scieee Open visual document viewer

An SDN-based architecture for security provisioning in Fog-to-Cloud (F2C) computing systems

Kahvazadeh, Sarang,Souza, Vitor Barbosa,Masip Bruin, Xavier,Marín Tordera, Eva,García Almiñana, Jordi,Diaz, Rodrigo

Abstract

The unstoppable adoption of cloud and fog computing is paving the way to developing innovative services, some requiring features not yet covered by either fog or cloud computing. Simultaneously, nowadays technology evolution is easing the monitoring of any kind of infrastructure, be it large or small, private or public, static or dynamic. The fog-to-cloud computing (F2C) paradigm recently came up to support foreseen and unforeseen services demands while simultaneously benefiting from the smart capacities of the edge devices. Inherited from cloud and fog computing, a challenging aspect in F2C is security provisioning. Unfortunately, security strategies employed by cloud computing require computation power not supported by devices at the edge of the network, whereas security strategies in fog are yet on their infancy. Put this way, in this paper we propose Software Defined Network (SDN)-based security management architecture based on a master/slave strategy. The proposed architecture is conceptually applied to a critical infrastructure (CI) scenario, thus analyzing the benefits F2C may bring for security provisioning in CIs.

Full text

Fu u e Technologies Con e ence (FTC) 2017 29-30 No embe 2017 | Vancou e , Canada 732 | P a g e An SDN-based A chi ec u e o Secu i y P o isioning in Fog- o-Cloud (F2C) Compu ing Sys ems Sa ang Kah azadeh*, Vi o B. Souza§*, Xa i Masip-B uin*, E a Ma ín-To de a*, Jo di Ga cia*, Rod igo Diaz‡ *Ad anced Ne wo k A chi ec u es Lab (CRAAX), Uni e si a Poli ècnica de Ca alunya (UPC), Spain {skah aza, ba bosa, xmasip, e a, jo dig}@ac.upc.edu § In o ma ics Depa men (DPI), Uni e sidade Fede al de Viçosa (UFV), B azil ‡ Cybe secu i y Lab, A os Spain od igo.d[email p o ec ed] Abs ac —The uns oppable adop ion o cloud and og compu ing is pa ing he way o de eloping inno a i e se ices, some equi ing ea u es no ye co e ed by ei he og o cloud compu ing. Simul aneously, nowadays echnology e olu ion is easing he moni o ing o any kind o in as uc u e, be i la ge o small, p i a e o public, s a ic o dynamic. The og- o-cloud compu ing (F2C) pa adigm ecen ly came up o suppo o eseen and un o eseen se ices demands while simul aneously bene i ing om he sma capaci ies o he edge de ices. Inhe i ed om cloud and og compu ing, a challenging aspec in F2C is secu i y p o isioning. Un o una ely, secu i y s a egies employed by cloud compu ing equi e compu a ion powe no suppo ed by de ices a he edge o he ne wo k, whe eas secu i y s a egies in og a e ye on hei in ancy. Pu his way, in his pape we p opose So wa e De ined Ne wo k (SDN)-based secu i y managemen a chi ec u e based on a mas e /sla e s a egy. The p oposed a chi ec u e is concep ually applied o a c i ical in as uc u e (CI) scena io, hus analyzing he bene i s F2C may b ing o secu i y p o isioning in CIs. Keywo ds—IoT; cloud compu ing; og compu ing; og- o-cloud compu ing; secu i y; So wa e De ined Ne wo k (SDN); c i ical in as uc u es I. INTRODUCTION AND MOTIVATION Nowadays, he ope a ion be ween people and machines is being signi ican ly empowe ed h ough bo h inno a i e communica ion pa adigms and new sma de ices, such as sma phones, able s o wea ables, jus o name a ew. The g ow h o de ices connec i i y pa ed he way o coin he e m In e ne o Things (IoT), s anding o ― hings‖ communica ing anywhe e, a any ime, and o anyone – a ― hing‖ in IoT e e s o any ype o connec ed de ice. The explosion o IoT and, in pa icula , he apid g ow h o connec ed use s h ough a la ge a ie y o he e ogeneous de ices, ueled he deploymen o new applica ions wi h s ic demands in se e al key aspec s, such as secu i y, compu ing powe o s o age. In o de o ace ha se o demands, cloud compu ing eme ged as an on- demand sel -se ice, scalable, loca ion independen , pay-as- you-go online compu ing model, enabling he use o emo e physical compu ing esou ces loca ed a a da a cen e s [1], [2]. The ou sou cing o da a and se ices p ocessing up o he cloud, b ings no only economic bene i