{"id":41695,"date":"2019-10-17T15:43:10","date_gmt":"2019-10-17T15:43:10","guid":{"rendered":"https:\/\/stg.cira.ca\/secure-iot-registry\/"},"modified":"2024-08-26T12:40:14","modified_gmt":"2024-08-26T16:40:14","slug":"secure-iot-registry","status":"publish","type":"page","link":"https:\/\/stg.cira.ca\/en\/secure-iot-registry\/","title":{"rendered":"Secure IoT Registry"},"content":{"rendered":"<p>CIRA recently joined L-SPARK Global\u2019s Secure IoT Accelerator program to help solve a massive, industry-wide problem: securing internet of things (IoT) devices.<\/p>\n<p>Over the coming year, CIRA Labs will be working with a cross-disciplinary team of experts, technologists and advisors to develop a cutting edge Secure IoT Registry \u2013 an innovative framework to securely provision IoT devices.<\/p>\n<h2><strong>So what\u2019s the pitch?<\/strong><\/h2>\n<p>Take an IoT device such as a generic smart city parking meter. The internet-connected smart meter is similar to a domain name in several respects:<\/p>\n<ul>\n<li>Both have owners and delegations.<\/li>\n<li>Each can be transferred to a different owner.<\/li>\n<li>Their delegation can change (e.g., pointing to a different cloud service provider is similar to pointing to a different IP address).<\/li>\n<\/ul>\n<p>As a domain registry, CIRA creates a public DNS zone file for .CA and we publish WHOIS information about each domain. As an IoT registry, we would track a given IoT device\u2019s eSIMID, public keys, cloud service provider, and mobile network operator (and their status), and then create a public DNS record of&nbsp;certificate fingerprints&nbsp;that can be used to authenticate individual IoT devices and their cloud service provider credentials based on the unique IoT device eSIMID \u2014 all while&nbsp;leveraging the internet based root of trust embedded in the DNS and DNSSEC.<\/p>\n<p>As a result, the CIRA IoT Registry allows the world\u2019s generic IoT devices to seamlessly and securely work between any manufacturer, owner, service provider and network operator.<\/p>\n<p><strong><\/strong><\/p>\n<p><img decoding=\"async\" class=\" size-full wp-image-1730\" src=\"https:\/\/stg.cira.ca\/uploads\/2019\/10\/iot-registry-explanation-graphics_191017-01_0.png\" alt=\"\" title=\"\" width=\"8000\" height=\"4500\" srcset=\"https:\/\/stg.cira.ca\/uploads\/2019\/10\/iot-registry-explanation-graphics_191017-01_0.png 8000w, https:\/\/stg.cira.ca\/uploads\/2019\/10\/iot-registry-explanation-graphics_191017-01_0-300x169.png 300w, https:\/\/stg.cira.ca\/uploads\/2019\/10\/iot-registry-explanation-graphics_191017-01_0-1024x576.png 1024w, https:\/\/stg.cira.ca\/uploads\/2019\/10\/iot-registry-explanation-graphics_191017-01_0-768x432.png 768w, https:\/\/stg.cira.ca\/uploads\/2019\/10\/iot-registry-explanation-graphics_191017-01_0-1536x864.png 1536w, https:\/\/stg.cira.ca\/uploads\/2019\/10\/iot-registry-explanation-graphics_191017-01_0-2048x1152.png 2048w\" sizes=\"(max-width: 8000px) 100vw, 8000px\" \/><\/p>\n<p><strong><\/strong><\/p>\n<h2><strong>What\u2019s the problem?<\/strong><\/h2>\n<p>With the widespread deployment of 5G networks on the horizon, there will soon be an explosion of internet-connected devices in households and businesses around the world. Everything from doorbells to fridges to thermostats will ship with a SIM card and a high-quality internet connection. As more and more devices become internet-connected, the cybersecurity risks around them will grow. With this in mind, CIRA is working on an innovative framework to mitigate the risks these devices pose to users as well as the public internet.<\/p>\n<p>&nbsp;<\/p>\n<h2><strong>How does the Secure IoT Registry work?<\/strong><\/h2>\n<p>CIRA Lab\u2019s IoT Registry will establish trust between the mobile network operators , cloud service providers, IoT device manufacturers, and end-users. The IoT Registry\u2019s core function is to enable any IoT device to connect to any cloud service providers. In short, the IoT registry lets you connect anything to everything securely.