Back close

Course Detail

Course Name Security of Internet Things-Security and Privacy of Internet of Things
Course Code 26SN636
Program M. Tech. in Cyber Security Systems & Networks
Credits 3
Campus Amritapuri

Syllabus

Syllabus

Fundamentals and Security Requirements: Fundamentals, Architecture of IoTs and Reference Models, Characteristics and Constraints of IoT Devices, IoT Security Requirements, Security Goals – Confidentiality, Integrity, Availability, Authentication and Non-Repudiation, IoT Privacy Preservation Issues, Threat Modelling and Attack Surface Analysis.

Threats, Attacks and Device Security: Attack Models – Attacks to Sensors in IoTs, Attacks to RFIDs in IoTs, Attacks to Network Functions in IoTs, Attacks to Back-end Systems, Physical Attacks, Side Channel Attacks, Malware and Botnet Attacks, Mirai Botnet and Distributed Denial of Service (DDoS) Attacks.

Security in Front-end Sensors and Equipment, Prevent Unauthorized Access to Sensor Data, M2M Security, RFID Security, Cyber-Physical Object Security, Hardware Security, Front-end System Privacy Protection.

Authentication and Access Control: Authentication and Access Control in IoT – Device Identity Management, Public Key Infrastructure (PKI) for IoT, Mutual Authentication, Lightweight Authentication Protocols, Role Based Access Control (RBAC), Attribute Based Access Control (ABAC), Capability Based Access Control, OAuth 2.0 and ACE-OAuth, Zero Trust Architecture for IoT.

Communication and Network Security: Networking Function Security – IoT Networking Protocols, Secure IoT Lower Layers, Secure IoT Higher Layers, Secure Communication Links in IoTs, Lightweight Cryptography, TLS and DTLS, MQTT Security, CoAP Security, ZigBee Security, Bluetooth Low Energy (BLE) Security, Secure Key Management.

Firmware, Software and Backend Security: Firmware and Software Security – Firmware Architecture, Firmware Extraction and Analysis, Secure Firmware Update, Over-the-Air (OTA) Security, Secure Resource Management, Secure IoT Databases.

Back-end Security – Secure Resource Management, Edge Computing Security, Fog Computing Security, Cloud Security for IoT, Secure APIs, Container Security, Industrial IoT Security, Smart Grid Security.

Emerging Trends and Applications: Blockchain for IoT Security, Artificial Intelligence and Machine Learning for IoT Security, Post Quantum Cryptography for IoT, eSIM and IoT SAFE, Security Standards and Frameworks, Existing Testbeds on Security and Privacy of IoT, Commercialized Security Products.

Text Books / References
  1. FeiHU, “Security and Privacy in Internet of Things (IoTs): Models, Algorithms, and Implementations”, CRC Press,2016
  2. Russell, Brian, and Drew Van Duren, “Practical Internet of Things Security”, PacktPublishing, 
  3. Ollie Whitehouse, “Security of Things: An Implementers’ Guide to Cyber-Securityfor Internet of Things Devices and Beyond”, NCC Group, 2014
  4. Josang, S. Furnell and S. Papadaki, “Security and Trust in Internet of Things”, Springer, 2021.
  5. NISTIR 8259, “Foundational Cybersecurity Activities for IoT Device Manufacturers”, National Institute of Standards and Technology (NIST), 2020.
  6. ETSI EN 303 645, “Cyber Security for Consumer Internet of Things: Baseline Requirements”, ETSI, 2020

