FoNAC - An automated Fog Node Audit and Certification scheme

FoNAC - An automated Fog Node Audit and Certification scheme
复制标题

FoNAC - 自动化雾节点审核和认证方案

DOI:
10.1016/j.cose.2020.101759
复制
发表时间:
2020
期刊:
Comput. Secur.
影响因子:
--
通讯作者:
S. Raza
S. Raza
中科院分区:
--
文献类型:
--
作者:
Mudassar Aslam;Bushra Mohsin;Abdul Nasir Khan;S. Raza

文献摘要

被引文献

相似文献

满足物联网数据的安全和隐私需求在新引入的中间雾计算层中变得同样重要,就像在其以前的技术层-云一样;但实现这种安全性是至关重要的,也是具有挑战性的。虽然雾层设备的安全保证是必要的,因为它们暴露于公共互联网,它变得更加复杂,比云层,因为它涉及大量的异构设备分层部署。手动审核和认证方案不适合大量的雾节点,从而抑制了所涉及的利益相关者完全使用手动安全保证方案。然而,通过引入对雾节点的自动化和持续监控和审计,可以提供可扩展和可行的安全保证,以确保可信,更新和无漏洞的雾层。本文提出了这样一个解决方案的形式,一个automatedFogNodeAuditandCertification计划(FoNAC),保证通过建议的雾层保证机制的安全雾层。FoNAC利用可信平台模块(TPM 2.0)功能来评估/验证运行雾节点的平台完整性,并在成功进行安全审计后向单个节点授予证书。在Dolev-Yao入侵者模型下,使用AVISPA进行了形式化的安全分析,验证了FoNAC的安全性。对FoNAC的安全性分析表明,FoNAC能够抵抗冒充、重放、伪造、拒绝服务和MITM攻击等网络攻击。
Meeting the security and privacy needs for IoT data becomes equally important in the newly introduced intermediary Fog Computing layer, as it was in its former technological layer - Cloud; but the accomplishment of such security is critical and challenging. While security assurance of the fog layer devices is imperative due to their exposure to the public Internet, it becomes even more complex, than the cloud layer, as it involves a large number of heterogeneous devices deployed hierarchically. Manual audit and certification schemes are unsuitable for large number of fog nodes thereby inhibiting the involved stakeholders to use manual security assurance schemes altogether. However, scalable and feasible security assurance can be provided by introducing automated and continuous monitoring and auditing of fog nodes to ensure a trusted, updated and vulnerability free fog layer. This paper presents such an solution in the form of an automatedFogNodeAudit andCertification scheme (FoNAC) which guarantees a secure fog layer through the proposed fog layer assurance mechanism. FoNAC leverages Trusted Platform Module (TPM 2.0) capabilities toevaluate/auditthe platform integrity of the operating fog nodes and grantscertificateto the individual node after a successful security audit. FoNAC security is also validated through its formal security analysis performed using AVISPA under Dolev-Yao intruder model. The security analysis of FoNAC shows its resistance against cyber-attacks like impersonation, replay attack, forgery, Denial of Service(DoS) and MITM attack.