<\/p>\n<p><img decoding=\"async\" class=\" size-full wp-image-1732\" src=\"https:\/\/stg.cira.ca\/uploads\/2019\/10\/cira-iot-registry_web-graphic_191017-011.png\" alt=\"\" title=\"\" width=\"2885\" height=\"2798\" srcset=\"https:\/\/stg.cira.ca\/uploads\/2019\/10\/cira-iot-registry_web-graphic_191017-011.png 2885w, https:\/\/stg.cira.ca\/uploads\/2019\/10\/cira-iot-registry_web-graphic_191017-011-300x291.png 300w, https:\/\/stg.cira.ca\/uploads\/2019\/10\/cira-iot-registry_web-graphic_191017-011-1024x993.png 1024w, https:\/\/stg.cira.ca\/uploads\/2019\/10\/cira-iot-registry_web-graphic_191017-011-768x745.png 768w, https:\/\/stg.cira.ca\/uploads\/2019\/10\/cira-iot-registry_web-graphic_191017-011-1536x1490.png 1536w, https:\/\/stg.cira.ca\/uploads\/2019\/10\/cira-iot-registry_web-graphic_191017-011-2048x1986.png 2048w\" sizes=\"(max-width: 2885px) 100vw, 2885px\" \/><\/p>\n<p>The IoT Registry is similar to a domain registry. In the same way that a domain name\u2019s (www.cira.ca) ownership can be transferred, an IoT device ownership can be transferred, from user A to user B. Similarly, in the same way the domain delegation can be changed, pointing to from user A\u2019s website to user B\u2019s website, an IoT device can connect from one cloud service provider to another. To facilitate these changes, CIRA has developed a solution to deliver IoT credentials directly on the eSIM card securely. We are leveraging the public DNS and it\u2019s DNSSEC based cryptographically enabled chain of trust feature as a new root of trust simplifying the verification of certificates.<\/p>\n<p>&nbsp;<\/p>\n<h2><strong>You can check out&nbsp;<a href=\"https:\/\/github.com\/CIRALabs\/CIRA-Secure-IoT-Registry\">our full demo here<\/a>.<\/strong><\/h2>\n<p><img decoding=\"async\" class=\" size-full wp-image-1734\" src=\"https:\/\/stg.cira.ca\/uploads\/2019\/10\/cira-IoT-registry-slide_0.PNG\" alt=\"\" title=\"\" width=\"977\" height=\"548\" srcset=\"https:\/\/stg.cira.ca\/uploads\/2019\/10\/cira-IoT-registry-slide_0.PNG 977w, https:\/\/stg.cira.ca\/uploads\/2019\/10\/cira-IoT-registry-slide_0-300x168.png 300w, https:\/\/stg.cira.ca\/uploads\/2019\/10\/cira-IoT-registry-slide_0-768x431.png 768w\" sizes=\"(max-width: 977px) 100vw, 977px\" \/><\/p>\n<h2>&nbsp;<\/h2>\n<h2><strong>What are the benefits of an IoT Registry?<\/strong><\/h2>\n<ul>\n<li><strong>Interoperability. <\/strong>Enabling generic IoT Devices to connect to generic Cloud Services using standard APIs.<strong>&nbsp; <\/strong>With an IoT Registry, any IoT device can be switched to any cloud provider easily and securely.<\/li>\n<li><strong>Streamlined operations.<\/strong> The Registry keeps track of cloud provider certificates and individual IoT device keys so that cloud providers and device manufacturers don\u2019t have to.<\/li>\n<li><strong>Proven security. <\/strong>Certificates are managed using cryptographically-enabled, road-worn DNSSEC enabled DNS infrastructure.<\/li>\n<li><strong>No \u201cman in the middle\u201d attacks.<\/strong> Our IoT Registry makes it impossible for attackers to create fake credentials. The credentials (public key pair) are created in a Hardware Security Module (HSM) and encrypted with the public key of the IoT device, keys are then destroyed, and the fingerprint of the IoT device keys can be validated in the public DNS using DNSSEC CERT records. &nbsp;The keys and configuration information are sent to the mobile network operator which, in turn, writes the IoT profile onto the eSIM IoT Security Applet, at which point the IoT device can decrypt the IoT profile.&nbsp; This ensures secure and trusted communication between the IoT registry and the device.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h2><strong><\/strong><strong>Why is CIRA working on this?<\/strong><\/h2>\n<blockquote>\n<p>&nbsp;<\/p>\n<p>\u201cThe incoming tsunami of IoT devices will fundamentally change the way we need to approach cybersecurity. Innovative technologies will require innovation in security, especially when so many IoT devices lack adequate security themselves. CIRA&#8217;s Secure IoT Registry demonstrates how a national registry can be used to establish trust and configure IoT devices of all types.