ABSTRACT The internet-of-things (IoT) consists of embedded devices and their networks of communication as they form decentralized frameworks of ubiquitous computing services. Within such decentralized systems the potential for malicious actors to impact the system is significant, with far-reaching consequences. Hence this work addresses the challenge of providing IoT systems engineers with a framework to elicit privacy and security design considerations, specifically for indoor adaptive smart environments. It introduces a new ambient intelligence indoor adaptive environment framework (CORE) which leverages multiple forms of data, and aims to elicit the privacy and security needs of this representative system. This contributes both a new adaptive IoT framework, but also an approach to systematically derive privacy and security design requirements via a combined and modified OCTAVE-Allegro and Privacy-by-Design methodology. This process also informs the future developments and evaluations of the CORE system, toward engineering more secure and private IoT systems.
CCS CONCEPTS• Human-centered computing → Mixed / augmented reality; Ambient intelligence; Ubiquitous and mobile computing design and evaluation methods; Contextual design; • Security and privacy → Mobile platform security; Distributed systems security; Mobile and wireless security; Domain-specific security and privacy architectures; KEYWORDS Privacy; security; internet-of-things; architectural framework; ambient intelligence ACM Reference Format: