Secure Edge Computing Management Based on Independent Microservices Providers for Gateway-Centric IoT Networks

Secure Edge Computing Management Based on Independent Microservices Providers for Gateway-Centric IoT Networks
复制标题

DOI:
10.1109/access.2020.3030297
复制
发表时间:
2020-01-01
期刊:
影响因子:
3.9
通讯作者:
Kim, Dohyeun
Kim, Dohyeun
中科院分区:
计算机科学3区
文献类型:
--
作者:
Jin, Wenquan;Xu, Rongxu;Kim, Dohyeun

文献摘要

被引文献

相似文献

边缘计算是一种新兴的计算范式,它将计算能力分布到网络边缘,以便在传感器和执行器所部署的环境附近进行计算。因此,基于足够的计算能力,可以从网络边缘向互联网提供异构解决方案。然而,网络边缘的设备计算和网络资源是受限的。在资源受限的情况下,从边缘计算提供安全服务是一项挑战。在本文中,我们提出一种安全的边缘计算方法,通过在边缘网关上部署带有安全网关的独立微服务提供商来提供设备、数据、用户和附加服务的管理。边缘网关是本地网络的枢纽,多个物联网设备部署在其中,以便与物理环境进行交互以实现传感和执行功能。网关通过基于多个独立服务器模块的微服务提供管理功能。每个以网关为中心的本地网络都有一个基于网关的独立管理服务。为了通过边缘网关提供安全的边缘计算服务,在提出的边缘网关上部署一个安全网关,以提供表述性状态转移应用编程接口,将安全服务而不是管理模块的微服务暴露给互联网。此外,在边缘网关中部署一个客户端支持网关,以提供基于网络会话的用户界面和访问转发服务,从而支持用户与安全网关的认证和授权。基于所提出的包括客户端支持网关和安全网关的边缘网关,物联网客户端和物联网设备能够进行通信,以便为用户提供安全的访问和可视化边缘服务。
Edge computing is an emerging computing paradigm that distributes the computational capability to the edge of networks for enabling the computation near to the environment where the sensors and actuators are deployed. Therefore, from the network edge, heterogeneous solutions can be provided to the Internet based on sufficient computing ability. Nevertheless, computing and networking resources are constrained for devices in the network edge. Providing secure services from edge computing is a challenge based on constrained resources. In this paper, we propose a secure edge computing to provide management of device, data, user and additional services based on deploying independent microservices providers with a security gateway on an edge gateway. The edge gateway is the hub of a local network where multiple IoT devices are deployed to interact with the physical environment for sensing and actuating. The gateway provides the management functionalities through microservices based on multiple independent server modules. Each gateway-centric local network has a standalone management service based on the gateway. For providing secure edge computing services through the edge gateway, a security gateway is deployed on the proposed edge gateway to provide Representational State Transfer Application Programming Interfaces to expose the security services to the Internet instead of microservices from management modules. Moreover, a client support gateway is deployed in the edge gateway to provide services of User Interface and access forwarding based on web sessions to support user authentication and authorization with the security gateway. Based on the proposed edge gateway including client support and security gateway, IoT clients and IoT devices are enabled to communicate for providing secure edge services of access and visualization to users.