Source-linked AI summary

Mobile Edge Computing, Fog et al.: A Survey and Analysis of Security Threats and Challenges

Rodrigo Roman, Javier Lopez, Masahiro Mambo

arXiv:1602.00484v2cs.CRcs.NI

TL;DR

Cloud centralization cannot meet some latency, context-awareness, and mobility requirements, while security research on emerging edge paradigms remains compartmentalized. The paper holistically analyzes their shared and distinct threats, challenges, and mechanisms, concluding that paradigms should consider advances from one another.

  • Problem

    Cloud computing cannot meet certain latency, jitter, context-awareness, and mobility requirements, while security analyses usually focus on one edge paradigm and overlook cross-paradigm synergies.

  • Method

    The paper holistically analyzes common features, differences, threats, challenges, and security mechanisms across fog, mobile edge, and mobile cloud computing.

  • Results

    The reviewed security literature contains very few studies specifically designed for fog computing and mobile edge computing compared with mobile cloud computing.

  • Takeaways & Limitations

    Research on edge-paradigm security should not be compartmentalized; each paradigm should consider advances in the others.

  • Takeaways & Limitations

    Security mechanisms may require adaptation to each paradigm’s specific infrastructure nuances, including mobile-operator infrastructure and user-owned edge data centers.

Abstract

from arXiv · show

For various reasons, the cloud computing paradigm is unable to meet certain requirements (e.g. low latency and jitter, context awareness, mobility support) that are crucial for several applications (e.g. vehicular networks, augmented reality). To fulfil these requirements, various paradigms, such as fog computing, mobile edge computing, and mobile cloud computing, have emerged in recent years. While these edge paradigms share several features, most of the existing research is compartmentalised; no synergies have been explored. This is especially true in the field of security, where most analyses focus only on one edge paradigm, while ignoring the others. The main goal of this study is to holistically analyse the security threats, challenges, and mechanisms inherent in all edge paradigms, while highlighting potential synergies and venues of collaboration. In our results, we will show that all edge paradigms should consider the advances in other paradigms.

1. Introduction

Cloud centralization increases latency and jitter and limits access to local context, motivating edge paradigms. Despite shared features, edge-security research remains compartmentalized, prompting this study’s holistic analysis.

  • Cloud limitations: Centralized cloud resources increase latency and jitter because data centers are physically distant from end users.Cloud services also lack direct access to precise location, local network conditions, and mobility behavior.
  • Emergence of edge paradigms: Fog, mobile edge, and mobile cloud computing emerged to provide cloud-like capabilities closer to the network edge.Edge data centers can operate autonomously, cooperate, and connect hierarchically with traditional cloud infrastructure.
  • Research gap: Although edge paradigms share features, architectures, protocols, services, and mechanisms are usually designed for only one paradigm.Their differences include mobile-network-operator infrastructure and user-owned edge data centers.
  • Research gap: Security research is especially siloed, with most studies focusing on individual paradigms rather than interdisciplinary analysis.Existing work has identified threats and developed mechanisms, but rarely examines synergies across paradigms.
  • Study scope: This study holistically analyzes common features, differences, threats, security mechanisms, challenges, and potential synergies across edge paradigms.Its organization covers paradigm characteristics, comparative analysis, and security issues affecting the edge ecosystem.

2. Overview of Edge Paradigms

Fog, MEC, and MCC place cloud-like computation, storage, or networking nearer to users through different architectures and delegation strategies. Their applications span IoT, mobile services, augmented interfaces, and edge-assisted computation.

  • Fog Computing: Fog computing extends or redefines cloud services across hierarchical infrastructures ranging from resource-poor edge devices to more powerful servers.Its applications include IoT analytics, smart infrastructure management, and low-latency augmented interfaces.
  • Fog Computing: Fog computing supports services such as vehicle-to-vehicle and vehicle-to-infrastructure systems, including shared parking applications.Standardization and architecture efforts address heterogeneous technologies, virtualization, and traffic engineering.
  • Fog Computing: Fog deployments have been proposed with APIs exposing local network statistics and sensor data to virtual machines, including airborne fog collaborations.These proposals illustrate how fog nodes can provide localized information and services.
  • Mobile Edge Computing: Mobile Edge Computing executes services within mobile-network infrastructure, with MEC servers deployed at locations such as base stations and aggregation sites.MEC targets low latency, high bandwidth, radio-network information, and location awareness, while also hosting NFV and SDN services.
  • Mobile Cloud Computing: Mobile Cloud Computing delegates storage and computationally intensive tasks from resource-limited mobile devices to remote resources, increasingly including edge cloudlets.Cloudlets are small nearby cloud infrastructures, and tests reported 51% improved response time and up to 42% lower energy consumption versus centralized clouds.

