Fu u e Technologies Con e ence (FTC) 2017
29-30 No embe 2017 | Vancou e , Canada
732 | P a g e
An SDN-based A chi ec u e o Secu i y P o isioning
in Fog- o-Cloud (F2C) Compu ing Sys ems
Sa ang Kah azadeh*, Vi o B. Souza§*, Xa i Masip-B uin*, E a Ma ín-To de a*, Jo di Ga cia*, Rod igo Diaz‡
*Ad anced Ne wo k A chi ec u es Lab (CRAAX), Uni e si a Poli ècnica de Ca alunya (UPC), Spain
{skah aza, ba bosa, xmasip, e a, jo dig}@ac.upc.edu
§ In o ma ics Depa men (DPI), Uni e sidade Fede al de Viçosa (UFV), B azil ‡ Cybe secu i y Lab, A os Spain
od igo.d[email p o ec ed]
Abs ac —The uns oppable adop ion o cloud and og
compu ing is pa ing he way o de eloping inno a i e se ices,
some equi ing ea u es no ye co e ed by ei he og o cloud
compu ing. Simul aneously, nowadays echnology e olu ion is
easing he moni o ing o any kind o in as uc u e, be i la ge o
small, p i a e o public, s a ic o dynamic. The og- o-cloud
compu ing (F2C) pa adigm ecen ly came up o suppo o eseen
and un o eseen se ices demands while simul aneously bene i ing
om he sma capaci ies o he edge de ices. Inhe i ed om
cloud and og compu ing, a challenging aspec in F2C is secu i y
p o isioning. Un o una ely, secu i y s a egies employed by
cloud compu ing equi e compu a ion powe no suppo ed by
de ices a he edge o he ne wo k, whe eas secu i y s a egies in
og a e ye on hei in ancy. Pu his way, in his pape we
p opose So wa e De ined Ne wo k (SDN)-based secu i y
managemen a chi ec u e based on a mas e /sla e s a egy. The
p oposed a chi ec u e is concep ually applied o a c i ical
in as uc u e (CI) scena io, hus analyzing he bene i s F2C may
b ing o secu i y p o isioning in CIs.
Keywo ds—IoT; cloud compu ing; og compu ing; og- o-cloud
compu ing; secu i y; So wa e De ined Ne wo k (SDN); c i ical
in as uc u es
I. INTRODUCTION AND MOTIVATION
Nowadays, he ope a ion be ween people and machines is
being signi ican ly empowe ed h ough bo h inno a i e
communica ion pa adigms and new sma de ices, such as
sma phones, able s o wea ables, jus o name a ew. The
g ow h o de ices connec i i y pa ed he way o coin he e m
In e ne o Things (IoT), s anding o ― hings‖ communica ing
anywhe e, a any ime, and o anyone – a ― hing‖ in IoT e e s
o any ype o connec ed de ice. The explosion o IoT and, in
pa icula , he apid g ow h o connec ed use s h ough a la ge
a ie y o he e ogeneous de ices, ueled he deploymen o
new applica ions wi h s ic demands in se e al key aspec s,
such as secu i y, compu ing powe o s o age. In o de o ace
ha se o demands, cloud compu ing eme ged as an on-
demand sel -se ice, scalable, loca ion independen , pay-as-
you-go online compu ing model, enabling he use o emo e
physical compu ing esou ces loca ed a a da a cen e s [1],
[2]. The ou sou cing o da a and se ices p ocessing up o he
cloud, b ings no only economic bene i s bu also ees use s o
ge conce ned on ela ed echnical aspec s.
Howe e , handling ha olume and a ie y o da a, while
simul aneously p o iding he eloci y demanded by IoT
applica ions, equi es a new compu ing pa adigm ha can
gua an ee low-la ency, as well as inc eased secu i y and
ene gy-e iciency, among o he s. The og compu ing pa adigm
[3] has been ecen ly p oposed as an ex ension o cloud
compu ing, le e aging a highly dis ibu ed se o esou ces
loca ed a he edge o he ne wo k, b inging compu ing, s o age
and ne wo k capabili ies close o he end-use s, wha
unques ionably acili a es o p o ide cha ac e is ics, such as
low-la ency, loca ion awa eness, geo-dis ibu ion, inc eased
da a secu i y and eal- ime p ocessing. Pu his way, in IoT
scena ios, cloud makes cen aliza ion while og makes
localiza ion.
