End-To-End Security Architecture for Federated Cloud and IoT Networks
Title | End-To-End Security Architecture for Federated Cloud and IoT Networks |
Publication Type | Conference Paper |
Year of Publication | 2017 |
Authors | Massonet, P., Deru, L., Achour, A., Dupont, S., Levin, A., Villari, M. |
Conference Name | 2017 IEEE International Conference on Smart Computing (SMARTCOMP) |
Keywords | actuator security, cloud computing, cloud networks, clouds, Communication networks, composability, Computer architecture, Data analysis, data analytics, data protection, end-to-end security architecture, heterogeneous platforms, Human Behavior, Internet of Things, IoT networks, Metrics, network federation mechanisms, network function virtualisation, network slices protection, NFV, pubcrawl, resilience, Resiliency, security, security of data, security policy enforcement, Sensors, service function chaining, SFC, smart Internet of Things, software architecture, virtualisation |
Abstract | Smart Internet of Things (IoT) applications will rely on advanced IoT platforms that not only provide access to IoT sensors and actuators, but also provide access to cloud services and data analytics. Future IoT platforms should thus provide connectivity and intelligence. One approach to connecting IoT devices, IoT networks to cloud networks and services is to use network federation mechanisms over the internet to create network slices across heterogeneous platforms. Network slices also need to be protected from potential external and internal threats. In this paper we describe an approach for enforcing global security policies in the federated cloud and IoT networks. Our approach allows a global security to be defined in the form of a single service manifest and enforced across all federation network segments. It relies on network function virtualisation (NFV) and service function chaining (SFC) to enforce the security policy. The approach is illustrated with two case studies: one for a user that wishes to securely access IoT devices and another in which an IoT infrastructure administrator wishes to securely access some remote cloud and data analytics services. |
URL | http://ieeexplore.ieee.org/document/7947005/ |
DOI | 10.1109/SMARTCOMP.2017.7947005 |
Citation Key | massonet_end–end_2017 |
- network federation mechanisms
- virtualisation
- Software Architecture
- smart Internet of Things
- SFC
- service function chaining
- sensors
- security policy enforcement
- security of data
- security
- Resiliency
- resilience
- pubcrawl
- NFV
- network slices protection
- network function virtualisation
- actuator security
- Metrics
- IoT networks
- Internet of Things
- Human behavior
- heterogeneous platforms
- end-to-end security architecture
- Data protection
- Data Analytics
- data analysis
- computer architecture
- composability
- Communication networks
- clouds
- cloud networks
- Cloud Computing