s bu also ees use s o ge conce ned on ela ed echnical aspec s. Howe e , handling ha olume and a ie y o da a, while simul aneously p o iding he eloci y demanded by IoT applica ions, equi es a new compu ing pa adigm ha can gua an ee low-la ency, as well as inc eased secu i y and ene gy-e iciency, among o he s. The og compu ing pa adigm [3] has been ecen ly p oposed as an ex ension o cloud compu ing, le e aging a highly dis ibu ed se o esou ces loca ed a he edge o he ne wo k, b inging compu ing, s o age and ne wo k capabili ies close o he end-use s, wha unques ionably acili a es o p o ide cha ac e is ics, such as low-la ency, loca ion awa eness, geo-dis ibu ion, inc eased da a secu i y and eal- ime p ocessing. Pu his way, in IoT scena ios, cloud makes cen aliza ion while og makes localiza ion. Le e aging cloud and og bene i s, og- o-cloud compu ing (F2C) has been ecen ly p oposed [4], as a new compu ing pa adigm p oposing an inno a i e hie a chical and dis ibu ed a chi ec u e. In he p oposed dis ibu ed a chi ec u e, use s’ de ices (i.e., edge de ices) may collec da a o be la e p ocessed in an ei he sequen ial o pa allel ashion a og, cloud o bo h, ueling he c ea ion o a la ge se o new se ices. The F2C compu ing model is in ended o join ly manage cloud and og esou ces in a coo dina ed way, demanding o a no el con ol and managemen s a egy, add essing some o he limi a ions inhe en o cloud and og compu ing. Many challenges a e ye unsol ed in he F2C compu ing model, om coo dina ed esou ces managemen a cloud and og o he challenges imposed when acing secu i y p o isioning. This pape ocuses on he secu i y aspec s o F2C, p oposing a no el SDN-based secu i y a chi ec u e ha is concep ually applied o a c i ical in as uc u e (CI) scena io, o uel discussion on he en isioned bene i s F2C may b ing o help secu e such a highly demanding scena ios. I mus be highligh ed ha besides he unsol ed secu i y issues om he seed cloud and og compu ing models, new F2C speci ic secu i y challenges come up. Thus, p oposing a solu ion o F2C undoub edly equi es a s ong backg ound on secu i y aspec s bo h in he cloud and og scena ios. On he cloud a ea, he ou sou cing o se ice p ocessing exposes well-known secu i y aspec s equi ing wide a en ion. Fo example, he dis ance be ween he end use and he cloud esou ces is no only adding long delays, bu also impac ing on he o e all secu i y. On he o he hand, al hough heo e ically og should b ing mo e p i acy — as a consequence o i s p oximi y o end-use s — i s dis ibu ed na u e makes og compu ing o ace no only secu i y challenges inhe i ed om cloud (shi ed om cloud o he edge), bu some o he inhe en Fu u e Technologies Con e ence (FTC) 2017 29-30 No embe 2017 | Vancou e , Canada 733 | P a g e o og compu ing. Fi s , og compu ing b ings i ualiza ion close o he use s, hus og compu ing mus also deal wi h secu i y issues ela ed o he i ualiza ion en i onmen as i usually happens in cloud compu ing. Second, ecognized he dis ibu ed s a egy adop ed by og compu ing, au hen ica ion in di e en le els u ns in o one o he main secu i y challenges in og. Indeed, he ac ha og compu ing shi s some compu a ional capabili ies, da a analysis, da a agg ega ion, da a il e ing and s o age o edge de ices, d i es he edge o he ne wo k o handle p i a e, sensi i e o con iden ial in o ma ion —such as, pe sonal in o ma ion o c i ical in as uc u es da a. Thus, secu e communica ions mus be g an ed in o de o gua an ee da a p i acy a he edge o he ne wo k. Thi d, he e is a high he e ogenei y in he de ices a he edge—nodes, se e s, ga eways, access poin s, e c.