Le e aging cloud and og bene i s, og- o-cloud compu ing
(F2C) has been ecen ly p oposed [4], as a new compu ing
pa adigm p oposing an inno a i e hie a chical and dis ibu ed
a chi ec u e. In he p oposed dis ibu ed a chi ec u e, use s’
de ices (i.e., edge de ices) may collec da a o be la e
p ocessed in an ei he sequen ial o pa allel ashion a og,
cloud o bo h, ueling he c ea ion o a la ge se o new
se ices. The F2C compu ing model is in ended o join ly
manage cloud and og esou ces in a coo dina ed way,
demanding o a no el con ol and managemen s a egy,
add essing some o he limi a ions inhe en o cloud and og
compu ing. Many challenges a e ye unsol ed in he F2C
compu ing model, om coo dina ed esou ces managemen a
cloud and og o he challenges imposed when acing secu i y
p o isioning. This pape ocuses on he secu i y aspec s o
F2C, p oposing a no el SDN-based secu i y a chi ec u e ha is
concep ually applied o a c i ical in as uc u e (CI) scena io, o
uel discussion on he en isioned bene i s F2C may b ing o
help secu e such a highly demanding scena ios.
I mus be highligh ed ha besides he unsol ed secu i y
issues om he seed cloud and og compu ing models, new
F2C speci ic secu i y challenges come up. Thus, p oposing a
solu ion o F2C undoub edly equi es a s ong backg ound on
secu i y aspec s bo h in he cloud and og scena ios.
On he cloud a ea, he ou sou cing o se ice p ocessing
exposes well-known secu i y aspec s equi ing wide a en ion.
Fo example, he dis ance be ween he end use and he cloud
esou ces is no only adding long delays, bu also impac ing on
he o e all secu i y. On he o he hand, al hough heo e ically
og should b ing mo e p i acy — as a consequence o i s
p oximi y o end-use s — i s dis ibu ed na u e makes og
compu ing o ace no only secu i y challenges inhe i ed om
cloud (shi ed om cloud o he edge), bu some o he inhe en
Fu u e Technologies Con e ence (FTC) 2017
29-30 No embe 2017 | Vancou e , Canada
733 | P a g e
o og compu ing. Fi s , og compu ing b ings i ualiza ion
close o he use s, hus og compu ing mus also deal wi h
secu i y issues ela ed o he i ualiza ion en i onmen as i
usually happens in cloud compu ing. Second, ecognized he
dis ibu ed s a egy adop ed by og compu ing, au hen ica ion
in di e en le els u ns in o one o he main secu i y challenges
in og. Indeed, he ac ha og compu ing shi s some
compu a ional capabili ies, da a analysis, da a agg ega ion, da a
il e ing and s o age o edge de ices, d i es he edge o he
ne wo k o handle p i a e, sensi i e o con iden ial in o ma ion
—such as, pe sonal in o ma ion o c i ical in as uc u es da a.
Thus, secu e communica ions mus be g an ed in o de o
gua an ee da a p i acy a he edge o he ne wo k. Thi d, he e
is a high he e ogenei y in he de ices a he edge—nodes,
se e s, ga eways, access poin s, e c.—, wha makes he design
o an a chi ec u e g an ing secu i y p o isioning a ha d
challenge. Mo eo e , we mus conside ha al hough
adi ional cloud secu i y p o ocols may heo e ically p o ide
some secu i y o og compu ing sys ems, he cons ain s on
p ocessing capaci ies o he edge de ices undoub edly limi he
e iciency o such exis ing p o ocols. On he o he hand,
secu i y ini ia i es designed o og compu ing canno mee he
huge amoun o p ocessing and s o age cloud equi emen s. In
addi ion, he design o secu e ogs and clouds wi h exis ing
secu i y a chi ec u es and p o ocols wi hou conside ing he
coo dina ed na u e o F2C (in e ope abili y, he e ogenei y,
e c.), may cause addi ional secu i y p oblems when conside ing
he whole se o esou ces en isioned in F2C. This is he i s
wo k dealing wi h comple e secu i y a chi ec u e o F2C
compu ing sys ems.
The challenging ques ion is: how can we design a new
secu i y a chi ec u e p o iding secu e communica ion,
con iden iali y, in eg i y, a ailabili y, mu ual og, cloud and
nodes au hen ica ion, and access con ol o F2C? In his pape
we assess ha he highly dis ibu ed F2C na u e can be
p ope ly managed by using a So wa e De ined Ne wo k
(SDN) based s a egy, le e aging a se o dis ibu ed con olle
nodes, h ough a mas e -sla e s a egy.
The pape is s uc u ed as ollows. Sec ion 2 desc ibes he
ela ed wo k, Sec ion 3 desc ibes he new SDN-based secu i y
o F2C, Sec ion 4 p esen s he ob ained esul s, and inally
Sec ion 5 concludes he pape .
II. RELATED WORK
Many ecen wo ks ha e assessed he design o secu i y
p o ocols and a chi ec u es o secu e og compu ing and cloud
compu ing communica ions in an independen ashion.
Ne e heless, none o hem conside ed a coo dina ed secu i y
scheme, as demanded by new compu ing models, such as og-
o-cloud. In his sec ion, we e isi some ele an wo ks on he
secu i y a ea o cloud and og compu ing pa adigms,
somehow ela ed o he speci ic F2C demands. I mus be
highligh ed ha none o he e isi ed wo ks a e designed o be
applied o F2C; hence he li e a u e e iew is in ended o lea n
om pas e o s in ela ed a eas.