Introduction

The Internet of Things (IoT) has emerged as a transformative technology that interconnects billions of devices, sensors, and services to enable intelligent applications in smart homes, healthcare, industrial automation, transportation, and smart cities. However, the heterogeneous and resource-constrained nature of IoT devices, coupled with large-scale deployment and pervasive connectivity, introduces significant security and privacy challenges. This course provides a comprehensive understanding of the principles, threats, vulnerabilities, and protection mechanisms associated with IoT ecosystems. The course covers IoT security requirements, privacy preservation, authentication and access control, secure communication protocols, hardware and firmware security, edge and cloud security, and emerging paradigms such as Zero Trust Architecture, Blockchain, Artificial Intelligence, and Post-Quantum Cryptography for IoT. The laboratory component provides hands-on experience in analyzing, designing, and implementing security and privacy solutions for IoT systems using contemporary tools and frameworks

Objectives and Outcomes

Course Objectives

  1. Understand IoT architectures, security requirements, privacy concerns, and threat models in IoT ecosystems.
  2. Analyze vulnerabilities, attacks, and countermeasures for IoT devices, sensors, communication protocols, and backend infrastructures.
  3. Apply authentication, access control, and secure communication mechanisms for protecting IoT systems and data.
  4. Develop practical skills in hardware security, firmware analysis, vulnerability assessment, and secure IoT application development using contemporary tools and frameworks.
  5. Evaluate emerging technologies and paradigms such as Zero Trust Architecture, Blockchain, Artificial Intelligence, and Post-Quantum Cryptography for enhancing security and privacy in IoT.

Pre-requisite: Basic knowledge of Computer Networks, Information Security, Cryptography, Operating Systems, and Embedded Systems.

Course Outcome

CO Description
CO1 Understand IoT architectures, security requirements, privacy issues, threat models, and attack surfaces in IoT ecosystems.
CO2 Analyze vulnerabilities and attacks on IoT devices, sensors, RFID systems, communication networks, and backend infrastructures.
CO3 Design and implement authentication, access control, and secure communication mechanisms for IoT systems using contemporary security frameworks and protocols.
CO4 Perform hardware reconnaissance, firmware analysis, vulnerability assessment, and implement security mechanisms for securing IoT devices and infrastructures.
CO5 Develop secure IoT applications incorporating privacy-preserving techniques, Zero Trust principles, secure communication, and device identity management.
CO6 Evaluate emerging technologies such as Blockchain, Artificial Intelligence, Post-Quantum Cryptography, and eSIM/IoT SAFE for enhancing security and privacy in IoT systems.

Evaluation Pattern

CO-PO Mapping 

Correlation Levels: 3 = High, 2 = Moderate, 1 = Low

CO / PO PO1 PO2 PO3
CO1 1 3
CO2 3 3
CO3 2 2 3
CO4 3 1 3
CO5 2 2 3
CO6 3 2 3
CO Justification
CO1 Understanding IoT architecture, security requirements, privacy and threat models contributes strongly to specialization knowledge (PO3) and problem analysis.
CO2 Analysis of attacks and vulnerabilities develops investigation and analytical skills (PO1) and enhances domain expertise (PO3).
CO3 Designing authentication, access control and secure communication mechanisms require design skills, use of modern tools/frameworks and technical documentation (PO2).
CO4 Hardware reconnaissance, firmware analysis and vulnerability assessment require research and investigative skills (PO1), modern security tools, and specialization knowledge (PO3).
CO5 Developing secure IoT applications using Zero Trust principles and secure communication mechanisms involves design and implementation skills, tool usage, and domain mastery (PO3).
CO6 Evaluation of Blockchain, AI, Post-Quantum Cryptography and eSIM/IoT SAFE requires investigation (PO1), technical reporting (PO2), and advanced specialization knowledge (PO3).

Evaluation Pattern – 70:30

  • Midterm Exam – 30%
  • Assignments – 10%
  • Lab Assignments – 30%
  • Final Exam – 30%

DISCLAIMER: The appearance of external links on this web site does not constitute endorsement by the School of Biotechnology/Amrita Vishwa Vidyapeetham or the information, products or services contained therein. For other than authorized activities, the Amrita Vishwa Vidyapeetham does not exercise any editorial control over the information you may find at these locations. These links are provided consistent with the stated purpose of this web site.

Admissions Apply Now