper, we describe the protocoladopted to perform the SLR and present the state-of-the-art on thefield by describing the main techniques reported in the retrievedstudies. To the best of our knowledge, ours is the first study tocompile information on a comprehensive set of security aspects inIoT. Moreover, we discuss the placement, in terms of architecturaltiers, for deploying security techniques, in an attempt to provideguidelines to help design decisions of security solution developers.We summarize our results showing security trends and researchgaps that can be explored in future studies.​ 

Index terms : Access control, architecture, authentication, data protection, internet of things, IoT, security, techniques, trust.