In he way, secu ing og and cloud, au ho s in [5] p opose
iden i y-based au hen ica ion o IoT assuming he cen al
da abase, con olle s, ga eways and hings dis ibu ed in a
hie a chical way. Key cha ac e is ics o his p oposal a e:
1) con olle s use an Ellip ic Cu e C yp og aphy (ECC) key
es ablishmen me hod o gene a e keys; 2) ga eways ake hei
ce i ica es om he con olle ; 3) hings a e egis e ed by
ga eways; and 4) hings and ga eways go h ough he
au hen ica ion phase. The p oposed solu ion p o ides a secu e
hie a chical a chi ec u e and p o ocol o og and cloud
communica ion, al hough secu i y o in e og communica ion
is no g an ed. The solu ion p oposed in [6] aims a
gua an eeing secu e end- o-end communica ions in IoT
scena ios. The p esen ed a chi ec u e is spli in o de ice laye ,
og laye (ga eways) and cloud laye , and uses he ull ini ial
ce i ica e-based Da ag am T anspo Laye Secu i y (DTLS)
p o ocol be ween end-use and sma ga eways o
au hen ica ion and au ho iza ion. Unlike he wo k in [5], he
p oposed secu i y a chi ec u e only p o ides a secu e in e og
communica ion wi hou conside ing he secu i y on he
communica ion be ween og and cloud nodes. The wo k in [7]
p oposes a og use / og se e mu ual au hen ica ion. In his
a chi ec u e, og use s s o e a long-li ed mas e sec e key,
which allows hem o oam h ough he ne wo k and mu ually
au hen ica e o any og se e unde cloud se ice p o ide
au ho iza ion. Un o una ely, his wo k p o ides secu i y in og
communica ions wi hou ema king cloud secu i y. In [8], a
ga eway-based og compu ing (mas e /sla e) o wi eless
senso s and ac ua o ne wo ks is p oposed. Simila o he wo k
in [7] his wo k is ocused on og so wi h no oom o be
applied o cloud, no o F2C.
Se e al solu ions al eady ocus on he SDN concep . The
a chi ec u e in [9] includes a de ice laye (con ains senso s o
da a collec ion), communica ion laye (includes SDN ga eways
and ou e s), compu ing laye (con ains a con olle wi h
accoun ing and billing mechanisms) and se ice laye (whe e
IoT se ices a e buil by de elope s and ope a o s h ough
p og amming he SDN con olle s) o he cons uc ion o an
SDN-based a chi ec u e o ho izon al IoT. The p oposed
a chi ec u e aces og communica ions h ough ga eways
wi hou con empla ing cloud in a coo dina ed way. The wo k
in [10] ocuses on an SDN app oach o secu ing IoT
ga eways. The p oposed a chi ec u e includes 3 laye s: 1) Edge
node, unning some se ices a he edge o he ne wo k o
educe he amoun o da a o be ans e ed o he cloud o
analysis, p ocessing, and s o age; 2) SDN con olle ,
suppo ing open- low swi ch; and 3) E2E applica ion, b inging
moni o ing capaci ies o anomaly de ec ion. Al hough, au ho s
only p o ide secu i y o IoT ga eways — wi hou conside ing
cloud secu i y — hey p opose o use a cen alized SDN
con olle wi h no capaci y o handle secu e mobili y issues.
Au ho s in [11] p opose me ging Fog compu ing and so wa e-
de ined ne wo king in o he IoT a chi ec u e. Au ho s a gue
ha he p oposed combined s a egy acili a es a ic con ol,
esou ce managemen , scalabili y, mobili y and eal- ime da a
deli e y. O he challenges add essed by such a combined
s a egy a e: 1) SDN con olle o ches a ion un angle og
o ches a ion issues; 2) og compu ing would sol e scalabili y
issues in SDN; 3) og b ings low-la ency o he whole IoT
a chi ec u e. Howe e , secu i y p o isioning is no discussed in
ha pape .
Fu u e Technologies Con e ence (FTC) 2017
29-30 No embe 2017 | Vancou e , Canada
734 | P a g e
Fig. 1. New SDN-based secu i y a chi ec u e.
Taking in o accoun he no el y o F2C compu ing, his is
he i s pape aimed a designing a solu ion o secu i y
p o isioning in F2C. The p oposed SDN-based solu ion is he
i s con ibu ion speci ically analyzing he cha ac e is ics
imposed by he hie a chical F2C a chi ec u e. Indeed, ou
p oposal sugges s using a F2C con olle (in he cloud) as a
mas e , and dis ibu ed og-con olle s as sub-mas e s, all
e icien ly managed in a coo dina ed ashion. To ha end a
p o ocol mus also be designed de ining how dis inc elemen s
in he a chi ec u e in e ac wi h each o he .
