Serenity, System Engineering for Security & Dependability
Information Society and MediaSixth Framework Programme
Forum
Newsletter Subscription Site Map Contact

Issues

The new requirements of AmI systems

The specific characteristics of AmI ecosystems make it almost impossible to adapt and to apply the existing security and dependability solutions.

The concepts of system and application as we know them today will disappear. Static architectures with well-defined pieces of hardware, software, communication links, limits and owners will be replaced by architectures that will be sensitive, adaptive, context-aware and responsive to users’ needs and habits : AmI environments. AmI systems will contain a large number of heterogeneous computing, communication infrastructures and devices. Moreover, not only systems but also applications will have to make effective use of the resources available on-the-fly, and adapt to different hardware and software, and even firmware configurations.

Security and dependability challenges will arise from complexity, ubiquity and autonomy of computing and communications as well as from the need for resilience, self-healing, mobility, dynamic content and volatile environments. In addition, the advent of new societal applications will lead to new policy challenges in areas such as the protection of citizens against cyber threats, privacy, identification and authentication for service access, interoperable content and digital rights management, for which strategic and solid research on security and trust is required.

Requirements today Requirements tomorrow
  • Security & Dependability only at application level
  • security and dependability considered as the last issue
  • security and dependability faced, mainly, from a technological point of view
  • security and dependability "applied to relatively stable, well-defined, consistent configurations, contexts and participants to security arrangements"
  • "conformable security"
  • Social, political, ethical, technological aspects to be considered
  • Heterogeneity, mobility, size, complexity, ...
  • Distribution of knowledge
  • data protection w.r.t. the operative context (privacy, anonymity, etc.)
  • Communication infrastructures and hardware devices not under the control of the security engineers

The challenge of their security
How a system built on "secure and dependable" components can be made "secure and dependable" itself ?
How to face the new architecture features that are sensitive, adaptive, context-aware...
In AmI environment, which is emphasis legal, privacy and social facets will have ?
How to handle on-demand request of services, new communications means, dynamic service composition, etc. with these new security and dependability issues ?
Who will be in charge of security and dependability in the AmI ? How to handle the fact that there will be no Central Administration left to monitor and check for security risks ?

Today’s economy and society are vitally dependent on distributed ICT infrastructures and systems serving their core processes and functionalities. With the availability of ubiquitous computing abilities, ad-hoc access to network and communication infrastructures, a variety of devices supporting the mobile users’ needs with advanced functionalities, and the ever growth of the available entities (including devices, applications, systems, environments, and their communication) that can spontaneously interact to offer completely new features and serve evolving requirements, this dependability will even increase.
Economy and society will be operating on the top of networks and infrastructures offering a universe of services, features, and functions that are combined, utilised, and dissolved in an on-demand way. This technology is pervasive, since the infrastructures are available anywhere and at anytime and integrate artefacts, people, processes, authorities and businesses, and, thus, society as a whole. It results in what we call Ambient Intelligence Ecosystems, acting goal-driven, adapting flexibly, and evolving over time.

AmI can benefit economy and society in meeting their advanced needs only if it is run reliably and secure. The openness and heterogeneity of AmI Ecosystems, though necessary for their operation, is more likely to show vulnerabilities than traditional systems and architectures designed to run in a particular domain of control. They have to cope with unknown resources, entities, and services, with behaviour that cannot be controlled by single entities or organisations, with vulnerabilities introduced by the heterogeneity of the technologies involved, and the evolving and potentially conflicting security requirements and policies of the parties involved.

SERENITY has the potential to provide a significant and extensive contribution to secure and make dependable AmI Ecosystems. With its systematic approach to the provision of security solutions, based on semantically enhanced patterns and integration schemes, it is able to exploit given security components and services and to combine them in a goal-driven and flexible way.

Finally, the SERENITY results are offered through a framework that can be adapted to one’s needs and utilised by different businesses and industries, thus enabling them to optimise their contribution to the security and dependability of an AmI Ecosystem according to their individual needs.

To learn more about SERENITY, the consortium, its activities, to discuss with the partners and participate in this initiative : Forum Portal Website.