Speaker
Description
Identity and Access Management (IAM) remains one of the most persistent challenges in the security of Edge IoT systems. Conventional IAM solutions, originally designed for centralised environments, are increasingly ill-suited to edge deployments: they suffer from high latency, low energy efficiency and high resource consumption; they lack true 'offline-first' operation in scenarios with intermittent connectivity; and they only partially comply with the Zero Trust principles set out in NIST SP 800-207 [7]. Although these problems affect Edge IoT in general, they are significantly exacerbated in devices based on ARM architectures, which dominate the IoT market due to their low energy consumption. These devices have constraints on resources such as CPU, memory and power, but at the same time offer the opportunity to use TrustZone to create secure and isolated execution environments (Trusted Execution Environments). This position paper advocates the integration of Biscuit (a capability-based authorisation model with Datalog- based attenuation) into a distributed Zero Trust architecture optimised for ARM devices with TrustZone. The resulting solution paves the way for the next generation of IAM for critical applications in 5G, the Industrial Internet of Things (IIoT) and connected healthcare.