The specific characteristics of AmI ecosystems make it almost impossible to adapt and to apply the existing security and dependability solutions.
The concepts of system and application as we know them today will disappear. Static architectures with well-defined pieces of hardware, software, communication links, limits and owners will be replaced by architectures that will be sensitive, adaptive, context-aware and responsive to users' needs and habits : AmI environments. AmI systems will contain a large number of heterogeneous computing, communication infrastructures and devices. Moreover, not only systems but also applications will have to make effective use of the resources available on-the-fly, and adapt to different hardware and software, and even firmware configurations.
Security and dependability challenges will arise from complexity, ubiquity and autonomy of computing and communications as well as from the need for resilience, self-healing, mobility, dynamic content and volatile environments. In addition, the advent of new societal applications will lead to new policy challenges in areas such as the protection of citizens against cyber threats, privacy, identification and authentication for service access, interoperable content and digital rights management, for which strategic and solid research on security and trust is required.
| Requirements today |
Requirements tomorrow |
- Security & Dependability only at application level
- security and dependability considered as the last issue
- security and dependability faced, mainly, from a technological point of view
- security and dependability "applied to relatively stable, well-defined, consistent configurations, contexts and participants to security arrangements"
|
- "conformable security"
- Social, political, ethical, technological aspects to be considered
- Heterogeneity, mobility, size, complexity, ...
- Distribution of knowledge
- data protection w.r.t. the operative context (privacy, anonymity, etc.)
- Communication infrastructures and hardware devices not under the control of the security engineers
|