A security policy enforcement framework for controlling IoT tenant applications in the edge

A security policy enforcement framework for controlling IoT tenant applications in the edge
复制标题

用于控制边缘 IoT 租户应用程序的安全策略执行框架

DOI:
10.1145/3277593.3277602
复制
发表时间:
2018
期刊:
Proceedings of the 8th International Conference on the Internet of Things
影响因子:
--
通讯作者:
Hong Linh Truong
Hong Linh Truong
中科院分区:
--
文献类型:
--
作者:
P. Nguyen;Phu H. Phung;Hong Linh Truong

文献摘要

被引文献

相似文献

在边缘计算的背景下,具有物联网数据中心和执行服务的物联网即服务(IoTaaS)允许物联网租户应用程序(应用程序)在物联网设备旁边执行,从而实现边缘分析和控制。然而,这对控制IoTaaS中的租户应用程序带来了新的安全挑战,而IoTaaS的巨大潜力只能通过灵活的安全机制来管理此类应用程序来实现。在本文中,我们提出了一个模型驱动的安全策略执行框架,名为MDSIoT,用于部署在边缘服务器中的物联网租户应用程序。该框架允许在模型级别指定执行策略,然后将其转换为可以在运行时部署用于策略实施的代码。此外,当部署在边缘以访问IoTaaS服务时,我们的方法支持物联网租户应用程序的互操作性。互操作性由中间代理层(网守)实现,该代理层将底层通信协议抽象为来自物联网租户应用程序的不同IoTaaS服务。因此,我们的方法支持自动部署和控制不同的物联网租户应用程序,独立于其技术,例如编程语言。我们已经开发了一个基于ThingML的建议看门人的概念验证,来自执行策略。多亏了ThingML工具,我们可以生成特定于平台的看门人代码,这些代码可以部署在边缘,用于根据执行策略控制物联网租户应用程序。
In the context of edge computing, IoT-as-a-Service (IoTaaS) with IoT data hubs and execution services allow IoT tenant applications (apps) to be executed next to IoT devices, enabling edge analytics and controls. However, this brings up new security challenges on controlling tenant apps in IoTaaS, whilst the great potential of IoTaaS can only be realized by flexible security mechanisms to govern such applications. In this paper, we propose a Model-Driven Security policy enforcement framework, named MDSIoT, for IoT tenant apps deployed in edge servers. This framework allows execution policies specified at the model level and then transformed into the code that can be deployed for policy enforcement at runtime. Moreover, our approach supports for the interoperability of IoT tenant apps when deployed in the edge to access IoTaaS services. The interoperability is enabled by an intermediate proxy layer (gatekeeper) that abstracts underlying communication protocols to the different IoTaaS services from IoT tenant apps. Therefore, our approach supports different IoT tenant apps to be deployed and controlled automatically, independently from their technologies, e.g. programming languages. We have developed a proof-of-concept of the proposed gatekeepers based on ThingML, derived from execution policies. Thanks to the ThingML tool, we can generate platform-specific code of gatekeepers that can be deployed in the edge for controlling IoT tenant apps based on the execution policies.