Hi Stefano, There are a number of possibilities to mitigate this: - Introduce a virtual private network on the devices - Introduce a specific gate or proxy where the requests are tunneled and subsequent authorization is enforced - Introduce a web service, where a device would register it's IP and subsequently get access to the infrastructure - Expose only the relevant set of GEs to the general public (only possible, if the GE providers do agree) - Introduce proper client authorization - Implement proper authorization patterns on all of the GEs - Perhaps even leverage I2ND technologies to have special network setups?! Furthermore we need to understand to how many devices this would apply, what GEs they want to access, how long the tests would last and in general how large the PoC would be. Best, /Thorsten From: fiware-testbed-bounces at lists.fi-ware.eu [mailto:fiware-testbed-bounces at lists.fi-ware.eu] On Behalf Of stefano de panfilis Sent: Dienstag, 4. September 2012 19:34 To: HENAR MUÑOZ FRUTOS Cc: Juanjo Hierro; fiware-testbed at lists.fi-ware.eu Subject: [Fiware-testbed] Fwd: Test bed access problem during the PoC dear henar, i think we should take this issue quite seriously. any idea? ciao, stefano ---------- Forwarded message ---------- From: Peretz Gurel <peretz at athenaiss.com<mailto:peretz at athenaiss.com>> Date: 2012/9/4 Subject: Test bed access problem during the PoC To: Juanjo Hierro <jhierro at tid.es<mailto:jhierro at tid.es>>, "stefano de panfilis (stefano.depanfilis at eng.it<mailto:stefano.depanfilis at eng.it>)" <stefano.depanfilis at eng.it<mailto:stefano.depanfilis at eng.it>> Cc: "Gavazzi Roberto (roberto.gavazzi at telecomitalia.it<mailto:roberto.gavazzi at telecomitalia.it>)" <roberto.gavazzi at telecomitalia.it<mailto:roberto.gavazzi at telecomitalia.it>> Dear Stefano and Juanjo, There is an additional aspect to the FIWARE security measure that is based on the IP address of the computer trying to access the test bed. Please see the attached short PPT (2 slides) that describes the problem. This is potentially a real problem for SafeCity. In the PoC in Stockholm we plan to use 3G connectivity to the internet and to the FIWARE test bed. We shall not know in advance the IP addresses of our servers in the PoC area. 1. How you propose to solve this issue? 2. We shall do some testing in the PoC site in Stockholm already on Sep 18. Can this issue be solved by that date? Best regards, Peretz Gurel European Projects Manager Athena security implementations Ltd Office: +972-3-5572548<tel:%2B972-3-5572548> Mobile: +972-54-4734045<tel:%2B972-54-4734045> Email: peretz at athenaiss.com<mailto:peretz at athenaiss.com> www.athenaiss.com<http://www.athenaiss.com> From: Peretz Gurel Sent: Tuesday, September 04, 2012 1:05 PM To: 'Juanjo Hierro'; stefano de panfilis (stefano.depanfilis at eng.it<mailto:stefano.depanfilis at eng.it>) Cc: Gavazzi Roberto (roberto.gavazzi at telecomitalia.it<mailto:roberto.gavazzi at telecomitalia.it>) Subject: Smartphones access to the FIWARE test bed Dear Stefano and Juanjo, An action Point from the last AB meeting is: " Peretz: There is an issue reported regarding access to the FI-WARE Testbed servers from smartphone. Juanjo: we need to understand the scenario to check what is the best solution, but be sure we will find one. AP- Safecity to send to Juanjo and Stefano a description of the scenario where direct access to VMs in the FI-WARE Testbed is required." Please see the attached short PPT that explains SafeCity requirement for a direct access from smartphones to the FIWARE test bed. Best regards, Peretz Gurel European Projects Manager Athena security implementations Ltd Office: +972-3-5572548<tel:%2B972-3-5572548> Mobile: +972-54-4734045<tel:%2B972-54-4734045> Email: peretz at athenaiss.com<mailto:peretz at athenaiss.com> www.athenaiss.com<http://www.athenaiss.com> -- Stefano De Panfilis Chief Innovation Officer Engineering Ingegneria Informatica S.p.A. via Riccardo Morandi 32 00148 Roma Italy tel (direct): +39-068307-4295 tel (secr.): +39-068307-4513 fax: +39-068307-4200 cell: +39-335-7542-567 -------------- next part -------------- An HTML attachment was scrubbed... URL: <https://lists.fiware.org/private/old-fiware-testbed/attachments/20120905/db817ce8/attachment.html>
You can get more information about our cookies and privacy policies clicking on the following links: Privacy policy Cookies policy