3. Analysis of Features and Synergies

Edge paradigms differ in properties and infrastructure, but share the goal of bringing cloud-like capabilities to the network edge. Their common virtualization and connectivity features provide a basis for comparison and potential synergies.

  • Comparative analysis: Table 2 compares the main properties of major edge paradigms with those of centralized cloud computing.The comparison combines properties introduced earlier with information gathered from existing reports and research documents.
  • Similarities: Despite different backgrounds, edge paradigms share the goal of bringing cloud computing-like capabilities to the network edge.They support multi-tenant virtualization infrastructures such as fog nodes, MEC servers, and cloudlets, accessible through broadband networks.
  • Similarities: Mobility is a shared feature across edge paradigms.The supplied passage introduces mobility as a commonality, while the accompanying figure labels show 5G infrastructure, proximate fog nodes, routers, and local servers.

ENTITIES

Edge paradigms share decentralized, proximity-based architectures and benefits, yet differ in deployment scope, infrastructure, and application control. Their common challenges create opportunities to adapt mechanisms across paradigms while preserving paradigm-specific requirements.

  • Shared features: Edge paradigms support mobility through higher-level mobility entities and mechanisms for migrating virtual machines.
  • Shared benefits: Proximity to edge data centers provides low and predictable latency and jitter, local context awareness, scalability, and high service availability.Availability is supported by local node redundancy and, in some paradigms, edge data centers hosted within communication infrastructure.
  • Differences: MEC deploys edge platforms in mobile-network infrastructure, whereas fog computing can use user-managed servers, access points, routers, and gateways, and MCC is more distributed.
  • Challenges: Decentralization and proximity bring benefits but also create common challenges involving mobility and distributed service infrastructures.
  • Collaboration: Shared solutions should be adapted to each paradigm’s protocols and use cases rather than developed in isolation.
  • Synergies: VM distribution, replication, migration, and merging mechanisms developed for fog computing and MEC can be adapted to any edge paradigm when local information is available.Superfluid-cloud advances also support deploying thousands of minimalistic VMs on commodity servers with minimal latency.
  • Synergies: Resource offloading, mobility prediction, context awareness, application scenarios, and supporting services developed for one paradigm may be adapted to related paradigms, subject to protocol differences.The network-store concept illustrates a supporting service whose digital distribution-platform architecture may be reusable even when its slices are not directly portable.
  • Collaboration: Open APIs and middleware can connect fog computing and MEC, enabling applications that use both paradigms despite separate standards and infrastructures.

4. Security Threats

Edge-paradigm security must address threats arising from underlying technologies, novel distributed interactions, heterogeneous infrastructure, and application scenarios such as IoT. The survey classifies threats across paradigms and examines how ownership, hardware, and trust-domain requirements shape their impact and mitigation.

  • Security scope: Edge security must orchestrate protections across wireless, distributed, peer-to-peer, and virtualization technologies rather than securing each building block independently.The survey stresses that securing individual enabling technologies does not guarantee security for the whole system.
  • Security requirements: Distributed edge environments require autonomous security mechanisms because centralized control may be unavailable and security processing must respect latency and infrastructure constraints.The cited discussion specifically mentions malicious attacks, intermittent connectivity, distributed applications, and microserver limitations.
  • Inherited threats: Edge paradigms inherit significant threats from their building blocks and application scenarios, with IoT combining multiple technology layers and global connectivity into a considerable attack surface.These inherited risks affect paradigms that use IoT, including fog computing.
  • Threat classification: The survey analyzes threats by enumerating important edge assets and classifying attacks in a framework intended to apply across edge paradigms.The classification is summarized in Table 4 and followed by paradigm-specific particularities.
  • Impact and ownership: A successful attack on centrally managed infrastructure can expand across the ecosystem, whereas compromise of a small-company edge data center has a more limited reach.The comparison is tied to attacker privilege escalation and the scope of the compromised infrastructure.
  • Hardware and operations: Microserver-based deployments may lack established secure virtualization support and experienced staff, leaving security policies, role separation, and log storage inadequately maintained.The passage contrasts these limitations with commodity servers that can reuse cloud security mechanisms.
  • Authorization: Each trust domain needs authorization infrastructure capable of disseminating, storing, and enforcing local policies while processing credentials across established trust relationships.The infrastructure may also account for factors such as geographical location and resource ownership.