III. THE PROPOSED SDN-BASED SECURITY ARCHITECTURE
The coo dina ed managemen o og and cloud esou ces
en isioned by F2C compu ing exace ba es adi ional cloud
secu i y issues, such as au hen ica ion, communica ions
p i acy among F2C laye s, con iden iali y, o in eg i y, jus o
name a ew. In his sec ion, we in oduce he ounda ions o an
SDN-based secu i y a chi ec u e o F2C compu ing sys ems.
As epo ed in he s a e o he a sec ion, applying SDN o
secu i y p o isioning is no a no el app oach and some exis ing
wo ks al eady bene i om he decoupling concep b ough by
SDN [12]. The s a egy loa ed in he pape le e ages he SDN
concep by p oposing a cen alized F2C con olle in cloud, as
a mas e , and se e al dis ibu ed con olle s co e ing he
di e en ogs. Fig. 1 illus a es he p oposed SDN-based
secu i y a chi ec u e, se ing ou le els, as ollows:
1) F2C con olle (Mas e ): A cen alized mas e
con olle loca ed a cloud, is esponsible o managing,
moni o ing and g an ing a secu e communica ion in he
a chi ec u e. This F2C con olle gi es au ho iza ion o all
componen s in he a chi ec u e o p o ide coo dina ed secu e
managemen and communica ion among hem.
2) Con ol A eas (Sub-mas e 1): We conside a dis ibu ed
secu i y con ol di ided in o dis inc con ol a eas, each one
con aining one Con ol A ea Uni associa ed o one og.
The e o e, each Con ol A ea Uni is esponsible o
implemen ing he equi ed con ol unc ionali ies [13]. They
a e esponsible o he es ablishmen o secu e coo dina ed
managemen and communica ion be ween ogs in di e en
a eas, as well as ogs o cloud, bo h equi ing F2C con olle
au ho iza ion. The sub-mas e 1 con olle s a e dis ibu ed
acco ding o each og loca ion, enabling a mobili y-awa e
a chi ec u e.
3) Clus e -head (Sub-mas e 2): This is an edge de ice
endo sed wi h high capaci y, in e ms o ne wo king,
compu ing, and s o age, i compa ed o o he edge de ices
loca ed in he same a ea. Each selec ed sub-mas e 2 is a
middlewa e be ween nodes (IoT edge de ices) and con ol
a eas on di e en ogs and is able o make da a p ocessing a
he edge o he ne wo k acco ding o i s esou ce capaci y.
4) Nodes (Sla es): Loca ed a he edge o he ne wo k, he
sla e laye is o med by he IoT de ices, which may include
bo h end-use mobile de ices and deployed de ices, such as
ixed senso s.
The di e en a chi ec u al le els mus coo dina ely ope a e
o success ully gua an ee secu i y p o isioning. To ha end, a
o mal handshaking p o ocol mus be de ined, se ing he
o mal p ocedu es o sys ems communica ion. Nex , we
in oduce he main a ionale o he p o ocol pe o mance. In
he p oposed a chi ec u e, con ol a eas (sub-mas e 1) mus
egis e and au hen ica e o F2C con olle in o de o con ol
ogs in di e en a eas. In a simila way, each clus e -head (sub-
mas e 2), posi ioned in dis inc ogs, mus egis e in con ol
a eas, while nodes mus egis e in he clus e -head. In he
egis a ion phase, we assume all con ol-a eas o be egis e ed
a he F2C con olle h ough a long- e m sec e -key, so hey
can con ol he dis ibu ed ogs. Simul aneously, each clus e -
head is also egis e ed in i s co esponding dis ibu ed
con olle . A e he egis a ion phase, each con ol-a ea akes
o e secu i y managemen in he dis ibu ed ogs, hence
educing he usual complexi y when done a cloud. I is wo h
men ioning ha , as illus a ed in Fig. 1 by he dashed line, he
clus e -head may communica e di ec ly wi h he F2C con olle
in some speci ic si ua ions (as desc ibed in he ollowing
pa ag aphs), hus also equi ing he egis a ion o clus e -
heads in he F2C con olle .
A e he egis a ion phase, he communica ion be ween
dis inc componen s o his a chi ec u e may be pe o med
hie a chically, u ning in o h ee dis inc ca ego ies, as
Fu u e Technologies Con e ence (FTC) 2017
29-30 No embe 2017 | Vancou e , Canada
735 | P a g e
in oduced in ou p e ious wo k in [14]. He e, we discuss he
p oposed a chi ec u e in an illus a i e sma ci y scena io in
o de o alida e he dis ibu ed con olle s app oach.