—, wha makes he design o an a chi ec u e g an ing secu i y p o isioning a ha d challenge. Mo eo e , we mus conside ha al hough adi ional cloud secu i y p o ocols may heo e ically p o ide some secu i y o og compu ing sys ems, he cons ain s on p ocessing capaci ies o he edge de ices undoub edly limi he e iciency o such exis ing p o ocols. On he o he hand, secu i y ini ia i es designed o og compu ing canno mee he huge amoun o p ocessing and s o age cloud equi emen s. In addi ion, he design o secu e ogs and clouds wi h exis ing secu i y a chi ec u es and p o ocols wi hou conside ing he coo dina ed na u e o F2C (in e ope abili y, he e ogenei y, e c.), may cause addi ional secu i y p oblems when conside ing he whole se o esou ces en isioned in F2C. This is he i s wo k dealing wi h comple e secu i y a chi ec u e o F2C compu ing sys ems. The challenging ques ion is: how can we design a new secu i y a chi ec u e p o iding secu e communica ion, con iden iali y, in eg i y, a ailabili y, mu ual og, cloud and nodes au hen ica ion, and access con ol o F2C? In his pape we assess ha he highly dis ibu ed F2C na u e can be p ope ly managed by using a So wa e De ined Ne wo k (SDN) based s a egy, le e aging a se o dis ibu ed con olle nodes, h ough a mas e -sla e s a egy. The pape is s uc u ed as ollows. Sec ion 2 desc ibes he ela ed wo k, Sec ion 3 desc ibes he new SDN-based secu i y o F2C, Sec ion 4 p esen s he ob ained esul s, and inally Sec ion 5 concludes he pape . II. RELATED WORK Many ecen wo ks ha e assessed he design o secu i y p o ocols and a chi ec u es o secu e og compu ing and cloud compu ing communica ions in an independen ashion. Ne e heless, none o hem conside ed a coo dina ed secu i y scheme, as demanded by new compu ing models, such as og- o-cloud. In his sec ion, we e isi some ele an wo ks on he secu i y a ea o cloud and og compu ing pa adigms, somehow ela ed o he speci ic F2C demands. I mus be highligh ed ha none o he e isi ed wo ks a e designed o be applied o F2C; hence he li e a u e e iew is in ended o lea n om pas e o s in ela ed a eas. In he way, secu ing og and cloud, au ho s in [5] p opose iden i y-based au hen ica ion o IoT assuming he cen al da abase, con olle s, ga eways and hings dis ibu ed in a hie a chical way. Key cha ac e is ics o his p oposal a e: 1) con olle s use an Ellip ic Cu e C yp og aphy (ECC) key es ablishmen me hod o gene a e keys; 2) ga eways ake hei ce i ica es om he con olle ; 3) hings a e egis e ed by ga eways; and 4) hings and ga eways go h ough he au hen ica ion phase. The p oposed solu ion p o ides a secu e hie a chical a chi ec u e and p o ocol o og and cloud communica ion, al hough secu i y o in e og communica ion is no g an ed. The solu ion p oposed in [6] aims a gua an eeing secu e end- o-end communica ions in IoT scena ios. The p esen ed a chi ec u e is spli in o de ice laye , og laye (ga eways) and cloud laye , and uses he ull ini ial ce i ica e-based Da ag am T anspo Laye Secu i y (DTLS) p o ocol be ween end-use and sma ga eways o au hen ica ion and au ho iza ion. Unlike he wo k in [5], he p oposed secu i y a chi ec u e only p o ides a secu e in e og communica ion wi hou conside ing he secu i y on he communica ion be ween og and cloud nodes. The wo k in [7] p oposes a og use / og se e mu ual au hen ica ion. In his a chi ec u e, og use s s o e a long-li ed mas e sec e key, which allows hem o oam h ough he ne wo k and mu ually au hen ica e o any og se e unde cloud se ice p o ide au ho iza ion. Un o una ely, his wo k p o ides secu i y in og communica ions wi hou ema king cloud secu i y. In [8], a ga eway-based og compu ing (mas e /sla e) o wi eless senso s and ac ua o ne wo ks is p oposed. Simila o he wo k in [7] his wo k is ocused on og so wi h no oom o be applied o cloud, no o F2C. Se e al solu ions al eady ocus on he SDN concep . The a chi ec u e in [9] includes a de ice laye (con ains senso s o da a collec ion), communica ion laye (includes SDN ga eways and ou e s), compu ing laye (con ains a con olle wi h accoun ing and billing mechanisms) and se ice laye (whe e IoT se ices a e buil by de elope s and ope a o s h ough p og amming he SDN con olle s) o he cons uc ion o an SDN-based a chi ec u e o ho izon al IoT. The p oposed a chi ec u e aces og communica ions h ough ga eways wi hou con empla ing cloud in a coo dina ed way. The wo k in [10] ocuses on an SDN app oach o secu ing IoT ga eways. The p oposed a chi ec u e includes 3 laye s: 1) Edge node, unning some se ices a he edge o he ne wo k o educe he amoun o da a o be ans e ed o he cloud o analysis, p ocessing, and s o age; 2) SDN con olle , suppo ing open- low swi ch; and 3) E2E applica ion, b inging moni o ing capaci ies o anomaly de ec ion. Al hough, au ho s only p o ide secu i y o IoT ga eways — wi hou conside ing cloud secu i y — hey p opose o use a cen alized