&#8221;<\/p>\n<p>-Brian O\u2019Higgins, Security Expert<\/p>\n<p>\u201cThe CIRA IoT Registry allows the world\u2019s generic IoT devices to seamlessly and securely work between any manufacturer, owner, service provider and network operator.\u201d<\/p>\n<p>-Don Slaunwhite, CIRA IoT Registry Product Manager<\/p>\n<\/blockquote>\n<p>CIRA is a purpose-driven not-for-profit working hard to make the internet safe, stable and secure through our DNS infrastructure and cybersecurity products. As we look ahead to the next evolution of the internet \u2013 an internet where cloud computing, big data, and IoT devices are ubiquitous \u2013 we see a huge opportunity to leverage our 20 years of world-class registry operations and help solve the problem of securely provisioning IoT devices. Once it\u2019s up and running, we are confident that our Secure IoT Registry will help make the global internet more secure.<\/p>\n<p>&nbsp;<\/p>\n<h2><strong>Learn more:<\/strong><\/h2>\n<ul>\n<li>CIRA: <a href=\"https:\/\/github.com\/CIRALabs\/CIRA-Secure-IoT-Registry\">&nbsp;IoT Registry DEMO<\/a>.<\/li>\n<li>CIRA: <a href=\"https:\/\/stg.cira.ca\/blog\/cybersecurity\/we-just-joined-a-brand-new-iot-accelerator-help-solve-a-massive-industry-wide\">We just joined a brand new IoT accelerator to help solve a massive, industry-wide security problem<\/a>.<\/li>\n<li>Ottawa Business Journal: <a href=\"https:\/\/obj.ca\/ottawa-based-cira-lands-spot-in-first-cohort-of-l-sparks-new-secure-iot-accelerator\/\">Ottawa-based CIRA lands spot in first cohort of L-Spark\u2019s new secure IoT accelerator<\/a>.<\/li>\n<li><span class=\"MsoHyperlink\"><\/span>CIRA: <a href=\"https:\/\/stg.cira.ca\/blog\/state-internet\/update-cira-iot-security\">An update from CIRA on IoT security<\/a><span class=\"MsoHyperlink\"><\/span><\/li>\n<li>ISOC: <a href=\"https:\/\/www.internetsociety.org\/deploy360\/dnssec\/\">DNSSEC Primer<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CIRA recently joined L-SPARK Global\u2019s Secure IoT Accelerator program to help solve a massive, industry-wide problem: securing internet of things (IoT) devices. Over the coming year, CIRA Labs will be working with a cross-disciplinary team of experts, technologists and advisors to develop a cutting edge Secure IoT Registry \u2013 an innovative framework to securely provision [&hellip;]<\/p>\n","protected":false},"author":11,"featured_media":1730,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"ngg_post_thumbnail":0,"slim_seo":{"title":"Secure IoT Registry - CIRA","description":"CIRA recently joined L-SPARK Global\u2019s Secure IoT Accelerator program to help solve a massive, industry-wide problem: securing internet of things (IoT) devices."}},"category":[664],"class_list":["post-41695","page","type-page","status-publish","has-post-thumbnail","hentry","cira_category-cybersecurity"],"acf":[],"publishpress_future_action":{"enabled":false,"date":"2026-06-10 21:01:21","action":"change-status","newStatus":"draft","terms":[],"taxonomy":"translation_priority","extraData":[]},"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/stg.cira.ca\/en\/wp-json\/wp\/v2\/pages\/41695","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/stg.cira.ca\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/stg.cira.ca\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/stg.cira.ca\/en\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/stg.cira.ca\/en\/wp-json\/wp\/v2\/comments?post=41695"}],"version-history":[{"count":0,"href":"https:\/\/stg.cira.ca\/en\/wp-json\/wp\/v2\/pages\/41695\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/stg.cira.ca\/en\/wp-json\/wp\/v2\/media\/1730"}],"wp:attachment":[{"href":"https:\/\/stg.cira.ca\/en\/wp-json\/wp\/v2\/media?parent=41695"}],"wp:term":[{"taxonomy":"cira_category","embeddable":true,"href":"https:\/\/stg.cira.ca\/en\/wp-json\/cira\/v1\/category?post=41695"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}