In he sma ci y scena io shown in Fig. 2, we assume a
cen alized F2C con olle loca ed a he cloud owned by he
sma ci y. The F2C con olle is esponsible o managing,
con olling and p o iding a secu e communica ion o all sma
ci y componen s. We assume a global opology including
dis ibu ed con olle s deployed in a a ic ligh , a s o e ( og1),
a gas s a ion, and a bus s a ion. These dis ibu ed con olle s
would au hen ica e and ake au ho iza ion om he F2C
con olle in he egis a ion and ini ializa ion s ep. The e o e,
all con olle s a e able o in e -communica e in o de o p o ide
secu e manageable communica ion o all sma ci y
componen s, deployed in dis inc ogs. Fo he sake o
simplici y, we conside ha in each og, he de ice wi h mo e
capaci y in e ms o ne wo k, s o age and compu ing is he one
selec ed as clus e -head.
In Fig. 2, og 1 is a s o e, whe e og use s’ de ices can be
con olled and au hen ica ed by he co esponding con ol a ea
uni deployed in he s o e. Le ’s suppose a og 1 use wan s o
communica e secu ely wi h a og use in og 4. Indeed, hey
can communica e in a secu e and manageable way h ough he
co esponding s o e con ol a ea uni and bus s a ion con ol-
a ea uni . These dis ibu ed con olle s acili a e og o og
au hen ica ion and communica ion. Hence, assuming ha a
og 1 use in he s o e wan s o ake in o ma ion abou bus
a i als, using ou dis ibu ed con olle s, he use can ge
secu e in o ma ion h ough he co esponding con ol-a ea uni
in he s o e ( his con ol-a ea uni has secu e in e
communica ion wi h bus con ol a ea uni ). In ano he
example, le ’s assume og 2 o be buil upon a se o ca s
mo ing in he same di ec ion (see ed ca s in Fig. 2) and og 3
buil upon ano he se o ca s all mo ing in he same di ec ion,
bu pe pendicula o ca s in og 2 (see g ay ca s in Fig. 2).
Wi hin each o hese ogs, one ca shall be selec ed as a clus e -
head and og 2 and og 3 can communica e in a secu e
manageable way h ough hei espec i e con ol-a ea uni
( a ic-ligh ). Fu he mo e, whe he he co esponding con ol-
a ea uni ( a ic-ligh ) ge s comp omised, a acked o down,
he selec ed clus e -head, o ins ance in og 2, which ob ained
a mas e key o di ec ly communica e o he F2C con olle
du ing he egis a ion s ep, makes use o his con olle o ge a
nea es and sa es con ol-a ea uni (suppose gas s a ion o bus
s a ion con ol-a ea uni ). The e o e, og 2 would be con olled
and managed by one o hem.
Mo eo e , he p oposed a chi ec u e also enables he og
use s in og 4 o be au hen ica ed o he sma ci y cloud
h ough he bus con ol a ea uni wi h less au hen ica ion delay.
Indeed, by deploying dis ibu ed con olle s o ogs
managemen , we dec ease he dis ance be ween ogs and cloud
which can be help ul o achie ing less au hen ica ion delay as
well as highe secu i y by a oiding known a acks, such as man
in he middle. Ano he p i ilege o dis ibu ed con olle s is
secu e mobili y and hando e .
Fig. 2. Sma ci y scena io.
Fo ins ance, assume ha og 2, og 3, og 4 and og 5 a e
on he mo e. Wi h he deploymen o dis ibu ed con olle s,
we a e able o manage secu e mobili y and hando e h ough
con ol a ea uni s in e communica ion.
IV. REVIEWING CRITICAL INFRASTRUCTURES SECURITY
NEEDS
I is widely ecognized and la gely epo ed he ele ance
C i ical In as uc u es (CIs) ha e o he unc ioning o a
socie y. A CI can be de ined as a se o asse s, be i ei he
physical o i ual, playing a i al ole in p o iding coun y’s
needs, o he ex en ha i s incapaci y o des uc ion would
ha e a de as a ing impac on secu i y, economy o public
heal h. The e a e many in as uc u es ha may be ca ego ized
as CI, such as (wi h no aim o be an exclusi e lis ) eme gency
se ices, wa e supply sys ems, ag icul u e and ood,
go e nmen , de ense indus y, in o ma ion echnology and
elecommunica ion, heal hca e, banking sys em, ene gy,
anspo a ion sys em, chemical indus y, pos al se ices,
na ional ai po s o mili a y sys ems. Indeed, b eaking secu i y
ulne abili ies in a CI causes c i ical in o ma ion leaks and
e ible disas e s in no mal coun ies ope a ion.
The e o e a comp ehensi e and exhaus i e iden i ica ion o
he key secu i y equi emen s in c i ical in as uc u es is a
mus o any coun y o se he p ope p ocedu es o secu i y
p o isioning.
Fu u e Technologies Con e ence (FTC) 2017
29-30 No embe 2017 | Vancou e , Canada
736 | P a g e
Fig. 3. De ice-cloud au hen ica ion (Scena io 1).