SDN con olle wi h no capaci y o handle secu e mobili y issues. Au ho s in [11] p opose me ging Fog compu ing and so wa e- de ined ne wo king in o he IoT a chi ec u e. Au ho s a gue ha he p oposed combined s a egy acili a es a ic con ol, esou ce managemen , scalabili y, mobili y and eal- ime da a deli e y. O he challenges add essed by such a combined s a egy a e: 1) SDN con olle o ches a ion un angle og o ches a ion issues; 2) og compu ing would sol e scalabili y issues in SDN; 3) og b ings low-la ency o he whole IoT a chi ec u e. Howe e , secu i y p o isioning is no discussed in ha pape . Fu u e Technologies Con e ence (FTC) 2017 29-30 No embe 2017 | Vancou e , Canada 734 | P a g e Fig. 1. New SDN-based secu i y a chi ec u e. Taking in o accoun he no el y o F2C compu ing, his is he i s pape aimed a designing a solu ion o secu i y p o isioning in F2C. The p oposed SDN-based solu ion is he i s con ibu ion speci ically analyzing he cha ac e is ics imposed by he hie a chical F2C a chi ec u e. Indeed, ou p oposal sugges s using a F2C con olle (in he cloud) as a mas e , and dis ibu ed og-con olle s as sub-mas e s, all e icien ly managed in a coo dina ed ashion. To ha end a p o ocol mus also be designed de ining how dis inc elemen s in he a chi ec u e in e ac wi h each o he . III. THE PROPOSED SDN-BASED SECURITY ARCHITECTURE The coo dina ed managemen o og and cloud esou ces en isioned by F2C compu ing exace ba es adi ional cloud secu i y issues, such as au hen ica ion, communica ions p i acy among F2C laye s, con iden iali y, o in eg i y, jus o name a ew. In his sec ion, we in oduce he ounda ions o an SDN-based secu i y a chi ec u e o F2C compu ing sys ems. As epo ed in he s a e o he a sec ion, applying SDN o secu i y p o isioning is no a no el app oach and some exis ing wo ks al eady bene i om he decoupling concep b ough by SDN [12]. The s a egy loa ed in he pape le e ages he SDN concep by p oposing a cen alized F2C con olle in cloud, as a mas e , and se e al dis ibu ed con olle s co e ing he di e en ogs. Fig. 1 illus a es he p oposed SDN-based secu i y a chi ec u e, se ing ou le els, as ollows: 1) F2C con olle (Mas e ): A cen alized mas e con olle loca ed a cloud, is esponsible o managing, moni o ing and g an ing a secu e communica ion in he a chi ec u e. This F2C con olle gi es au ho iza ion o all componen s in he a chi ec u e o p o ide coo dina ed secu e managemen and communica ion among hem. 2) Con ol A eas (Sub-mas e 1): We conside a dis ibu ed secu i y con ol di ided in o dis inc con ol a eas, each one con aining one Con ol A ea Uni associa ed o one og. The e o e, each Con ol A ea Uni is esponsible o implemen ing he equi ed con ol unc ionali ies [13]. They a e esponsible o he es ablishmen o secu e coo dina ed managemen and communica ion be ween ogs in di e en a eas, as well as ogs o cloud, bo h equi ing F2C con olle au ho iza ion. The sub-mas e 1 con olle s a e dis ibu ed acco ding o each og loca ion, enabling a mobili y-awa e a chi ec u e. 3) Clus e -head (Sub-mas e 2): This is an edge de ice endo sed wi h high capaci y, in e ms o ne wo king, compu ing, and s o age, i compa ed o o he edge de ices loca ed in he same a ea. Each selec ed sub-mas e 2 is a middlewa e be ween nodes (IoT edge de ices) and con ol a eas on di e en ogs and is able o make da a p ocessing a he edge o he ne wo k acco ding o i s esou ce capaci y. 4) Nodes (Sla es): Loca ed a he edge o he ne wo k, he sla e laye is o med by he IoT de ices, which may include bo h end-use mobile de ices and deployed de ices, such as ixed senso s. The di e en a chi ec u al le els mus coo dina ely ope a e o success ully gua an ee secu i y p o isioning. To ha end, a o mal handshaking p o ocol mus be de ined, se ing he o mal p ocedu es o sys ems communica ion. Nex , we in oduce he main a ionale o he p o ocol pe o mance. In he p oposed a chi ec u e, con ol a eas (sub-mas e 1) mus egis e and au hen ica e o F2C con olle in o de o con ol ogs in di e en a eas. In a simila way, each clus e -head (sub- mas e 2), posi ioned in dis inc ogs, mus egis e in con ol a eas, while nodes mus egis e in he clus e -head. In he egis a ion phase, we assume all con ol-a eas o be egis e ed a he F2C con olle h ough