애스크로AIPublic Preview
← 학술논문 검색
학술논문한국IT서비스학회지2016.12 발행KCI 피인용 7

사물인터넷(IoT) 환경에서의 개인정보 위험 분석 프레임워크

Risk Analysis for Protecting Personal Information in IoT Environments

이애리(연세대학교 바른ICT연구소); 김범수(연세대학교); 장재영(한국인터넷진흥원)

15권 4호, 41~62쪽

초록

In Internet of Things (IoT) era, more diverse types of information are collected and the environment of information usage, distribution, and processing is changing. Recently, there have been a growing number of cases involving breach and infringement of personal information in IoT services, for examples, including data breach incidents of Web cam service or drone and hacking cases of smart connected car or individual monitoring service. With the evolution of IoT, concerns on personal information protection has become a crucial issue and thus the risk analysis and management method of personal information should be systematically prepared. This study shows risk factors in IoT regarding possible breach of personal information and infringement of privacy. We propose “a risk analysis framework of protecting personal information in IoT environments” consisting of asset (personal information-type and sensitivity) subject to risk, threats of infringement (device, network, and server points), and social impact caused from the privacy incident. To verify this proposed framework, we conducted risk analysis of IoT services (smart communication device, connected car, smart healthcare, smart home, and smart infra) using this framework. Based on the analysis results, we identified the level of risk to personal information in IoT services and suggested measures to protect personal information and appropriately use it.

Abstract

In Internet of Things (IoT) era, more diverse types of information are collected and the environment of information usage, distribution, and processing is changing. Recently, there have been a growing number of cases involving breach and infringement of personal information in IoT services, for examples, including data breach incidents of Web cam service or drone and hacking cases of smart connected car or individual monitoring service. With the evolution of IoT, concerns on personal information protection has become a crucial issue and thus the risk analysis and management method of personal information should be systematically prepared. This study shows risk factors in IoT regarding possible breach of personal information and infringement of privacy. We propose “a risk analysis framework of protecting personal information in IoT environments” consisting of asset (personal information-type and sensitivity) subject to risk, threats of infringement (device, network, and server points), and social impact caused from the privacy incident. To verify this proposed framework, we conducted risk analysis of IoT services (smart communication device, connected car, smart healthcare, smart home, and smart infra) using this framework. Based on the analysis results, we identified the level of risk to personal information in IoT services and suggested measures to protect personal information and appropriately use it.

발행기관:
한국IT서비스학회
DOI:
http://dx.doi.org/10.9716/KITS.2016.15.4.041
분류:
경영과학

AI 법률 상담

이 논문의 주제에 대해 더 알고 싶으신가요?

460만+ 법률 자료에서 관련 판례·법령·해석례를 찾아 답변합니다

AI 상담 시작
사물인터넷(IoT) 환경에서의 개인정보 위험 분석 프레임워크 | 한국IT서비스학회지 2016 | AskLaw | 애스크로 AI