Fig. 4. End- o-end au hen ica ion (Scena io 2).
In ac , we ca ego ize mos common secu i y equi emen s
in c i ical in as uc u es in o [15]: s ong ne wo k secu i y
managemen , s ong iden i ica ion and au hen ica ion
mechanism, i m secu i y policy, da a con iden iali y, o ensics
analysis, ope a ional echnology (OT) p o ec ion, OT ne wo k
p o ec ion, secu e communica ion channel, cascading a ec
p o ec ion, anomaly beha io de ec ion mechanism, high
ne wo k a ic de ec ion mechanism ( o DoS/DDoS a acks),
secu i y in o ma ion and e en managemen (SIEM),
an imalwa e and an i i uses p o ec ion mechanism, ha dwa e
secu i y, da a p i acy, da a in eg i y, and IT ne wo k
p o ec ion.
F om a secu i y pe spec i e CIs use o sha e a common,
dis ibu ed, coo dina ed scena io, in ended o be an ex emely
secu e amewo k including global policies and solu ions o
gua an ee he equi ed pe o mance. The dis ibu ed policy
de ined in he SDN-based secu i y a chi ec u e p oposed in his
pape seems o be a p ope solu ion o be applied in CI
scena ios. Indeed, he cen alized and dis ibu ed con olle s in
ou a chi ec u e will help CIs: 1) ease componen s
au hen ica ion; 2) ease sys ems au ho iza ion h ough a mas e -
sla e s a egy; and 3) p o ide a coo dina ed managemen
be ween di e en CIs o communica e in a secu e way.
V. PRELIMINARY EXPERIMENTAL RESULTS
This sec ion p esen s p elimina y a chi ec u e e alua ions
aiming a alida ing he bene i s o he p oposed SDN-based
a chi ec u e o secu i y p o isioning. To ha end, we pu he
ocus on analyzing he delay equi ed o au hen ica ion
pu poses, conside ing a adi ional s a egy based on cloud
au hen ica ion and ano he one in e ed om he p oposed
SDN-based secu i y a chi ec u e. Two scena ios a e analyzed,
one demanding og-cloud au hen ica ion and he o he one
demanding og- og (end- o-end) au hen ica ion.
Scena io 1. Fog-cloud au hen ica ion: Le us assume a
empe a u e-senso ) in a nuclea powe s a ion wan s o
au hen ica e wi h he nuclea powe cloud o communica ion.
Two dis inc app oaches may be deployed, as illus a ed in
Fig. 3. A adi ional cloud au hen ica ion scheme is shown in
ed-lines whils ou p oposal is shown in b own-lines.
The adi ional au hen ica ion p ocedu e pe o ms as
ollows:
S ep 1: Fog node ( empe a u e-senso ) exchange
au hen ica ion messages wi h cloud (nuclea -powe
cloud).
S ep 2: Tempe a u e senso and nuclea powe
da acen e a e au hen ica ed.
On he o he hand, he p oposed au hen ica ion p ocedu e
pe o ms as ollows:
S ep 1*: Tempe a u e-senso exchange au hen ica ion
messages wi h he Con ol-A ea uni is linked o. As
Con ol-A ea uni s ake pe mission om he F2C
con olle o con ol dis ibu ed Fogs du ing egis a ion
phase, he con olle can do au hen ica ion o Fogs wi h
hei p imi i e F2C con olle au ho iza ion.
S ep 2*: Nuclea powe cloud and empe a u e-senso
a e au hen ica ed o communica ion. The senso
ecei es acknowledgmen om cloud.
Scena io 2. End- o-end au hen ica ion: Fo a scena io
equi ing end- o-end au hen ica ion, such as a powe sys em
willing o es ablish a secu e communica ion wi h a hospi al, we
illus a e in Fig. 4 he adi ional au hen ica ion in ed-line and
he p oposed au hen ica ion scheme in b own-line.
The adi ional end- o-end au hen ica ion p ocedu e
pe o ms as ollows:
S ep 1: Fog 1 (Powe sys em) exchange au hen ica ion
messages wi h he cloud aiming a se ing secu e
communica ion wi h Fog N (Hospi al).
S ep 2: Fog N au hen ica e om cloud o ha e
communica ion wi h Fog 1.
S ep 3: Powe sys em and hospi al may es ablish secu e
communica ion a e au hen ica ion.
The p oposed end- o-end au hen ica ion p ocedu e
pe o ms as ollows:
Fu u e Technologies Con e ence (FTC) 2017
29-30 No embe 2017 | Vancou e , Canada
737 | P a g e
S ep 1*: Powe sys em exchange au hen ica ion
messages wi h i s Con ol-A ea uni in o de o es ablish
secu e communica ion wi h he hospi al.
