scieee Science in your language
[en] (orig)

An SDN-based architecture for security provisioning in Fog-to-Cloud (F2C) computing systems

Abstract

The unstoppable adoption of cloud and fog computing is paving the way to developing innovative services, some requiring features not yet covered by either fog or cloud computing. Simultaneously, nowadays technology evolution is easing the monitoring of any kind of infrastructure, be it large or small, private or public, static or dynamic. The fog-to-cloud computing (F2C) paradigm recently came up to support foreseen and unforeseen services demands while simultaneously benefiting from the smart capacities of the edge devices. Inherited from cloud and fog computing, a challenging aspect in F2C is security provisioning. Unfortunately, security strategies employed by cloud computing require computation power not supported by devices at the edge of the network, whereas security strategies in fog are yet on their infancy. Put this way, in this paper we propose Software Defined Network (SDN)-based security management architecture based on a master/slave strategy. The proposed architecture is conceptually applied to a critical infrastructure (CI) scenario, thus analyzing the benefits F2C may bring for security provisioning in CIs.

Read accessible full text

An SDN-based architecture for security provisioning in Fog-to-Cloud (F2C) computing systems

Author: Kahvazadeh, Sarang,Souza, Vitor Barbosa,Masip Bruin, Xavier,Marín Tordera, Eva,García Almiñana, Jordi,Diaz, Rodrigo
Publisher: The Science and Information (SAI) Organization
Year: 2017
Source: https://upcommons.upc.edu/bitstream/2117/121356/1/A%20SDN....pdf
Fu u e Technologies Con e ence (FTC) 2017
29-30 No embe 2017 | Vancou e , Canada
732 | P a g e
An SDN-based A chi ec u e o Secu i y P o isioning
in Fog- o-Cloud (F2C) Compu ing Sys ems
Sa ang Kah azadeh*, Vi o B. Souza§*, Xa i Masip-B uin*, E a Ma ín-To de a*, Jo di Ga cia*, Rod igo Diaz‡
*Ad anced Ne wo k A chi ec u es Lab (CRAAX), Uni e si a Poli ècnica de Ca alunya (UPC), Spain
{skah aza, ba bosa, xmasip, e a, jo dig}@ac.upc.edu
§ In o ma ics Depa men (DPI), Uni e sidade Fede al de Viçosa (UFV), B azil ‡ Cybe secu i y Lab, A os Spain
od igo.d[email p o ec ed]
Abs ac —The uns oppable adop ion o cloud and og
compu ing is pa ing he way o de eloping inno a i e se ices,
some equi ing ea u es no ye co e ed by ei he og o cloud
compu ing. Simul aneously, nowadays echnology e olu ion is
easing he moni o ing o any kind o in as uc u e, be i la ge o
small, p i a e o public, s a ic o dynamic. The og- o-cloud
compu ing (F2C) pa adigm ecen ly came up o suppo o eseen
and un o eseen se ices demands while simul aneously bene i ing
om he sma capaci ies o he edge de ices. Inhe i ed om
cloud and og compu ing, a challenging aspec in F2C is secu i y
p o isioning. Un o una ely, secu i y s a egies employed by
cloud compu ing equi e compu a ion powe no suppo ed by
de ices a he edge o he ne wo k, whe eas secu i y s a egies in
og a e ye on hei in ancy. Pu his way, in his pape we
p opose So wa e De ined Ne wo k (SDN)-based secu i y
managemen a chi ec u e based on a mas e /sla e s a egy. The
p oposed a chi ec u e is concep ually applied o a c i ical
in as uc u e (CI) scena io, hus analyzing he bene i s F2C may
b ing o secu i y p o isioning in CIs.
Keywo ds—IoT; cloud compu ing; og compu ing; og- o-cloud
compu ing; secu i y; So wa e De ined Ne wo k (SDN); c i ical
in as uc u es
I. INTRODUCTION AND MOTIVATION
Nowadays, he ope a ion be ween people and machines is
being signi ican ly empowe ed h ough bo h inno a i e
communica ion pa adigms and new sma de ices, such as
sma phones, able s o wea ables, jus o name a ew. The
g ow h o de ices connec i i y pa ed he way o coin he e m
In e ne o Things (IoT), s anding o ― hings‖ communica ing
anywhe e, a any ime, and o anyone – a ― hing‖ in IoT e e s
o any ype o connec ed de ice. The explosion o IoT and, in
pa icula , he apid g ow h o connec ed use s h ough a la ge
a ie y o he e ogeneous de ices, ueled he deploymen o
new applica ions wi h s ic demands in se e al key aspec s,
such as secu i y, compu ing powe o s o age. In o de o ace
ha se o demands, cloud compu ing eme ged as an on-
demand sel -se ice, scalable, loca ion independen , pay-as-
you-go online compu ing model, enabling he use o emo e
physical compu ing esou ces loca ed a a da a cen e s [1],
[2]. The ou sou cing o da a and se ices p ocessing up o he
cloud, b ings no only economic bene i s bu also ees use s o
ge conce ned on ela ed echnical aspec s.
