{"id":2206,"date":"2023-06-01T10:13:00","date_gmt":"2023-06-01T10:13:00","guid":{"rendered":"https:\/\/open.ieec.uned.es\/iot\/?p=2206"},"modified":"2023-07-10T10:23:32","modified_gmt":"2023-07-10T10:23:32","slug":"security-management-on-arduino-based-electronic-devices-2","status":"publish","type":"post","link":"https:\/\/open.ieec.uned.es\/iot\/security-management-on-arduino-based-electronic-devices-2\/","title":{"rendered":"Security management on Arduino-based electronic devices"},"content":{"rendered":"\n<p>Recientemente ha sido publicado nuestro art\u00edculo \u00bb <em>Security management on Arduino-based electronic<\/em> <em>devices<\/em>\u00bb publicado en la revista indexada en JCR (Q1) \u00abIEEE Consumer Electronics Magazine\u00bb.<\/p>\n\n\n\n<p>Aqu\u00ed os dejamos el abstract por si os interesa:<\/p>\n\n\n\n<p><em>Arduino has emerged as a very popular electronic<\/em> <em>board because of its low-cost, open hardware approach and<\/em> <em>flexibility with a huge potential for prototyping, small product<\/em> <em>runs, Internet of Things, makers or educational electronic<\/em> <em>projects, among others. However, there is a literature gap<\/em> <em>concerning wide analysis on different versions and types of<\/em> <em>Arduino boards, which include software, hardware and<\/em> <em>communication vulnerabilities analysis. This work analyzes the<\/em> <em>software, hardware and communication vulnerabilities that can<\/em> <em>be found in different versions of Arduino boards (entry level,<\/em> <em>enhanced features, Internet of Things-oriented, non-official and<\/em> <em>with Operating System). The results of the analysis show that, in<\/em> <em>most cases, Arduino boards present hardware and software<\/em> <em>limitations and security vulnerabilities, probably due to their<\/em> <em>low-cost requirement design. Some examples are: an easy-to override<\/em> <em>firmware, lack of power protection or non-encrypted<\/em> <em>board communications in the case of Arduino Yun. Also Arduino<\/em> <em>does not check bad use of memory stack, so bad memory<\/em> <em>operations may end up easily on memory corruption and<\/em> <em>unexpected behavior. <\/em><\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" src=\"https:\/\/open.ieec.uned.es\/iot\/wp-content\/uploads\/2023\/07\/image-7-806x1024.png\" alt=\"\" class=\"wp-image-2208\" width=\"465\" height=\"591\" srcset=\"https:\/\/open.ieec.uned.es\/iot\/wp-content\/uploads\/2023\/07\/image-7-806x1024.png 806w, https:\/\/open.ieec.uned.es\/iot\/wp-content\/uploads\/2023\/07\/image-7-236x300.png 236w, https:\/\/open.ieec.uned.es\/iot\/wp-content\/uploads\/2023\/07\/image-7-768x976.png 768w, https:\/\/open.ieec.uned.es\/iot\/wp-content\/uploads\/2023\/07\/image-7.png 996w\" sizes=\"(max-width: 465px) 100vw, 465px\" \/><\/figure>\n\n\n\n<p><em>All these limitations and vulnerabilitie<\/em>s <em>may lead to security breaches on the deployed environment.<\/em> <em>Therefore, any security management policy must take these<\/em> <em>weaknesses into account<\/em> <\/p>\n\n\n\n<p>Aqu\u00ed os dejamos el enlace a la referencia por si quer\u00e9is citarla:<\/p>\n\n\n\n<ul><li>J. Sainz-Raso, S. Martin, G. Diaz, M. Castro. Security management on Arduino-based electronic devices. IEEE Consumer Electronics Magazine, May 2023, vol. 12, issue 3, pp. 72-84-9. Print ISSN: 2162-2248. On-line ISSN: 2162-2256. Digital Object Identifier: 10.1109\/MCE.2022.3184118. IEEE (Institute of Electrical and Electronic Engineers), Print ISSN: 2162-2248. Online ISSN: 2162-2256.<\/li><\/ul>\n\n\n\n<p>Esta investigaci\u00f3n est\u00e1 muy relacionada con otras que llevamos realizando desde hace tiempo, a trav\u00e9s por ejemplo de los art\u00edculos:<\/p>\n\n\n\n<ul><li><em>Sainz-Raso J., Martin, S., Diaz G., and Castro. M. \u201cSecurity<\/em> <em>Vulnerabilities in Raspberry Pi\u2013Analysis of the System Weaknesses,\u201d<\/em> <em>IEEE Consumer Electronics Magazine, vol. 8, no. 6, pp. 47-52, Nov.<\/em> <em>2019<\/em>.<\/li><li><em>S. Martin-Gutierrez, P. Martin, G. Diaz-Orueta, and M. Castro-Gil,<\/em> <em>\u00abVulnerabilities on embeded systems,\u00bb Dyna. Septiembre 2016, pp.<\/em> <em>484-484.<\/em><\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<div class=\"slide-text-bg2\"><span>Recientemente ha sido publicado nuestro art\u00edculo \u00bb Security management on Arduino-based electronic devices\u00bb publicado en la revista indexada en JCR (Q1)<\/span><\/div>\n<div class=\"slide-btn-area-sm\"><a href=\"https:\/\/open.ieec.uned.es\/iot\/security-management-on-arduino-based-electronic-devices-2\/\" class=\"slide-btn-sm\">Read More<\/a><\/div>\n","protected":false},"author":1,"featured_media":2208,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/open.ieec.uned.es\/iot\/wp-json\/wp\/v2\/posts\/2206"}],"collection":[{"href":"https:\/\/open.ieec.uned.es\/iot\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/open.ieec.uned.es\/iot\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/open.ieec.uned.es\/iot\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/open.ieec.uned.es\/iot\/wp-json\/wp\/v2\/comments?post=2206"}],"version-history":[{"count":1,"href":"https:\/\/open.ieec.uned.es\/iot\/wp-json\/wp\/v2\/posts\/2206\/revisions"}],"predecessor-version":[{"id":2209,"href":"https:\/\/open.ieec.uned.es\/iot\/wp-json\/wp\/v2\/posts\/2206\/revisions\/2209"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/open.ieec.uned.es\/iot\/wp-json\/wp\/v2\/media\/2208"}],"wp:attachment":[{"href":"https:\/\/open.ieec.uned.es\/iot\/wp-json\/wp\/v2\/media?parent=2206"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/open.ieec.uned.es\/iot\/wp-json\/wp\/v2\/categories?post=2206"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/open.ieec.uned.es\/iot\/wp-json\/wp\/v2\/tags?post=2206"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}