Overview
ISO/IEC 27071:2023 - "Cybersecurity - Security recommendations for establishing trusted connections between devices and services" provides a framework and practical recommendations for building trusted connections that rely on hardware security modules (HSMs). The standard addresses the lifecycle and components needed to ensure device and service authenticity, integrity and mutual trust in environments such as IoT, mobile, cloud services, and edge deployments. Note: ISO/IEC 27071:2023 does not address privacy.
Key topics and technical requirements
The standard organizes recommendations around core components required for trusted connections and contains informative annexes (threats, solutions, examples). Major technical topics include:
- Hardware security module (HSM): guidance for tamper-resistant modules that safeguard keys and provide cryptographic functions.
- Roots of trust (RoT / vRoT / TAM): establishing physical and virtual roots of trust, including roots for measurement, storage and reporting.
- Identity and identity keys (IK): recommendations for issuing and managing device and service identities to prevent forgery.
- Authentication and key establishment: mutual authentication between device and service and secure key establishment to create protected channels (complements protocols like TLS).
- Remote attestation: recommendations for attesting device/service integrity and environment characteristics to detect tampering or unauthorized software.
- Data integrity and authenticity: signing or otherwise protecting sensor and processed data to ensure long-term integrity and provenance.
- Trusted user interface (TUI): protecting UI integrity and authenticity under the control of a trust anchor module.
- Informative content: threat models, practical solutions for components, and an example workflow for establishing a trusted connection.
Practical applications
ISO/IEC 27071:2023 is intended for real-world scenarios where devices and services must prove authenticity and protect data integrity, including:
- Securing IoT device-to-cloud connections and preventing sensor data forgery.
- Hardening mobile devices, PCs, gateways and cloud infrastructures with HSM-based roots of trust.
- Designing mutual authentication and attestation flows in industrial control systems and critical infrastructure.
- Supporting trustworthy telemetry, digital signing of sensor data, and compliance-focused device provisioning.
Who should use this standard
- Device manufacturers and firmware architects
- Cloud service providers and platform engineers
- Security architects, system integrators and solution designers
- HSM vendors, PKI and CA operators
- IoT developers and compliance officers
Related standards
- ISO/IEC 27070 - requirements for establishing virtualized roots of trust (referenced by ISO/IEC 27071).
- Standards and best practices for TLS, PKI and trusted computing technologies are complementary when implementing the recommendations in ISO/IEC 27071:2023.
Keywords: ISO/IEC 27071:2023, trusted connections, hardware security module, HSM, root of trust, remote attestation, identity, authentication, data integrity, IoT security, cloud services.