S ep 2*: Hospi al au hen ica e om i s Con ol-A ea
uni o es ablish secu e communica ion wi h he powe
sys em. Is i wo h men ioning ha , as in Scena io 1, all
Con ol-A ea uni s a e al eady egis e ed in F2C
con olle , he e o e, dis ibu ed con olle s has
pe mission o au hen ica e Fogs wi h no need o each
ou o he cloud.
S ep 3*: Powe sys em and hospi al may se a secu e
communica ion a e au hen ica ion.
In bo h scena ios, he deploymen o he p oposed s a egy
o au hen ica ion le e ages he low delay au hen ica ion
p o ided by he dis ibu ed con olle s loca ed close o he end-
use s. Indeed, Table 1 shows ha he au hen ica ion ime in og
nodes a e signi ican ly lowe han he au hen ica ion in cloud
when using adi ional schemes, such as he SSL
Au hen ica ion P o ocol (SAP). The es ima ed delays o bo h
og and cloud au hen ica ion we e based on wo ks in he
li e a u e, such as [16], [17]. Consequen ly, Table 2 shows he
es ima ed delays o he wo scena ios analyzed, clea ly
highligh ing he bene i s in e ms o educed delay when
applying he SDN-based secu i y a chi ec u e.
F om he ob ained esul s we may in e he e ec s he
p oposed a chi ec u e may ha e in pa icula CI scena ios.
Recognized he signi icance au hen ica ion has in CI scena ios,
we may s a e ha acco ding o ou e alua ion, he educed
delay o bo h og and cloud au hen ica ion b ough by ou
a chi ec u e will be ex emely bene icial in CI scena ios. Le us
conside wo well-known CI scena ios, such as a hospi al
(eHeal h sec o ) and a ain p o ide ( anspo sec o ). In bo h
scena ios low delay au hen ica ion is key o gua an ee he eal
ime pe o mance, manda o y in bo h domains. Fo ins ance, le
us assume a pa ien needs o communica e p i a ely wi h
his/he doc o . Acco ding o he solu ion p oposed in his
pape , he au hen ica ion phase would be execu ed a bo h he
dis ibu ed con olle s ( ogs) and he cen alized con olle
(cloud), hus wi h a s ong impac on delay educ ion. Mo ing
o he anspo scena io, a ain mus communica e wi h
se e al s a ions o check a ic and in e locking sys ems o
a oid acciden s. This equi es mu ual ain and s a ions
au hen ica ion wi h e y low delay o gua an ee a as eac ion,
hus p e en ing undesi ed disas e s o come. The SDN-based
secu i y a chi ec u e p oposed in his pape le e aging he
deploymen o dis ibu ed con olle s, would undoub edly help
dec ease he au hen ica ion delay, hus con ibu ing o a mo e
secu e pe o mance.
I is also wo h no icing ha he p oposed secu i y
a chi ec u e would no impac only on indi idual CI scena ios
bu also on he communica ion among hem. Indeed, CIs a e
usually dependen each o he , so secu e communica ion among
hem is a mus . Fo example, hospi al in as uc u e is s ongly
dependen on he powe p o ide , same o a ain company, o
a mili a y sys em wi h he eme gency con ol sys em. To make
dependencies eliable and e icien , a secu e communica ions
s a egy mus be deployed among hem.
TABLE I. AUTHENTICATION DELAY COMPARISON IN FOG AND CLOUD
Loca ion
La ency
Fog au hen ica ion
~ 300 ms
Cloud au hen ica ion
~ 1000 ms
TABLE II. AUTHENTICATION DELAY COMPARISON IN THE TWO
SCENARIOS ANALYZED
Scena io
La ency
Cloud s a egy
SDN-based s a egy
Fog-cloud au hen ica ion
~ 1000 ms
~ 300 ms
end- o-end au hen ica ion
~ 2000 ms
~ 600 ms
In his sec ion he p oposed a chi ec u e has been
p elimina y alida ed in e ms o delay. Howe e , beyond he
bene i s in oduced in esponse ime, we en ision many o he
ad an ages, pa icula ly e e ing o a c i ical ask, such as he
complexi y b ough by managing huge cen alized da abases
loca ed a cloud. Assuming an IoT scena io whe e housands o
he e ogeneous de ices a e e e asking o communica ion,
keeping s ong secu i y gua an ees equi es a huge da abase o
be managed. The p oposed dis ibu ed a chi ec u e elie es he
complexi y o e head in oduced by such a managemen ,
h ough he deploymen o local da abases a og p emises.
