RFC 8576: Internet of Things (IoT) Security: State of the Art and Challenges
In plain English — editorial summary, not part of the RFC
The Internet of Things (IoT) concept refers to the usage of standard Internet protocols to allow for human-to-thing and thing-to-thing communication. The security needs for IoT systems are well recognized, and many standardization steps to provide security have been taken -- for example, the specification of the Constrained Application Protocol (CoAP) secured with Datagram Transport Layer Security (DTLS). However, security challenges still exist, not only because there are some use cases that lack a suitable solution, but also because many IoT devices and systems have been designed and deployed with very limited security capabilities. In this document, we first discuss the various stages in the lifecycle of a thing. Next, we document the security threats to a thing and the challenges that one might face to protect against these threats. Lastly, we discuss the next steps needed to facilitate the deployment of secure IoT systems. This document can be used by implementers and authors of IoT specifications as a reference for details about security considerations while documenting their specific security challenges, threat models, and mitigations. This document is a product of the IRTF Thing-to-Thing Research Group (T2TRG).
Document record
- Document ID
- RFC8576
- Published
- April 2019
- Authors
- O. Garcia-Morchon; S. Kumar; M. Sethi
- Status
- INFORMATIONAL
- Stream
- IRTF
- Area
- —
- Pages
- 50
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 8628OAuth 2.0 Device Authorization GrantCurrent
August 2019
- RFC 7744Use Cases for Authentication and Authorization in Constrained EnvironmentsCurrent
January 2016
- RFC 8724SCHC: Generic Framework for Static Context Header Compression and FragmentationUpdated
April 2020
- RFC 8387Practical Considerations and Implementation Experiences in Securing Smart Object NetworksCurrent
May 2018
- RFC 8323CoAP (Constrained Application Protocol) over TCP, TLS, and WebSocketsUpdated
February 2018
- RFC 8240Report from the Internet of Things Software Update (IoTSU) Workshop 2016Current
September 2017
- RFC 9011Static Context Header Compression and Fragmentation (SCHC) over LoRaWANCurrent
April 2021
- RFC 9100Sensor Measurement Lists (SenML) Features and VersionsCurrent
August 2021
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?