Howe e , handling ha olume and a ie y o da a, while
simul aneously p o iding he eloci y demanded by IoT
applica ions, equi es a new compu ing pa adigm ha can
gua an ee low-la ency, as well as inc eased secu i y and
ene gy-e iciency, among o he s. The og compu ing pa adigm
[3] has been ecen ly p oposed as an ex ension o cloud
compu ing, le e aging a highly dis ibu ed se o esou ces
loca ed a he edge o he ne wo k, b inging compu ing, s o age
and ne wo k capabili ies close o he end-use s, wha
unques ionably acili a es o p o ide cha ac e is ics, such as
low-la ency, loca ion awa eness, geo-dis ibu ion, inc eased
da a secu i y and eal- ime p ocessing. Pu his way, in IoT
scena ios, cloud makes cen aliza ion while og makes
localiza ion.
Le e aging cloud and og bene i s, og- o-cloud compu ing
(F2C) has been ecen ly p oposed [4], as a new compu ing
pa adigm p oposing an inno a i e hie a chical and dis ibu ed
a chi ec u e. In he p oposed dis ibu ed a chi ec u e, use s’
de ices (i.e., edge de ices) may collec da a o be la e
p ocessed in an ei he sequen ial o pa allel ashion a og,
cloud o bo h, ueling he c ea ion o a la ge se o new
se ices. The F2C compu ing model is in ended o join ly
manage cloud and og esou ces in a coo dina ed way,
demanding o a no el con ol and managemen s a egy,
add essing some o he limi a ions inhe en o cloud and og
compu ing. Many challenges a e ye unsol ed in he F2C
compu ing model, om coo dina ed esou ces managemen a
cloud and og o he challenges imposed when acing secu i y
p o isioning. This pape ocuses on he secu i y aspec s o
F2C, p oposing a no el SDN-based secu i y a chi ec u e ha is
concep ually applied o a c i ical in as uc u e (CI) scena io, o
uel discussion on he en isioned bene i s F2C may b ing o
help secu e such a highly demanding scena ios.
I mus be highligh ed ha besides he unsol ed secu i y
issues om he seed cloud and og compu ing models, new
F2C speci ic secu i y challenges come up. Thus, p oposing a
solu ion o F2C undoub edly equi es a s ong backg ound on
secu i y aspec s bo h in he cloud and og scena ios.
On he cloud a ea, he ou sou cing o se ice p ocessing
exposes well-known secu i y aspec s equi ing wide a en ion.
Fo example, he dis ance be ween he end use and he cloud
esou ces is no only adding long delays, bu also impac ing on
he o e all secu i y. On he o he hand, al hough heo e ically
og should b ing mo e p i acy — as a consequence o i s
p oximi y o end-use s — i s dis ibu ed na u e makes og
compu ing o ace no only secu i y challenges inhe i ed om
cloud (shi ed om cloud o he edge), bu some o he inhe en
Fu u e Technologies Con e ence (FTC) 2017
29-30 No embe 2017 | Vancou e , Canada
733 | P a g e
o og compu ing. Fi s , og compu ing b ings i ualiza ion
close o he use s, hus og compu ing mus also deal wi h
secu i y issues ela ed o he i ualiza ion en i onmen as i
usually happens in cloud compu ing. Second, ecognized he
dis ibu ed s a egy adop ed by og compu ing, au hen ica ion
in di e en le els u ns in o one o he main secu i y challenges
in og. Indeed, he ac ha og compu ing shi s some
compu a ional capabili ies, da a analysis, da a agg ega ion, da a
il e ing and s o age o edge de ices, d i es he edge o he
ne wo k o handle p i a e, sensi i e o con iden ial in o ma ion
—such as, pe sonal in o ma ion o c i ical in as uc u es da a.
Thus, secu e communica ions mus be g an ed in o de o
gua an ee da a p i acy a he edge o he ne wo k. Thi d, he e
is a high he e ogenei y in he de ices a he edge—nodes,
se e s, ga eways, access poin s, e c.—, wha makes he design
o an a chi ec u e g an ing secu i y p o isioning a ha d
challenge. Mo eo e , we mus conside ha al hough
adi ional cloud secu i y p o ocols may heo e ically p o ide
some secu i y o og compu ing sys ems, he cons ain s on
p ocessing capaci ies o he edge de ices undoub edly limi he
e iciency o such exis ing p o ocols. On he o he hand,
secu i y ini ia i es designed o og compu ing canno mee he
huge amoun o p ocessing and s o age cloud equi emen s. In
addi ion, he design o secu e ogs and clouds wi h exis ing
secu i y a chi ec u es and p o ocols wi hou conside ing he
coo dina ed na u e o F2C (in e ope abili y, he e ogenei y,
e c.), may cause addi ional secu i y p oblems when conside ing
he whole se o esou ces en isioned in F2C. This is he i s
wo k dealing wi h comple e secu i y a chi ec u e o F2C
compu ing sys ems.
