Institute of Operating Systems and Computer Networks Platzhalter für Bild, Bild auf Titelfolie hinter das Logo einsetzen The G GAL Mon onitori oring g Con oncep cept for Di for Dist stri ribu buted ed AAL Pla Platforms forms Felix Büsching, Maximiliano Bottazzi, Lars Wolf
7540 km 754 km Bra Brauns unschweig ig Be Beij ijing ing F. Büsching, M. Bottazzi, L. Wolf | Monitoring Concept for Distributed AAL Platforms 2 / 16 Institute of Operating Systems and Computer Networks
What hat are are we we deali aling wi with th in G German rmany? y? 2005 2050 1910 F. Büsching, M. Bottazzi, L. Wolf | Monitoring Concept for Distributed AAL Platforms 3 / 16 Institute of Operating Systems and Computer Networks
What hat the the he hell ll is is GAL? AL? German Project “GAL” G estaltung A ltergerechter L ebenswelten “Design of Environments for Aging” Research project Funded by the state of Lower Saxony Interdisciplinary approach F. Büsching, M. Bottazzi, L. Wolf | Monitoring Concept for Distributed AAL Platforms 5 / 16 Institute of Operating Systems and Computer Networks
Use Ca se Cases ses / S / Scen cenarios Exem xemplar ary y Assi ssist sting Syst ystem ems 1. Personal activity and household assistant 2. Monitoring of sports activities in prevention and rehabilitation 3. Sensor-based activity determination 4. Sensor-based fall prevention and fall recognition All running on the same platform @ho @home e of of an an el elder erly y perso son F. Büsching, M. Bottazzi, L. Wolf | Monitoring Concept for Distributed AAL Platforms 6 / 16 Institute of Operating Systems and Computer Networks
Multi lti-Servi rvices Home Home Platform latform – Middle leware ware an and Gate ateway way Ultrasonic Power Microphones Cameras White Goods Sensors Sensor I²C USB FireWire PowerLine Ethernet GAL-Middleware Platform Multi Services Home Platform PSTN, GSM, KNX, EIB, IEEE802.15.4 ISDN LON Body Area Home Notification / User Internet Network Automation Alarm Interfaces F. Büsching, M. Bottazzi, L. Wolf | Monitoring Concept for Distributed AAL Platforms 7 / 16 Institute of Operating Systems and Computer Networks
Moti otivati vation on: Go Going ing out utsi side! de! 0 1 2 9 5 8 4 7 6 3 F. Büsching, M. Bottazzi, L. Wolf | Monitoring Concept for Distributed AAL Platforms 8 / 16 Institute of Operating Systems and Computer Networks
Remote mote Bac ackup & & Mon onitori toring: Ci Circum cumst stances ces 3 2 4 1 Internet F. Büsching, M. Bottazzi, L. Wolf | Monitoring Concept for Distributed AAL Platforms 9 / 16 Institute of Operating Systems and Computer Networks
Fiel eld S d Study udy – Cond ndit itio ions ns & & As Assump mpti tion ons 3 2 4 1 Internet Scattered MSHP-Systems Connection to the internet Various physical layers (Modem, ISDN, xDSL, GSM, 3G, 4G…) Various (asymmetric) connection speeds (56 kbit/s >100 Mbit/s) Firewalls, NAT No access to intermediate systems (routers, provider networks, ...) F. Büsching, M. Bottazzi, L. Wolf | Monitoring Concept for Distributed AAL Platforms 10 / 16 Institute of Operating Systems and Computer Networks
Conne nnectio ion Spe n Speed VNC (load) 50 40 Bandwidth (Kbyte/s) 30 20 10 SSH (load) 0 F. Büsching, M. Bottazzi, L. Wolf | Monitoring Concept for Distributed AAL Platforms 11 / 16 Institute of Operating Systems and Computer Networks