5. Security Challenges and Opportunities

The survey reviews security research across edge paradigms and related fields, identifying reusable mechanisms and open problems. It emphasizes cross-paradigm synergies because existing security research is often isolated within individual paradigms.

  • Scope of analysis: The state-of-the-art analysis covers security research across all edge paradigms, related paradigms, existing shortcomings, and potential research areas.The authors explicitly include cloud, grid, and peer-to-peer computing among the related fields considered.
  • Research direction: The review uses cross-paradigm comparison to identify collaboration opportunities rather than treating each edge paradigm as an isolated security domain.This follows from the stated analysis of potential synergies across the paradigms.
  • Potential synergies: Decentralized peer-to-peer mechanisms and technology-independent protocols may be adapted to edge environments when their assumptions match edge requirements.The survey identifies decentralized communication and independence from underlying implementation technologies as enabling conditions.

5.1. Specific challenges and promising solutions

Specific security challenges include cross-domain identity, authentication, access control, network protection, trust management, and intrusion detection. The survey identifies mechanisms from edge and related paradigms that could address these challenges, while noting unresolved centralization and distribution issues.

  • Identity and authentication: No research work had yet addressed identifying and authenticating members of a worldwide edge-data-center infrastructure owned by different companies and individuals.The survey points to federated-cloud identity management and peer-to-peer mutual authentication as possible sources of solutions.
  • Identity and authentication: Inter-cloud SSO standards and decentralized peer-to-peer mutual authentication offer approaches compatible with edge infrastructures.The cited examples include SAML, OpenID, and authentication without a central authentication server.
  • User authentication: Centralized user authentication in mobile cloud computing is limited when its authentication server must remain continuously accessible.The passage contrasts this requirement with the availability conditions of edge environments.
  • Context and mobility: Location-specific and situational authentication schemes exploit the proximity of edge data centers to end users.Related mechanisms from wireless sensor networks and IoT may also be adapted to edge paradigms.
  • Context and mobility: Secure handover authentication can support migration between regions, but existing mobile-cloud protocols commonly depend on centralized cloud authentication servers.The survey identifies this dependency as leaving room for improvement.
  • Access control: Fine-grained access control remains sparsely studied, with proposals covering cloudlet ACLs, MEC policy components, fog policy management, and federated role mapping.The cited approaches span personal cloudlets, MEC small cells, fog computing, and multicloud environments.
  • Network security: SDN and NFV can isolate traffic, direct flows toward security devices, and reconfigure networks in real time, but both introduce security challenges of their own.These technologies also address management of distributed virtualized network infrastructure.
  • Trust management: Trust research is limited and concentrated mainly on mobile cloud computing, despite the importance of trust for edge paradigms.Existing work includes peer-to-peer trust, user call-pattern analysis, and centralized edge-data-center reputation.

5.2. Summary

The review finds that edge-security research is uneven across paradigms and that existing mechanisms may provide foundations for new solutions. It also identifies adaptation requirements and several open security priorities.

  • Few reviewed studies specifically target fog computing and mobile edge computing, while mobile cloud computing has received more attention.Many mobile-cloud studies address distributed mobile-device clusters rather than edge data centres or cloudlets.
  • Existing security mechanisms can serve as foundations for new mechanisms or be reused and adapted across edge paradigms.Adaptation must account for paradigm-specific features, including mobile network operator infrastructures and user-owned edge data centres.
  • Future work must assess denial-of-service attacks, rogue data centres, malicious virtual machines, and their detection or neutralisation by intrusion detection and prevention systems.
  • Edge ecosystems need identity-management support, consistent network configuration and access-control policies, trust-management analysis, and lower-latency security mechanisms.The review also calls for studying privacy impacts and the security of mobile entities.
  • Secure software engineering, security and usability, fault tolerance and resilience, and forensics remain neglected research areas.Usable security can limit misconfigurations, while fault tolerance and forensics support continued operation and prosecution of malicious adversaries.

6. Conclusions

The study holistically analyses security threats, challenges, and mechanisms across fog, mobile edge, and mobile cloud computing. It concludes that edge-security research should not be compartmentalised, while emphasising that the field remains in its infancy with multiple open issues.

  • The study analyses common features and problems across edge paradigms, then examines their threats and security mechanisms.
  • Research should not be compartmentalised; all edge paradigms should consider advances in the other paradigms.
  • Edge-paradigm security remains in its infancy, leaving multiple open issues for future consideration.
Loading 1602.00484v2…