The challenging ques ion is: how can we design a new
secu i y a chi ec u e p o iding secu e communica ion,
con iden iali y, in eg i y, a ailabili y, mu ual og, cloud and
nodes au hen ica ion, and access con ol o F2C? In his pape
we assess ha he highly dis ibu ed F2C na u e can be
p ope ly managed by using a So wa e De ined Ne wo k
(SDN) based s a egy, le e aging a se o dis ibu ed con olle
nodes, h ough a mas e -sla e s a egy.
The pape is s uc u ed as ollows. Sec ion 2 desc ibes he
ela ed wo k, Sec ion 3 desc ibes he new SDN-based secu i y
o F2C, Sec ion 4 p esen s he ob ained esul s, and inally
Sec ion 5 concludes he pape .
II. RELATED WORK
Many ecen wo ks ha e assessed he design o secu i y
p o ocols and a chi ec u es o secu e og compu ing and cloud
compu ing communica ions in an independen ashion.
Ne e heless, none o hem conside ed a coo dina ed secu i y
scheme, as demanded by new compu ing models, such as og-
o-cloud. In his sec ion, we e isi some ele an wo ks on he
secu i y a ea o cloud and og compu ing pa adigms,
somehow ela ed o he speci ic F2C demands. I mus be
highligh ed ha none o he e isi ed wo ks a e designed o be
applied o F2C; hence he li e a u e e iew is in ended o lea n
om pas e o s in ela ed a eas.
In he way, secu ing og and cloud, au ho s in [5] p opose
iden i y-based au hen ica ion o IoT assuming he cen al
da abase, con olle s, ga eways and hings dis ibu ed in a
hie a chical way. Key cha ac e is ics o his p oposal a e:
1) con olle s use an Ellip ic Cu e C yp og aphy (ECC) key
es ablishmen me hod o gene a e keys; 2) ga eways ake hei
ce i ica es om he con olle ; 3) hings a e egis e ed by
ga eways; and 4) hings and ga eways go h ough he
au hen ica ion phase. The p oposed solu ion p o ides a secu e
hie a chical a chi ec u e and p o ocol o og and cloud
communica ion, al hough secu i y o in e og communica ion
is no g an ed. The solu ion p oposed in [6] aims a
gua an eeing secu e end- o-end communica ions in IoT
scena ios. The p esen ed a chi ec u e is spli in o de ice laye ,
og laye (ga eways) and cloud laye , and uses he ull ini ial
ce i ica e-based Da ag am T anspo Laye Secu i y (DTLS)
p o ocol be ween end-use and sma ga eways o
au hen ica ion and au ho iza ion. Unlike he wo k in [5], he
p oposed secu i y a chi ec u e only p o ides a secu e in e og
communica ion wi hou conside ing he secu i y on he
communica ion be ween og and cloud nodes. The wo k in [7]
p oposes a og use / og se e mu ual au hen ica ion. In his
a chi ec u e, og use s s o e a long-li ed mas e sec e key,
which allows hem o oam h ough he ne wo k and mu ually
au hen ica e o any og se e unde cloud se ice p o ide
au ho iza ion. Un o una ely, his wo k p o ides secu i y in og
communica ions wi hou ema king cloud secu i y. In [8], a
ga eway-based og compu ing (mas e /sla e) o wi eless
senso s and ac ua o ne wo ks is p oposed. Simila o he wo k
in [7] his wo k is ocused on og so wi h no oom o be
applied o cloud, no o F2C.
Se e al solu ions al eady ocus on he SDN concep . The
a chi ec u e in [9] includes a de ice laye (con ains senso s o
da a collec ion), communica ion laye (includes SDN ga eways
and ou e s), compu ing laye (con ains a con olle wi h
accoun ing and billing mechanisms) and se ice laye (whe e
IoT se ices a e buil by de elope s and ope a o s h ough
p og amming he SDN con olle s) o he cons uc ion o an
SDN-based a chi ec u e o ho izon al IoT. The p oposed
a chi ec u e aces og communica ions h ough ga eways
wi hou con empla ing cloud in a coo dina ed way. The wo k
in [10] ocuses on an SDN app oach o secu ing IoT
ga eways. The p oposed a chi ec u e includes 3 laye s: 1) Edge
node, unning some se ices a he edge o he ne wo k o
educe he amoun o da a o be ans e ed o he cloud o
analysis, p ocessing, and s o age; 2) SDN con olle ,
suppo ing open- low swi ch; and 3) E2E applica ion, b inging
moni o ing capaci ies o anomaly de ec ion. Al hough, au ho s
only p o ide secu i y o IoT ga eways — wi hou conside ing
cloud secu i y — hey p opose o use a cen alized SDN
con olle wi h no capaci y o handle secu e mobili y issues.
Au ho s in [11] p opose me ging Fog compu ing and so wa e-
de ined ne wo king in o he IoT a chi ec u e. Au ho s a gue
ha he p oposed combined s a egy acili a es a ic con ol,
esou ce managemen , scalabili y, mobili y and eal- ime da a
deli e y. O he challenges add essed by such a combined
s a egy a e: 1) SDN con olle o ches a ion un angle og
o ches a ion issues; 2) og compu ing would sol e scalabili y
issues in SDN; 3) og b ings low-la ency o he whole IoT
a chi ec u e. Howe e , secu i y p o isioning is no discussed in
ha pape .