Fiel eld S d Study udy – Cond ndit itio ions ns & & As Assump mpti tion ons 3 2 4 1 Internet Scattered MSHP-Systems Connection to the internet Various physical layers (Modem, ISDN, xDSL, GSM, 3G, 4G…) Various (asymmetric) connection speeds (56 kbit/s >100 Mbit/s) Firewalls, NAT No access to intermediate systems (routers, provider networks, ...) F. Büsching, M. Bottazzi, L. Wolf | Monitoring Concept for Distributed AAL Platforms 12 / 16 Institute of Operating Systems and Computer Networks
GAL P AL Pri rivac vacy y an and S Securi rity ty Parad aradigm “Ever very bi y bit of recorded and processed data st stays ays at at a persons ho home on their own MSHP(-System)” All processing is done “at home” – no online-service/cloud/server involved Only high level alarms leave the platform No transmission of low-level data User may initiate transfer No way in (from the outside) … in contradiction to Remote Monitoring Remote Configuration Remote Backup & Restore F. Büsching, M. Bottazzi, L. Wolf | Monitoring Concept for Distributed AAL Platforms 13 / 16 Institute of Operating Systems and Computer Networks
VPN: M VPN: Mea eans s of Choi hoice VPN Concentrator at central place MSHPs establish connection to VPN concentrator Initiated from each MSHP TUN-Interface is the only usable Interface MSHPs not reachable from “the Internet” MSHPs Monitoring VPN- 1 Instance Concentrator Internet n F. Büsching, M. Bottazzi, L. Wolf | Monitoring Concept for Distributed AAL Platforms 14 / 16 Institute of Operating Systems and Computer Networks
Ap Appli licati ation on Laye Layer r VPN: Open enVPN VPN Open Source Layer 5 – no problem for Transport Layer Security (TLS) Intermediate Systems Little Overhead NAT Firewalls MSHP Intermediate Concentrator Systems Virtual Interface (IP Router) Application 5: Application OpenVPN OpenVPN 4: Transport TCP/UDP TCP/UDP TCP 3: Network IP IP IP IP 2: Data Link 2: Data Link Ethernet Ethernet Ethernet 1: Physical 1: Physical F. Büsching, M. Bottazzi, L. Wolf | Monitoring Concept for Distributed AAL Platforms 15 / 16 Institute of Operating Systems and Computer Networks
Imp mple leme mentati tation on Pre-install MHSPs Settings C-A concentrator address A-C C-B Certificates Pairs of keys for every system B-C Just… … carry the preconfigured system to end user! … plug it in (existing Internet connection) -> System is capable of being monitored F. Büsching, M. Bottazzi, L. Wolf | Monitoring Concept for Distributed AAL Platforms 16 / 16 Institute of Operating Systems and Computer Networks
Curre rrent t statu tatus & & Futu ture re W Work ork Automated setup of MSHP systems VPN concentrator up and running Basic monitoring by heartbeat ping Remote configuration by SSH access Web interface for detailed monitoring and remote configuration Encrypted remote backup and restore Just about to deploy the systems! F. Büsching, M. Bottazzi, L. Wolf | Monitoring Concept for Distributed AAL Platforms 17 / 16 Institute of Operating Systems and Computer Networks
Summary an mmary and C Con onclu lusion on Privacy and Security have to be addressed in AAL Platforms Storing & processing the data in p place may be an option! Remote Monitoring of AAL Platforms is needed At least if deployed in rural areas Application Layer VPN (e.g. OpenVPN)… Secures Monitoring Traffic Even unsecure SNMP v1/2 is utilizable Deals with Firewalls, NAT, IS Solves some privacy & security issues If connection is initiated by remote AAL system Thanks for the attention! buesching@ibr.cs.tu-bs.de F. Büsching, M. Bottazzi, L. Wolf | Monitoring Concept for Distributed AAL Platforms 18 / 16 Institute of Operating Systems and Computer Networks
Recommend
More recommend