A city is a large human settlement that serves the people who live there, and a smart city is a concept of how cities might better serve their residents through new forms of technology. In this paper, we focus on four major smart city domains according to Maslow's hierarchy of needs: smart utility, smart transportation, smart homes, and smart healthcare. Numerous IoT applications have been developed to achieve the intelligence that we desire in our smart domains, ranging from personal gadgets such as health trackers and smart watches to large-scale industrial IoT systems such as nuclear and energy management systems. However, many of the existing smart city IoT solutions can be made better by considering the suitability of their security strategies. Inappropriate system security designs generally occur in two scenarios: first, system designers recognize the importance of security but are unsure of where, when, or how to implement it; and second, system designers try to fit traditional security designs to meet the smart city security context. Thus, the objective of this paper is to provide application designers with the missing security link they may need to improve their security designs. By evaluating the specific context of each smart city domain and the context-specific security requirements, we aim to provide directions on when, where, and how they should implement security strategies and the possible security challenges they need to consider. In addition, we present a new perspective on security issues in smart cities from a data-centric viewpoint by referring to the reference architecture, the Activity-Network-Things (ANT)-centric architecture, built upon the concept of "security in a zero-trust environment". By doing so, we reduce the security risks posed by new system interactions or unanticipated user behaviors while avoiding the hassle of regularly upgrading security models.
翻译:城市是一个大型的人类住区,为居住在那里的人们服务,而智能城市则是一个城市如何通过新技术形式更好地为居民服务的概念。在本文中,我们根据马斯洛的需求等级,侧重于四个主要智能城市领域:智能公用事业、智能交通、智能住宅和智能医疗。开发了许多IOT应用软件,以获得我们在智能领域的所需情报,从个人工具,如健康追踪器和智能手表,到大规模工业性IOT系统,如核和能源管理系统。然而,许多现有的智能城市IOT解决方案可以通过考虑其安全战略的适宜性而得到更好的改进。在两种情况下,系统安全设计师通常认识到安全的重要性,但不确定何时或如何执行;第二,系统设计师试图将传统安全设计与智能城市安全环境相匹配。因此,本文件的目的是为应用程序设计师提供缺少的安全核心链接,从而降低其安全设计。通过评估每个智能城市域域域域和内部安全理念的具体背景,我们从安全理念角度出发,在考虑新的安全方向时,我们如何从新的安全方向上进行升级。