Fu u e Technologies Con e ence (FTC) 2017
29-30 No embe 2017 | Vancou e , Canada
734 | P a g e
Fig. 1. New SDN-based secu i y a chi ec u e.
Taking in o accoun he no el y o F2C compu ing, his is
he i s pape aimed a designing a solu ion o secu i y
p o isioning in F2C. The p oposed SDN-based solu ion is he
i s con ibu ion speci ically analyzing he cha ac e is ics
imposed by he hie a chical F2C a chi ec u e. Indeed, ou
p oposal sugges s using a F2C con olle (in he cloud) as a
mas e , and dis ibu ed og-con olle s as sub-mas e s, all
e icien ly managed in a coo dina ed ashion. To ha end a
p o ocol mus also be designed de ining how dis inc elemen s
in he a chi ec u e in e ac wi h each o he .
III. THE PROPOSED SDN-BASED SECURITY ARCHITECTURE
The coo dina ed managemen o og and cloud esou ces
en isioned by F2C compu ing exace ba es adi ional cloud
secu i y issues, such as au hen ica ion, communica ions
p i acy among F2C laye s, con iden iali y, o in eg i y, jus o
name a ew. In his sec ion, we in oduce he ounda ions o an
SDN-based secu i y a chi ec u e o F2C compu ing sys ems.
As epo ed in he s a e o he a sec ion, applying SDN o
secu i y p o isioning is no a no el app oach and some exis ing
wo ks al eady bene i om he decoupling concep b ough by
SDN [12]. The s a egy loa ed in he pape le e ages he SDN
concep by p oposing a cen alized F2C con olle in cloud, as
a mas e , and se e al dis ibu ed con olle s co e ing he
di e en ogs. Fig. 1 illus a es he p oposed SDN-based
secu i y a chi ec u e, se ing ou le els, as ollows:
1) F2C con olle (Mas e ): A cen alized mas e
con olle loca ed a cloud, is esponsible o managing,
moni o ing and g an ing a secu e communica ion in he
a chi ec u e. This F2C con olle gi es au ho iza ion o all
componen s in he a chi ec u e o p o ide coo dina ed secu e
managemen and communica ion among hem.
2) Con ol A eas (Sub-mas e 1): We conside a dis ibu ed
secu i y con ol di ided in o dis inc con ol a eas, each one
con aining one Con ol A ea Uni associa ed o one og.
The e o e, each Con ol A ea Uni is esponsible o
implemen ing he equi ed con ol unc ionali ies [13]. They
a e esponsible o he es ablishmen o secu e coo dina ed
managemen and communica ion be ween ogs in di e en
a eas, as well as ogs o cloud, bo h equi ing F2C con olle
au ho iza ion. The sub-mas e 1 con olle s a e dis ibu ed
acco ding o each og loca ion, enabling a mobili y-awa e
a chi ec u e.
3) Clus e -head (Sub-mas e 2): This is an edge de ice
endo sed wi h high capaci y, in e ms o ne wo king,
compu ing, and s o age, i compa ed o o he edge de ices
loca ed in he same a ea. Each selec ed sub-mas e 2 is a
middlewa e be ween nodes (IoT edge de ices) and con ol
a eas on di e en ogs and is able o make da a p ocessing a
he edge o he ne wo k acco ding o i s esou ce capaci y.
4) Nodes (Sla es): Loca ed a he edge o he ne wo k, he
sla e laye is o med by he IoT de ices, which may include
bo h end-use mobile de ices and deployed de ices, such as
ixed senso s.
The di e en a chi ec u al le els mus coo dina ely ope a e
o success ully gua an ee secu i y p o isioning. To ha end, a
o mal handshaking p o ocol mus be de ined, se ing he
o mal p ocedu es o sys ems communica ion. Nex , we
in oduce he main a ionale o he p o ocol pe o mance. In
he p oposed a chi ec u e, con ol a eas (sub-mas e 1) mus
egis e and au hen ica e o F2C con olle in o de o con ol
ogs in di e en a eas. In a simila way, each clus e -head (sub-
mas e 2), posi ioned in dis inc ogs, mus egis e in con ol
a eas, while nodes mus egis e in he clus e -head. In he
egis a ion phase, we assume all con ol-a eas o be egis e ed
a he F2C con olle h ough a long- e m sec e -key, so hey
can con ol he dis ibu ed ogs. Simul aneously, each clus e -
head is also egis e ed in i s co esponding dis ibu ed
con olle . A e he egis a ion phase, each con ol-a ea akes
o e secu i y managemen in he dis ibu ed ogs, hence
educing he usual complexi y when done a cloud. I is wo h
men ioning ha , as illus a ed in Fig. 1 by he dashed line, he
clus e -head may communica e di ec ly wi h he F2C con olle
in some speci ic si ua ions (as desc ibed in he ollowing
pa ag aphs), hus also equi ing he egis a ion o clus e -
heads in he F2C con olle .
