IoT Security
14.Jul.2020

Introduce the latest IoT device certification processes to deal with the frequent information security attacks

Share:
Whenever emerging technologies and applications appear in the market, problems sometimes arise that were not thought of when they were originally planned. This is just like the launch of Internet of Things (IoT) products. They are accompanied by some security attacks such as the Mirai Botnet in 2016 [1]. When we discuss the security attacks on the IoT products, we often find that the attacks are because users have not changed the default password of the IoT product login page. Moreover, users do not fully understand and are unfamiliar with the functions provided by IoT products, so that these products with remote login functions are exposed on the Internet. In addition, manufacturers are not paying attention to security issues and trends, and use insecure software design such as using software packages with known vulnerabilities, no specific settings for password length and complexity required for user accounts, or even turning on debug mode by default, etc. These security design vulnerabilities are all targeted by malicious programs, when cyberattackers want to attack and spread to IoT products.

In response to the security issues of IoT products, many organizations at home and abroad have actively developed the related product security regulations. The Industrial Development Bureau (IDB) of Ministry of Economic Affairs (MOEA) and National Communications Commission (NCC) as the competent authorities has entrusted the Association of Information and Communication Standards (TAICS) to formulate the security inspection standards and certification systems. Currently, TAICS has completed the industry information security standards and certification systems for video surveillance system, smart bus and smart street lamp. Manufacturers can entrust an accredited laboratory to conduct security testing on their IoT products, and can get the qualified certification mark after product passed the tests and audits [2].
 
Video Surveillance Product Certification Program
Video Surveillance Product Certification Program
 

In the United States, the Cellular Telecommunication Industry Association (CTIA) developed the IoT Cybersecurity Certification Program [3]. IoT product manufacturers who want to get the IoT Cybersecurity Certification Program certificate established by CTIA can first choose a CTIA Authorized Testing Laboratory (CATL) for pre-certification operation, and then submit certification request through the CTIA certification website. The CTIA accredited laboratory would conduct testing and submit test reports to CTIA for review, helping the product to get CTIA's security certification.
 
CTIA IoT Cybersecurity Certification Program
CTIA IoT Cybersecurity Certification Program
 

In addition to governments, industry associations or other organizations, large enterprises also require that products manufactured by their suppliers need to meet their security requirements. For example, Amazon requires that all products using Alexa Cloud services must undergo security testing by authorized security laboratories [4]. The laboratory would submit the test report to Amazon for review. Only after the review is passed, the product can be released [5].
 
Alexa Product Certification Procedure
Alexa Product Certification Procedure
 

By passing different information security certifications, IoT products have the ability to resist different attacks from hackers. The information security certifications must be carried out by a qualified certification laboratory. The report issued by the certification laboratory is the only way to apply for a certificate of conformity to the administrations. To become an accredited laboratory, applicants must first pass the ISO 17025 laboratory certification and be familiar with the testing items of security standards and certification systems. They also need to develop standard operating procedures for testing items, and have to comply with the requirements of ISO 17025 in terms of personnel, tools, environment, and testing practices. Onward Security has an ISO 17025-certified security testing laboratory and has been authorized by TAICS, CTIA and Amazon. As an accredited security testing laboratory, it can conduct security certification testing for IoT products, smart phones, webcams, Amazon Alexa products, etc. The laboratory assists manufacturers to get security certificates or marks, thus meeting buyer requirements and entering the international market.
 

Inquiry

Contact Us
Thank you for visiting us. Please leave your contact information, and we will reply you as soon as we can.
  • Onward Security is committed to your privacy. Your information won't be shared with third parties and is used to contact you about relevant content. You may unsubscribe at any time. For more info, please read our Privacy Policy. By clicking below submit button, you consent to allow Onward Security to store and process the personal information submitted above to provide you the content requested.

Why Onward Security

In-depth Cybersecurity Techniques+

  • Uncovered 40+ zero-day vulnerabilities (CVE)
  • Discovered 3000+ IoT product vulnerabilities

Dedicated to IoT Product Security+

  • 150+ cybersecurity projects in IoT industry
  • Tested 700+ IoT product security

Global Compliance and Certification Capability+

  • 300+ customers / 10+ countries certification obtained
  • Compliance experience in IIoT, medical, automotive, BFSI, and consumer IoT industry
Subscribe to Newsletter:

Verification

Click the numbers in sequence.

WeChat
This site uses cookies to improve your experience and to provide content customized specifically to your interests. By continuing to browse our site without changing your cookie settings (click the Privacy Policy button for more info), or by clicking the Continue button, you hereby acknowledge and agree to our privacy policy and use of cookies.