a long- e m sec e -key, so hey can con ol he dis ibu ed ogs. Simul aneously, each clus e - head is also egis e ed in i s co esponding dis ibu ed con olle . A e he egis a ion phase, each con ol-a ea akes o e secu i y managemen in he dis ibu ed ogs, hence educing he usual complexi y when done a cloud. I is wo h men ioning ha , as illus a ed in Fig. 1 by he dashed line, he clus e -head may communica e di ec ly wi h he F2C con olle in some speci ic si ua ions (as desc ibed in he ollowing pa ag aphs), hus also equi ing he egis a ion o clus e - heads in he F2C con olle . A e he egis a ion phase, he communica ion be ween dis inc componen s o his a chi ec u e may be pe o med hie a chically, u ning in o h ee dis inc ca ego ies, as Fu u e Technologies Con e ence (FTC) 2017 29-30 No embe 2017 | Vancou e , Canada 735 | P a g e in oduced in ou p e ious wo k in [14]. He e, we discuss he p oposed a chi ec u e in an illus a i e sma ci y scena io in o de o alida e he dis ibu ed con olle s app oach. In he sma ci y scena io shown in Fig. 2, we assume a cen alized F2C con olle loca ed a he cloud owned by he sma ci y. The F2C con olle is esponsible o managing, con olling and p o iding a secu e communica ion o all sma ci y componen s. We assume a global opology including dis ibu ed con olle s deployed in a a ic ligh , a s o e ( og1), a gas s a ion, and a bus s a ion. These dis ibu ed con olle s would au hen ica e and ake au ho iza ion om he F2C con olle in he egis a ion and ini ializa ion s ep. The e o e, all con olle s a e able o in e -communica e in o de o p o ide secu e manageable communica ion o all sma ci y componen s, deployed in dis inc ogs. Fo he sake o simplici y, we conside ha in each og, he de ice wi h mo e capaci y in e ms o ne wo k, s o age and compu ing is he one selec ed as clus e -head. In Fig. 2, og 1 is a s o e, whe e og use s’ de ices can be con olled and au hen ica ed by he co esponding con ol a ea uni deployed in he s o e. Le ’s suppose a og 1 use wan s o communica e secu ely wi h a og use in og 4. Indeed, hey can communica e in a secu e and manageable way h ough he co esponding s o e con ol a ea uni and bus s a ion con ol- a ea uni . These dis ibu ed con olle s acili a e og o og au hen ica ion and communica ion. Hence, assuming ha a og 1 use in he s o e wan s o ake in o ma ion abou bus a i als, using ou dis ibu ed con olle s, he use can ge secu e in o ma ion h ough he co esponding con ol-a ea uni in he s o e ( his con ol-a ea uni has secu e in e communica ion wi h bus con ol a ea uni ). In ano he example, le ’s assume og 2 o be buil upon a se o ca s mo ing in he same di ec ion (see ed ca s in Fig. 2) and og 3 buil upon ano he se o ca s all mo ing in he same di ec ion, bu pe pendicula o ca s in og 2 (see g ay ca s in Fig. 2). Wi hin each o hese ogs, one ca shall be selec ed as a clus e - head and og 2 and og 3 can communica e in a secu e manageable way h ough hei espec i e con ol-a ea uni ( a ic-ligh ). Fu he mo e, whe he he co esponding con ol- a ea uni ( a ic-ligh ) ge s comp omised, a acked o down, he selec ed clus e -head, o ins ance in og 2, which ob ained a mas e key o di ec ly communica e o he F2C con olle du ing he egis a ion s ep, makes use o his con olle o ge a nea es and sa es con ol-a ea uni (suppose gas s a ion o bus s a ion con ol-a ea uni ). The e o e, og 2 would be con olled and managed by one o hem. Mo eo e , he p oposed a chi ec u e also enables he og use s in og 4 o be au hen ica ed o he sma ci y cloud h ough he bus con ol a ea uni wi h less au hen ica ion delay. Indeed, by deploying dis ibu ed con olle s o ogs managemen , we dec ease he dis ance be ween ogs and cloud which can be help ul o achie ing less au hen ica ion delay as well as highe secu i y by a oiding known a acks, such as man in he middle. Ano he p i ilege o dis ibu ed con olle s is secu e mobili y and hando e . Fig. 2. Sma ci y scena io. Fo ins ance, assume ha og 2, og 3, og 4 and og 5 a e on he mo e. Wi h he deploymen o dis ibu ed con olle s, we a e able o manage secu e mobili y and hando e h ough con ol a ea uni s in e communica ion. IV. REVIEWING CRITICAL INFRASTRUCTURES SECURITY NEEDS I is widely ecognized and la gely epo ed he ele ance C i ical In as