A e he egis a ion phase, he communica ion be ween
dis inc componen s o his a chi ec u e may be pe o med
hie a chically, u ning in o h ee dis inc ca ego ies, as
Fu u e Technologies Con e ence (FTC) 2017
29-30 No embe 2017 | Vancou e , Canada
735 | P a g e
in oduced in ou p e ious wo k in [14]. He e, we discuss he
p oposed a chi ec u e in an illus a i e sma ci y scena io in
o de o alida e he dis ibu ed con olle s app oach.
In he sma ci y scena io shown in Fig. 2, we assume a
cen alized F2C con olle loca ed a he cloud owned by he
sma ci y. The F2C con olle is esponsible o managing,
con olling and p o iding a secu e communica ion o all sma
ci y componen s. We assume a global opology including
dis ibu ed con olle s deployed in a a ic ligh , a s o e ( og1),
a gas s a ion, and a bus s a ion. These dis ibu ed con olle s
would au hen ica e and ake au ho iza ion om he F2C
con olle in he egis a ion and ini ializa ion s ep. The e o e,
all con olle s a e able o in e -communica e in o de o p o ide
secu e manageable communica ion o all sma ci y
componen s, deployed in dis inc ogs. Fo he sake o
simplici y, we conside ha in each og, he de ice wi h mo e
capaci y in e ms o ne wo k, s o age and compu ing is he one
selec ed as clus e -head.
In Fig. 2, og 1 is a s o e, whe e og use s’ de ices can be
con olled and au hen ica ed by he co esponding con ol a ea
uni deployed in he s o e. Le ’s suppose a og 1 use wan s o
communica e secu ely wi h a og use in og 4. Indeed, hey
can communica e in a secu e and manageable way h ough he
co esponding s o e con ol a ea uni and bus s a ion con ol-
a ea uni . These dis ibu ed con olle s acili a e og o og
au hen ica ion and communica ion. Hence, assuming ha a
og 1 use in he s o e wan s o ake in o ma ion abou bus
a i als, using ou dis ibu ed con olle s, he use can ge
secu e in o ma ion h ough he co esponding con ol-a ea uni
in he s o e ( his con ol-a ea uni has secu e in e
communica ion wi h bus con ol a ea uni ). In ano he
example, le ’s assume og 2 o be buil upon a se o ca s
mo ing in he same di ec ion (see ed ca s in Fig. 2) and og 3
buil upon ano he se o ca s all mo ing in he same di ec ion,
bu pe pendicula o ca s in og 2 (see g ay ca s in Fig. 2).
Wi hin each o hese ogs, one ca shall be selec ed as a clus e -
head and og 2 and og 3 can communica e in a secu e
manageable way h ough hei espec i e con ol-a ea uni
( a ic-ligh ). Fu he mo e, whe he he co esponding con ol-
a ea uni ( a ic-ligh ) ge s comp omised, a acked o down,
he selec ed clus e -head, o ins ance in og 2, which ob ained
a mas e key o di ec ly communica e o he F2C con olle
du ing he egis a ion s ep, makes use o his con olle o ge a
nea es and sa es con ol-a ea uni (suppose gas s a ion o bus
s a ion con ol-a ea uni ). The e o e, og 2 would be con olled
and managed by one o hem.
Mo eo e , he p oposed a chi ec u e also enables he og
use s in og 4 o be au hen ica ed o he sma ci y cloud
h ough he bus con ol a ea uni wi h less au hen ica ion delay.
Indeed, by deploying dis ibu ed con olle s o ogs
managemen , we dec ease he dis ance be ween ogs and cloud
which can be help ul o achie ing less au hen ica ion delay as
well as highe secu i y by a oiding known a acks, such as man
in he middle. Ano he p i ilege o dis ibu ed con olle s is
secu e mobili y and hando e .
Fig. 2. Sma ci y scena io.
Fo ins ance, assume ha og 2, og 3, og 4 and og 5 a e
on he mo e. Wi h he deploymen o dis ibu ed con olle s,
we a e able o manage secu e mobili y and hando e h ough
con ol a ea uni s in e communica ion.
IV. REVIEWING CRITICAL INFRASTRUCTURES SECURITY
NEEDS
I is widely ecognized and la gely epo ed he ele ance
C i ical In as uc u es (CIs) ha e o he unc ioning o a
socie y. A CI can be de ined as a se o asse s, be i ei he
physical o i ual, playing a i al ole in p o iding coun y’s
needs, o he ex en ha i s incapaci y o des uc ion would
ha e a de as a ing impac on secu i y, economy o public
heal h. The e a e many in as uc u es ha may be ca ego ized
as CI, such as (wi h no aim o be an exclusi e lis ) eme gency
se ices, wa e supply sys ems, ag icul u e and ood,
go e nmen , de ense indus y, in o ma ion echnology and
elecommunica ion, heal hca e, banking sys em, ene gy,
anspo a ion sys em, chemical indus y, pos al se ices,
na ional ai po s o mili a y sys ems. Indeed, b eaking secu i y
ulne abili ies in a CI causes c i ical in o ma ion leaks and
e ible disas e s in no mal coun ies ope a ion.
