Security and Privacy for Connected Devices

Abstract

The thesis tackles the challenge of providing secure and private connected devices. Our definition of connected device includes information technology, operational technology, and Internet of Things devices and their related networks and communication technologies. Since we connect billions of devices and use them for pervasive critical services, like communication, positioning, and transportation, it is essential to protect connected devices from security, privacy, and even safety breaches. Security and privacy of connected devices is a massive research area. We focus on four urgent research questions (RQ1–RQ4) related to the security and privacy of standard and proprietary technologies used by connected devices, risk assessment with threat modeling, and unauthorized device and user tracking. We answer the presented research questions with novel contributions from four research papers (BLUFFS, E-Spoofer, ADF, and FP-tracer) and discuss five more research papers related to the thesis (E-Trojans, CTRAPS, BreakMi, AutoBtSec, and BLURtooth). We conclude the thesis discussing future directions in connected system security and privacy, including the open-source hardware revolution.

Publication
HDR Thesis, École polytechnique (EP)