VI. CONCLUSIONS
Dis inc ne wo k pa adigms such as Cloud compu ing, og
compu ing and, in special, he ecen ly p oposed combined
og- o-cloud (F2C) compu ing a e imposing new secu i y
challenges in dis inc aspec s. This pape add esses secu i y
aspec s in F2C compu ing by illus a ing, in e ms o
au hen ica ion delay, how isola ed og and cloud secu i y
solu ions a e no su icien o gua an ee he deploymen o a
us able F2C coo dina ed managemen solu ion. In o de o
con ibu e o ha p oblem, we in oduce an SDN-based
secu i y a chi ec u e suppo ed by mas e /sla e s a egies
augmen ed by deploying a se o well-de ined dis ibu ed
con olle s. The pape a gues ha h ough he deploymen o
his s a egy, we can dec ease he au hen ica ion delay in bo h
og and cloud communica ions. Finally, we conclude assessing
ha he e a e s ill many challenges o so ou , hus s ong
e o s mus be alloca ed by he scien i ic communi y o
p o ide a solu ion add essing he speci ic equi emen s b ough
by he en isioned F2C scena io.
ACKNOWLEDGMENT
This wo k is suppo ed by he H2020 CIPSEC p ojec
(700378). Fo UPC au ho s by he Spanish Minis y o
Economy and Compe i i eness and by he Eu opean Regional
De elopmen Fund unde con ac TEC2015-66220-R
(MINECO/FEDER), and o V. Ba bosa by CAPES
Founda ion, no 11888/13-0.
REFERENCES
[1] J.Gonzalez-Ma ínez, e al., Cloud compu ing and educa ion: A s a e-o -
he-a su ey, Compu e s & Educa ion 80 (2015) 132-151, 2014.
[2] S.Singh, Y. Jeong, J. H. Pa k, A su ey on cloud compu ing secu i y:
Issues, h ea s, and solu ions, Jou nal o Ne wo k and Compu e
Applica ions 75 (2016) 200–222, 2016 Else ie .
[3] F. Bonomi, e al., Fog Compu ing: A Pla o m o In e ne o Things and
Analy ics, Big Da a and In e ne o Things: A Roadmap o Sma
En i onmen s Vol. 546 o S udies in Compu a ional In elligence 2014.
Fu u e Technologies Con e ence (FTC) 2017
29-30 No embe 2017 | Vancou e , Canada
738 | P a g e
[4] X. Masip-B uin, e al., Foggy clouds and cloudy ogs: a eal need o
coo dina ed managemen o og- o-cloud (F2C) compu ing sys ems,
IEEE Wi eless Communica ion Magazine, Oc obe 2016.
[5] O. Salman, e al., Iden i y-Based Au hen ica ion Scheme o he In e ne
o Things, 2016 IEEE Symposium on Compu e s and Communica ion.
[6] S.R.Moosa i, e al., End- o-end secu i y scheme o mobili y enabled
heal hca e IoT, Fu u e Gene a ion Compu e Sys ems 64 2016.
[7] M. H. Ib ahim, Oc opus: An Edge-Fog Mu ual Au hen ica ion Scheme,
In e na ional Jou nal o Ne wo k Secu i y, Vol.18, No.6, No . 2016.
[8] W. Lee, e al., A Ga eway based Fog Compu ing A chi ec u e o
Wi eless Senso s and Ac ua o Ne wo ks, ICACT 2016.
[9] Y. Li, e al., A SDN-based A chi ec u e o Ho izon al In e ne o
Things Se ices, Communica ions (ICC), 2016.
[10] R. Vilal a, R.Ciungu. A.Mayo al, R.Casellas, R. Ma inez, D.Pubill,
J.Se a, R.Munoz, and C.Ve ikoukis, Imp o ing Secu i y in In e ne o
Things wi h So wa e De ined Ne wo king, Globcom Decembe 2016
[11] S.Tomo ic, K.Yoshigoe, I.Malje ic, I.Radusino ic, So wa e-De ined
og Ne wo k A chi ec u e o IoT, Wi eless pe s Commun (2017).
[12] F. Hu, Q. Hao, K. Bao, A Su ey on So wa e-De ined Ne wo k and
OpenFlow: F om Concep o Implemen a ion, IEEE Communica ions
Su e eys & Tu o ials, Vol. 16, N. 4, 2014.
[13] V. Souza, e al., Insigh s in o he Se ice Execu ion in a Combined Fog-
o-Cloud (F2C) Compu ing Sys em. 2016, Technical epo .
h p://www.ac.upc.edu/app/ esea ch- epo s/h ml/RR/2016/10.pd
[14] S. Kah azadeh, e al., Secu ing combined Fog- o-Cloud sys em Th ough
SDN App oach, C osscloud , Se bia, 2017.
[15] CIPSEC p ojec a www.cipsec.eu
[16] H. Li, e al., Iden i y-based au hen ica ion o cloud compu ing. In IEEE
In e na ional Con e ence on Cloud Compu ing. Sp inge , 2009. 157-166.
[17] C. Dsouza, e al.. Policy-d i en secu i y managemen o og compu ing:
P elimina y amewo k and a case s udy. IEEE 15 h In e na ional
Con e ence on In o ma ion Reuse and In eg a ion (IRI). 2014.