The e o e a comp ehensi e and exhaus i e iden i ica ion o
he key secu i y equi emen s in c i ical in as uc u es is a
mus o any coun y o se he p ope p ocedu es o secu i y
p o isioning.
Fu u e Technologies Con e ence (FTC) 2017
29-30 No embe 2017 | Vancou e , Canada
736 | P a g e
Fig. 3. De ice-cloud au hen ica ion (Scena io 1).
Fig. 4. End- o-end au hen ica ion (Scena io 2).
In ac , we ca ego ize mos common secu i y equi emen s
in c i ical in as uc u es in o [15]: s ong ne wo k secu i y
managemen , s ong iden i ica ion and au hen ica ion
mechanism, i m secu i y policy, da a con iden iali y, o ensics
analysis, ope a ional echnology (OT) p o ec ion, OT ne wo k
p o ec ion, secu e communica ion channel, cascading a ec
p o ec ion, anomaly beha io de ec ion mechanism, high
ne wo k a ic de ec ion mechanism ( o DoS/DDoS a acks),
secu i y in o ma ion and e en managemen (SIEM),
an imalwa e and an i i uses p o ec ion mechanism, ha dwa e
secu i y, da a p i acy, da a in eg i y, and IT ne wo k
p o ec ion.
F om a secu i y pe spec i e CIs use o sha e a common,
dis ibu ed, coo dina ed scena io, in ended o be an ex emely
secu e amewo k including global policies and solu ions o
gua an ee he equi ed pe o mance. The dis ibu ed policy
de ined in he SDN-based secu i y a chi ec u e p oposed in his
pape seems o be a p ope solu ion o be applied in CI
scena ios. Indeed, he cen alized and dis ibu ed con olle s in
ou a chi ec u e will help CIs: 1) ease componen s
au hen ica ion; 2) ease sys ems au ho iza ion h ough a mas e -
sla e s a egy; and 3) p o ide a coo dina ed managemen
be ween di e en CIs o communica e in a secu e way.
V. PRELIMINARY EXPERIMENTAL RESULTS
This sec ion p esen s p elimina y a chi ec u e e alua ions
aiming a alida ing he bene i s o he p oposed SDN-based
a chi ec u e o secu i y p o isioning. To ha end, we pu he
ocus on analyzing he delay equi ed o au hen ica ion
pu poses, conside ing a adi ional s a egy based on cloud
au hen ica ion and ano he one in e ed om he p oposed
SDN-based secu i y a chi ec u e. Two scena ios a e analyzed,
one demanding og-cloud au hen ica ion and he o he one
demanding og- og (end- o-end) au hen ica ion.
Scena io 1. Fog-cloud au hen ica ion: Le us assume a
empe a u e-senso ) in a nuclea powe s a ion wan s o
au hen ica e wi h he nuclea powe cloud o communica ion.
Two dis inc app oaches may be deployed, as illus a ed in
Fig. 3. A adi ional cloud au hen ica ion scheme is shown in
ed-lines whils ou p oposal is shown in b own-lines.
The adi ional au hen ica ion p ocedu e pe o ms as
ollows:
 S ep 1: Fog node ( empe a u e-senso ) exchange
au hen ica ion messages wi h cloud (nuclea -powe
cloud).
 S ep 2: Tempe a u e senso and nuclea powe
da acen e a e au hen ica ed.
On he o he hand, he p oposed au hen ica ion p ocedu e
pe o ms as ollows:
 S ep 1*: Tempe a u e-senso exchange au hen ica ion
messages wi h he Con ol-A ea uni is linked o. As
Con ol-A ea uni s ake pe mission om he F2C
con olle o con ol dis ibu ed Fogs du ing egis a ion
phase, he con olle can do au hen ica ion o Fogs wi h
hei p imi i e F2C con olle au ho iza ion.
 S ep 2*: Nuclea powe cloud and empe a u e-senso
a e au hen ica ed o communica ion. The senso
ecei es acknowledgmen om cloud.
Scena io 2. End- o-end au hen ica ion: Fo a scena io
equi ing end- o-end au hen ica ion, such as a powe sys em
willing o es ablish a secu e communica ion wi h a hospi al, we
illus a e in Fig. 4 he adi ional au hen ica ion in ed-line and
he p oposed au hen ica ion scheme in b own-line.
The adi ional end- o-end au hen ica ion p ocedu e
pe o ms as ollows:
 S ep 1: Fog 1 (Powe sys em) exchange au hen ica ion
messages wi h he cloud aiming a se ing secu e
communica ion wi h Fog N (Hospi al).
 S ep 2: Fog N au hen ica e om cloud o ha e
communica ion wi h Fog 1.
 S ep 3: Powe sys em and hospi al may es ablish secu e
communica ion a e au hen ica ion.