uc u es (CIs) ha e o he unc ioning o a socie y. A CI can be de ined as a se o asse s, be i ei he physical o i ual, playing a i al ole in p o iding coun y’s needs, o he ex en ha i s incapaci y o des uc ion would ha e a de as a ing impac on secu i y, economy o public heal h. The e a e many in as uc u es ha may be ca ego ized as CI, such as (wi h no aim o be an exclusi e lis ) eme gency se ices, wa e supply sys ems, ag icul u e and ood, go e nmen , de ense indus y, in o ma ion echnology and elecommunica ion, heal hca e, banking sys em, ene gy, anspo a ion sys em, chemical indus y, pos al se ices, na ional ai po s o mili a y sys ems. Indeed, b eaking secu i y ulne abili ies in a CI causes c i ical in o ma ion leaks and e ible disas e s in no mal coun ies ope a ion. The e o e a comp ehensi e and exhaus i e iden i ica ion o he key secu i y equi emen s in c i ical in as uc u es is a mus o any coun y o se he p ope p ocedu es o secu i y p o isioning. Fu u e Technologies Con e ence (FTC) 2017 29-30 No embe 2017 | Vancou e , Canada 736 | P a g e Fig. 3. De ice-cloud au hen ica ion (Scena io 1). Fig. 4. End- o-end au hen ica ion (Scena io 2). In ac , we ca ego ize mos common secu i y equi emen s in c i ical in as uc u es in o [15]: s ong ne wo k secu i y managemen , s ong iden i ica ion and au hen ica ion mechanism, i m secu i y policy, da a con iden iali y, o ensics analysis, ope a ional echnology (OT) p o ec ion, OT ne wo k p o ec ion, secu e communica ion channel, cascading a ec p o ec ion, anomaly beha io de ec ion mechanism, high ne wo k a ic de ec ion mechanism ( o DoS/DDoS a acks), secu i y in o ma ion and e en managemen (SIEM), an imalwa e and an i i uses p o ec ion mechanism, ha dwa e secu i y, da a p i acy, da a in eg i y, and IT ne wo k p o ec ion. F om a secu i y pe spec i e CIs use o sha e a common, dis ibu ed, coo dina ed scena io, in ended o be an ex emely secu e amewo k including global policies and solu ions o gua an ee he equi ed pe o mance. The dis ibu ed policy de ined in he SDN-based secu i y a chi ec u e p oposed in his pape seems o be a p ope solu ion o be applied in CI scena ios. Indeed, he cen alized and dis ibu ed con olle s in ou a chi ec u e will help CIs: 1) ease componen s au hen ica ion; 2) ease sys ems au ho iza ion h ough a mas e - sla e s a egy; and 3) p o ide a coo dina ed managemen be ween di e en CIs o communica e in a secu e way. V. PRELIMINARY EXPERIMENTAL RESULTS This sec ion p esen s p elimina y a chi ec u e e alua ions aiming a alida ing he bene i s o he p oposed SDN-based a chi ec u e o secu i y p o isioning. To ha end, we pu he ocus on analyzing he delay equi ed o au hen ica ion pu poses, conside ing a adi ional s a egy based on cloud au hen ica ion and ano he one in e ed om he p oposed SDN-based secu i y a chi ec u e. Two scena ios a e analyzed, one demanding og-cloud au hen ica ion and he o he one demanding og- og (end- o-end) au hen ica ion. Scena io 1. Fog-cloud au hen ica ion: Le us assume a empe a u e-senso ) in a nuclea powe s a ion wan s o au hen ica e wi h he nuclea powe cloud o communica ion. Two dis inc app oaches may be deployed, as illus a ed in Fig. 3. A adi ional cloud au hen ica ion scheme is shown in ed-lines whils ou p oposal is shown in b own-lines. The adi ional au hen ica ion p ocedu e pe o ms as ollows:  S ep 1: Fog node ( empe a u e-senso ) exchange au hen ica ion messages wi h cloud (nuclea -powe cloud).  S ep 2: Tempe a u e senso and nuclea powe da acen e a e au hen ica ed. On he o he hand, he p oposed au hen ica ion p ocedu e pe o ms as ollows:  S ep 1*: Tempe a u e-senso exchange au hen ica ion messages wi h he Con ol-A ea uni is linked o. As Con ol-A ea uni s ake pe mission om he F2C con olle o con ol dis ibu ed Fogs du ing egis a ion phase, he con olle can do au hen ica ion o Fogs wi h hei p imi i e F2C con olle au ho iza ion.  S ep 2*: Nuclea powe cloud and empe a u e-senso a e au hen ica ed o communica ion. The senso ecei es acknowledgmen om cloud. Scena io 2. End- o-end au hen ica ion: Fo a scena io equi ing end- o-end au hen ica ion, such as a powe sys em willing o es ablish a secu e communica ion wi h a hospi al, we illus a e in Fig. 4 he adi ional au hen ica ion in ed-line and he p oposed au hen ica ion scheme in b own-line. The adi ional end- o-end au hen ica ion p ocedu e pe o ms as ollows:  S ep 1: Fog 1 (Powe sys em) exchange au hen ica ion messages wi h he cloud aiming a se ing secu e communica ion wi h Fog N (Hospi al).  