The p oposed end- o-end au hen ica ion p ocedu e
pe o ms as ollows:

Fu u e Technologies Con e ence (FTC) 2017
29-30 No embe 2017 | Vancou e , Canada
737 | P a g e
 S ep 1*: Powe sys em exchange au hen ica ion
messages wi h i s Con ol-A ea uni in o de o es ablish
secu e communica ion wi h he hospi al.
 S ep 2*: Hospi al au hen ica e om i s Con ol-A ea
uni o es ablish secu e communica ion wi h he powe
sys em. Is i wo h men ioning ha , as in Scena io 1, all
Con ol-A ea uni s a e al eady egis e ed in F2C
con olle , he e o e, dis ibu ed con olle s has
pe mission o au hen ica e Fogs wi h no need o each
ou o he cloud.
 S ep 3*: Powe sys em and hospi al may se a secu e
communica ion a e au hen ica ion.
In bo h scena ios, he deploymen o he p oposed s a egy
o au hen ica ion le e ages he low delay au hen ica ion
p o ided by he dis ibu ed con olle s loca ed close o he end-
use s. Indeed, Table 1 shows ha he au hen ica ion ime in og
nodes a e signi ican ly lowe han he au hen ica ion in cloud
when using adi ional schemes, such as he SSL
Au hen ica ion P o ocol (SAP). The es ima ed delays o bo h
og and cloud au hen ica ion we e based on wo ks in he
li e a u e, such as [16], [17]. Consequen ly, Table 2 shows he
es ima ed delays o he wo scena ios analyzed, clea ly
highligh ing he bene i s in e ms o educed delay when
applying he SDN-based secu i y a chi ec u e.
F om he ob ained esul s we may in e he e ec s he
p oposed a chi ec u e may ha e in pa icula CI scena ios.
Recognized he signi icance au hen ica ion has in CI scena ios,
we may s a e ha acco ding o ou e alua ion, he educed
delay o bo h og and cloud au hen ica ion b ough by ou
a chi ec u e will be ex emely bene icial in CI scena ios. Le us
conside wo well-known CI scena ios, such as a hospi al
(eHeal h sec o ) and a ain p o ide ( anspo sec o ). In bo h
scena ios low delay au hen ica ion is key o gua an ee he eal
ime pe o mance, manda o y in bo h domains. Fo ins ance, le
us assume a pa ien needs o communica e p i a ely wi h
his/he doc o . Acco ding o he solu ion p oposed in his
pape , he au hen ica ion phase would be execu ed a bo h he
dis ibu ed con olle s ( ogs) and he cen alized con olle
(cloud), hus wi h a s ong impac on delay educ ion. Mo ing
o he anspo scena io, a ain mus communica e wi h
se e al s a ions o check a ic and in e locking sys ems o
a oid acciden s. This equi es mu ual ain and s a ions
au hen ica ion wi h e y low delay o gua an ee a as eac ion,
hus p e en ing undesi ed disas e s o come. The SDN-based
secu i y a chi ec u e p oposed in his pape le e aging he
deploymen o dis ibu ed con olle s, would undoub edly help
dec ease he au hen ica ion delay, hus con ibu ing o a mo e
secu e pe o mance.
I is also wo h no icing ha he p oposed secu i y
a chi ec u e would no impac only on indi idual CI scena ios
bu also on he communica ion among hem. Indeed, CIs a e
usually dependen each o he , so secu e communica ion among
hem is a mus . Fo example, hospi al in as uc u e is s ongly
dependen on he powe p o ide , same o a ain company, o
a mili a y sys em wi h he eme gency con ol sys em. To make
dependencies eliable and e icien , a secu e communica ions
s a egy mus be deployed among hem.
TABLE I. AUTHENTICATION DELAY COMPARISON IN FOG AND CLOUD
Loca ion
La ency
Fog au hen ica ion
~ 300 ms
Cloud au hen ica ion
~ 1000 ms
TABLE II. AUTHENTICATION DELAY COMPARISON IN THE TWO
SCENARIOS ANALYZED
Scena io
La ency
Cloud s a egy
SDN-based s a egy
Fog-cloud au hen ica ion
~ 1000 ms
~ 300 ms
end- o-end au hen ica ion
~ 2000 ms
~ 600 ms
In his sec ion he p oposed a chi ec u e has been
p elimina y alida ed in e ms o delay. Howe e , beyond he
bene i s in oduced in esponse ime, we en ision many o he
ad an ages, pa icula ly e e ing o a c i ical ask, such as he
complexi y b ough by managing huge cen alized da abases
loca ed a cloud. Assuming an IoT scena io whe e housands o
he e ogeneous de ices a e e e asking o communica ion,
keeping s ong secu i y gua an ees equi es a huge da abase o
be managed. The p oposed dis ibu ed a chi ec u e elie es he
complexi y o e head in oduced by such a managemen ,
h ough he deploymen o local da abases a og p emises.