S ep 2: Fog N au hen ica e om cloud o ha e communica ion wi h Fog 1.  S ep 3: Powe sys em and hospi al may es ablish secu e communica ion a e au hen ica ion. The p oposed end- o-end au hen ica ion p ocedu e pe o ms as ollows: Fu u e Technologies Con e ence (FTC) 2017 29-30 No embe 2017 | Vancou e , Canada 737 | P a g e  S ep 1*: Powe sys em exchange au hen ica ion messages wi h i s Con ol-A ea uni in o de o es ablish secu e communica ion wi h he hospi al.  S ep 2*: Hospi al au hen ica e om i s Con ol-A ea uni o es ablish secu e communica ion wi h he powe sys em. Is i wo h men ioning ha , as in Scena io 1, all Con ol-A ea uni s a e al eady egis e ed in F2C con olle , he e o e, dis ibu ed con olle s has pe mission o au hen ica e Fogs wi h no need o each ou o he cloud.  S ep 3*: Powe sys em and hospi al may se a secu e communica ion a e au hen ica ion. In bo h scena ios, he deploymen o he p oposed s a egy o au hen ica ion le e ages he low delay au hen ica ion p o ided by he dis ibu ed con olle s loca ed close o he end- use s. Indeed, Table 1 shows ha he au hen ica ion ime in og nodes a e signi ican ly lowe han he au hen ica ion in cloud when using adi ional schemes, such as he SSL Au hen ica ion P o ocol (SAP). The es ima ed delays o bo h og and cloud au hen ica ion we e based on wo ks in he li e a u e, such as [16], [17]. Consequen ly, Table 2 shows he es ima ed delays o he wo scena ios analyzed, clea ly highligh ing he bene i s in e ms o educed delay when applying he SDN-based secu i y a chi ec u e. F om he ob ained esul s we may in e he e ec s he p oposed a chi ec u e may ha e in pa icula CI scena ios. Recognized he signi icance au hen ica ion has in CI scena ios, we may s a e ha acco ding o ou e alua ion, he educed delay o bo h og and cloud au hen ica ion b ough by ou a chi ec u e will be ex emely bene icial in CI scena ios. Le us conside wo well-known CI scena ios, such as a hospi al (eHeal h sec o ) and a ain p o ide ( anspo sec o ). In bo h scena ios low delay au hen ica ion is key o gua an ee he eal ime pe o mance, manda o y in bo h domains. Fo ins ance, le us assume a pa ien needs o communica e p i a ely wi h his/he doc o . Acco ding o he solu ion p oposed in his pape , he au hen ica ion phase would be execu ed a bo h he dis ibu ed con olle s ( ogs) and he cen alized con olle (cloud), hus wi h a s ong impac on delay educ ion. Mo ing o he anspo scena io, a ain mus communica e wi h se e al s a ions o check a ic and in e locking sys ems o a oid acciden s. This equi es mu ual ain and s a ions au hen ica ion wi h e y low delay o gua an ee a as eac ion, hus p e en ing undesi ed disas e s o come. The SDN-based secu i y a chi ec u e p oposed in his pape le e aging he deploymen o dis ibu ed con olle s, would undoub edly help dec ease he au hen ica ion delay, hus con ibu ing o a mo e secu e pe o mance. I is also wo h no icing ha he p oposed secu i y a chi ec u e would no impac only on indi idual CI scena ios bu also on he communica ion among hem. Indeed, CIs a e usually dependen each o he , so secu e communica ion among hem is a mus . Fo example, hospi al in as uc u e is s ongly dependen on he powe p o ide , same o a ain company, o a mili a y sys em wi h he eme gency con ol sys em. To make dependencies eliable and e icien , a secu e communica ions s a egy mus be deployed among hem. TABLE I. AUTHENTICATION DELAY COMPARISON IN FOG AND CLOUD Loca ion La ency Fog au hen ica ion ~ 300 ms Cloud au hen ica ion ~ 1000 ms TABLE II. AUTHENTICATION DELAY COMPARISON IN THE TWO SCENARIOS ANALYZED Scena io La ency Cloud s a egy SDN-based s a egy Fog-cloud au hen ica ion ~ 1000 ms ~ 300 ms end- o-end au hen ica ion ~ 2000 ms ~ 600 ms In his sec ion he p oposed a chi ec u e has been p elimina y alida ed in e ms o delay. Howe e , beyond he bene i s in oduced in esponse ime, we en ision many o he ad an ages, pa icula ly e e ing o a c i ical ask, such as he complexi y b ough by managing huge cen alized da abases loca ed a cloud. Assuming an IoT scena io whe e housands o he e ogeneous de ices a e e e asking o communica ion, keeping s ong secu i y gua an ees equi es a huge da abase o be managed. The p oposed dis ibu ed a chi ec u e elie es he complexi y o e head in oduced by such a managemen , h ough he deploymen o local da abases a og p emises. VI. CONCLUSIONS Dis inc ne wo k pa adigms such as Cloud compu ing, og compu ing and, in special, he ecen ly p oposed combined og- o-cloud (F2C) compu ing a e imposing new secu i y challenges in dis inc aspec s. This pape add esses secu i y aspec s in F2C compu ing by illus a ing, in e ms o au hen ica ion delay, how isola ed og and cloud secu i y solu ions a e no su icien o gua an ee he deploymen o a us able F2C coo dina ed managemen solu ion. In o de o con ibu e o ha p oblem, we in oduce an SDN-based secu i y a chi ec u e suppo ed by mas e /sla e s a egies augmen ed by deploying a se o well-de ined dis ibu ed con olle s. The pape a gues ha h ough he deploymen o his s a egy, we can dec ease he au hen ica ion delay in bo h og and cloud communica ions. Finally, we conclude assessing ha he e a e s ill many challenges o so ou , hus s ong e o s mus be alloca ed by he scien i ic communi y o p o ide a solu ion add essing he speci ic equi emen s b ough by he en isioned F2C scena io. ACKNOWLEDGMENT This wo k is suppo ed by he H2020 CIPSEC p ojec (700378). Fo UPC au ho s by he Spanish Minis y o Economy and Compe i i eness and by he Eu opean Regional De elopmen Fund unde con ac TEC2015-66220-R (MINECO/FEDER), and o V. Ba bosa by CAPES Founda ion, no 11888/13-0. REFERENCES [1] J.Gonzalez-Ma ínez, e al., Cloud compu ing and educa ion: A s a e-o - he-a su ey, Compu e s & Educa ion 80 (2015) 132-151, 2014. [2] S.Singh, Y. Jeong, J. H. Pa k, A su ey on cloud compu ing secu i y: Issues, h ea s, and solu ions, Jou nal o Ne wo k and Compu e Applica ions 75 (2016) 200–222, 2016 Else ie . [3] F. Bonomi, e al., Fog Compu ing: A Pla o m o In e ne o Things and Analy ics, Big Da a and In e ne o Things: A Roadmap o Sma En i onmen s Vol. 546 o S udies in Compu a ional In elligence 2014. Fu u e Technologies Con e ence (FTC) 2017 29-30 No embe 2017 | Vancou e , Canada 738 | P a g e [4] X. Masip-B uin, e al., Foggy clouds and cloudy ogs: a eal need o coo dina ed managemen o og- o-cloud (F2C) compu ing sys ems, IEEE Wi eless Communica ion Magazine, Oc obe 2016. [5] O. Salman, e al., Iden i y-Based Au hen ica ion Scheme o he In e ne o Things, 2016 IEEE Symposium on Compu e s and Communica ion. [6] S.R.Moosa i, e al., End- o-end secu i y scheme o mobili y enabled heal hca e IoT, Fu u e Gene a ion Compu e Sys ems 64 2016. [7] M. H. Ib ahim, Oc opus: An Edge-Fog Mu ual Au hen ica ion Scheme, In e na ional Jou nal o Ne wo k Secu i y, Vol.18, No.6, No . 2016. [8] W. Lee, e al., A Ga eway based Fog Compu ing A chi ec u e o Wi eless Senso s and Ac ua o Ne wo ks, ICACT 2016. [9] Y. Li, e al., A SDN-based A chi ec u e o Ho izon al In e ne o Things Se ices, Communica ions (ICC), 2016. [10] R. Vilal a, R.Ciungu. A.Mayo al, R.Casellas, R. Ma inez, D.Pubill, J.Se a, R.Munoz, and C.Ve ikoukis, Imp o ing Secu i y in In e ne o Things wi h So wa e De ined Ne wo king, Globcom Decembe 2016 [11] S.Tomo ic, K.Yoshigoe, I.Malje ic, I.Radusino ic, So wa e-De ined og Ne wo k A chi ec u e o IoT, Wi eless pe s Commun (2017). [12] F. Hu, Q. Hao, K. Bao, A Su ey on So wa e-De ined Ne wo k and OpenFlow: F om Concep o Implemen a ion, IEEE Communica ions Su e eys & Tu o ials, Vol. 16, N. 4, 2014. [13] V. Souza, e al., Insigh s in o he Se ice Execu ion in a Combined Fog- o-Cloud (F2C) Compu ing Sys em. 2016, Technical epo . h p://www.ac.upc.edu/app/ esea ch- epo s/h ml/RR/2016/10.pd [14] S. Kah azadeh, e al., Secu ing combined Fog- o-Cloud sys em Th ough SDN App oach, C osscloud , Se bia, 2017. [15] CIPSEC p ojec a www.cipsec.eu [16] H. Li, e al., Iden i y-based au hen ica ion o cloud compu ing. In IEEE In e na ional Con e ence on Cloud Compu ing. Sp inge , 2009. 157-166. [17] C. Dsouza, e al.. Policy-d i en secu i y managemen o og compu ing: P elimina y amewo k and a case s udy. IEEE 15 h In e na ional Con e ence on In o ma ion Reuse and In eg a ion (IRI). 2014.