VI. CONCLUSIONS
Dis inc ne wo k pa adigms such as Cloud compu ing, og
compu ing and, in special, he ecen ly p oposed combined
og- o-cloud (F2C) compu ing a e imposing new secu i y
challenges in dis inc aspec s. This pape add esses secu i y
aspec s in F2C compu ing by illus a ing, in e ms o
au hen ica ion delay, how isola ed og and cloud secu i y
solu ions a e no su icien o gua an ee he deploymen o a
us able F2C coo dina ed managemen solu ion. In o de o
con ibu e o ha p oblem, we in oduce an SDN-based
secu i y a chi ec u e suppo ed by mas e /sla e s a egies
augmen ed by deploying a se o well-de ined dis ibu ed
con olle s. The pape a gues ha h ough he deploymen o
his s a egy, we can dec ease he au hen ica ion delay in bo h
og and cloud communica ions. Finally, we conclude assessing
ha he e a e s ill many challenges o so ou , hus s ong
e o s mus be alloca ed by he scien i ic communi y o
p o ide a solu ion add essing he speci ic equi emen s b ough
by he en isioned F2C scena io.
ACKNOWLEDGMENT
This wo k is suppo ed by he H2020 CIPSEC p ojec
(700378). Fo UPC au ho s by he Spanish Minis y o
Economy and Compe i i eness and by he Eu opean Regional
De elopmen Fund unde con ac TEC2015-66220-R
(MINECO/FEDER), and o V. Ba bosa by CAPES
Founda ion, no 11888/13-0.
REFERENCES
[1] J.Gonzalez-Ma ínez, e al., Cloud compu ing and educa ion: A s a e-o -
he-a su ey, Compu e s & Educa ion 80 (2015) 132-151, 2014.
[2] S.Singh, Y. Jeong, J. H. Pa k, A su ey on cloud compu ing secu i y:
Issues, h ea s, and solu ions, Jou nal o Ne wo k and Compu e
Applica ions 75 (2016) 200–222, 2016 Else ie .
[3] F. Bonomi, e al., Fog Compu ing: A Pla o m o In e ne o Things and
Analy ics, Big Da a and In e ne o Things: A Roadmap o Sma
En i onmen s Vol. 546 o S udies in Compu a ional In elligence 2014.
Fu u e Technologies Con e ence (FTC) 2017
29-30 No embe 2017 | Vancou e , Canada
738 | P a g e
[4] X. Masip-B uin, e al., Foggy clouds and cloudy ogs: a eal need o
coo dina ed managemen o og- o-cloud (F2C) compu ing sys ems,
IEEE Wi eless Communica ion Magazine, Oc obe 2016.
[5] O. Salman, e al., Iden i y-Based Au hen ica ion Scheme o he In e ne
o Things, 2016 IEEE Symposium on Compu e s and Communica ion.
[6] S.R.Moosa i, e al., End- o-end secu i y scheme o mobili y enabled
heal hca e IoT, Fu u e Gene a ion Compu e Sys ems 64 2016.
[7] M. H. Ib ahim, Oc opus: An Edge-Fog Mu ual Au hen ica ion Scheme,
In e na ional Jou nal o Ne wo k Secu i y, Vol.18, No.6, No . 2016.
[8] W. Lee, e al., A Ga eway based Fog Compu ing A chi ec u e o
Wi eless Senso s and Ac ua o Ne wo ks, ICACT 2016.
[9] Y. Li, e al., A SDN-based A chi ec u e o Ho izon al In e ne o
Things Se ices, Communica ions (ICC), 2016.
[10] R. Vilal a, R.Ciungu. A.Mayo al, R.Casellas, R. Ma inez, D.Pubill,
J.Se a, R.Munoz, and C.Ve ikoukis, Imp o ing Secu i y in In e ne o
Things wi h So wa e De ined Ne wo king, Globcom Decembe 2016
[11] S.Tomo ic, K.Yoshigoe, I.Malje ic, I.Radusino ic, So wa e-De ined
og Ne wo k A chi ec u e o IoT, Wi eless pe s Commun (2017).
[12] F. Hu, Q. Hao, K. Bao, A Su ey on So wa e-De ined Ne wo k and
OpenFlow: F om Concep o Implemen a ion, IEEE Communica ions
Su e eys & Tu o ials, Vol. 16, N. 4, 2014.
[13] V. Souza, e al., Insigh s in o he Se ice Execu ion in a Combined Fog-
o-Cloud (F2C) Compu ing Sys em. 2016, Technical epo .
h p://www.ac.upc.edu/app/ esea ch- epo s/h ml/RR/2016/10.pd
[14] S. Kah azadeh, e al., Secu ing combined Fog- o-Cloud sys em Th ough
SDN App oach, C osscloud , Se bia, 2017.
[15] CIPSEC p ojec a www.cipsec.eu
[16] H. Li, e al., Iden i y-based au hen ica ion o cloud compu ing. In IEEE
In e na ional Con e ence on Cloud Compu ing. Sp inge , 2009. 157-166.
[17] C. Dsouza, e al.. Policy-d i en secu i y managemen o og compu ing:
P elimina y amewo k and a case s udy. IEEE 15 h In e na ional
Con e ence on In o ma ion Reuse and In eg a ion (IRI). 2014.