Source-linked AI summary

A Survey on Security and Privacy Issues in Edge Computing-Assisted Internet of Things

Abdulmalik Alwarafy, Khaled A. Al-Thelaya, Mohamed Abdallah, Jens Schneider, Mounir Hamdi

arXiv:2008.03252v1cs.NIcs.CR

TL;DR

The paper addresses security and privacy risks in EC-assisted IoT, where edge processing supports IoT but sensitive data and distributed systems create protection challenges. It conducts a comprehensive survey of architectures, attacks, countermeasures, security classifications, and open research directions, concluding with a structured analysis of threats and protections reported in the literature.

  • Problem

    EC-assisted IoT introduces security and privacy challenges because edge nodes store sensitive IoT data and may be more vulnerable than centralized cloud servers.

  • Method

    The paper performs a comprehensive literature survey covering EC-assisted IoT architecture, attacks, countermeasures, security mechanisms, and classifications by services, objectives, and functions.

  • Results

    The survey provides classifications of attacks and threats, analyzes countermeasures and security mechanisms, and relates solutions to EC-assisted IoT security functions and services.

  • Takeaways & Limitations

    The paper identifies which attacks and countermeasures are reported for EC-assisted IoT and highlights threats that remain unresolved.

Abstract

from arXiv · show

Internet of Things (IoT) is an innovative paradigm envisioned to provide massive applications that are now part of our daily lives. Millions of smart devices are deployed within complex networks to provide vibrant functionalities including communications, monitoring, and controlling of critical infrastructures. However, this massive growth of IoT devices and the corresponding huge data traffic generated at the edge of the network created additional burdens on the state-of-the-art centralized cloud computing paradigm due to the bandwidth and resources scarcity. Hence, edge computing (EC) is emerging as an innovative strategy that brings data processing and storage near to the end users, leading to what is called EC-assisted IoT. Although this paradigm provides unique features and enhanced quality of service (QoS), it also introduces huge risks in data security and privacy aspects. This paper conducts a comprehensive survey on security and privacy issues in the context of EC-assisted IoT. In particular, we first present an overview of EC-assisted IoT including definitions, applications, architecture, advantages, and challenges. Second, we define security and privacy in the context of EC-assisted IoT. Then, we extensively discuss the major classifications of attacks in EC-assisted IoT and provide possible solutions and countermeasures along with the related research efforts. After that, we further classify some security and privacy issues as discussed in the literature based on security services and based on security objectives and functions. Finally, several open challenges and future research directions for secure EC-assisted IoT paradigm are also extensively provided.

I. INTRODUCTION

IoT supports diverse vital-sector applications but produces massive data volumes that strain centralized cloud computing, motivating edge-assisted processing. Because edge-assisted IoT handles sensitive data and faces evolving threats, this survey organizes attacks, countermeasures, security issues, and future directions.

  • IoT applications: IoT connects smart devices, sensors, and actuators to exchange service-relevant data across diverse applications and vital sectors.Examples include smart buildings, vehicles, energy management, health monitoring, supply chains, and wearable devices.
  • Motivation: 200 billion connectable IoT devices and sensors were expected by 2020, generating more than 500 ZB of data and burdening centralized cloud resources.The passage identifies bandwidth and resource scarcity as pressures on the centralized cloud paradigm.
  • Motivation: Edge computing places processing and storage near data sources, supporting IoT with reduced latency, flexible access, and enhanced network security.The network edge was expected to process and store 40% of edge-originated data in the future EC-assisted IoT architecture.
  • Security and privacy motivation: EC-assisted IoT manages sensitive data in critical sectors, making devices and networks targets for hacking, cybercriminals, and governmental attacks.Potentially exposed information includes financial accounts, bank cards, location data, and health information.
  • Research gap: Existing literature leaves gaps in comprehensive and current coverage of EC-assisted IoT security and privacy attacks, countermeasures, classifications, and research findings.The survey is proposed to address these shortcomings through a comprehensive literature survey.
  • Contributions: The paper surveys EC-assisted IoT architecture and security, classifies attacks and issues, analyzes countermeasures, and identifies open challenges and future research directions.Its organization covers background, attacks and threats, solutions, security and privacy classifications, and future directions.

II. INTEGRATION OF EDGE COMPUTING AND IOT: EC-ASSISTED IOT

EC-assisted IoT integrates edge computing with IoT to support time-sensitive applications by placing processing, storage, and network resources closer to data-originating devices. The integration improves communication, computation, and storage capabilities but introduces heterogeneity, resource-management, security, privacy, and smart-system challenges.

  • Integration of EC and IoT: EC-assisted IoT combines IoT devices with edge computing to support critical applications requiring enhanced QoS.IoT devices can use both edge and cloud resources, while edge computing is particularly beneficial for time-sensitive applications.
  • Architecture: The standard EC-assisted IoT architecture contains three layers, with IoT devices and sensors serving as EC end users.Compared with conventional IoT, it adds an EC layer; compared with conventional EC, it differs in its treatment of core networks and data-originating things.
  • Architectures and technologies: Cloudlets, vehicular edge computing, edge-cloud, mobile edge computing, and mobile cloud computing support EC-assisted IoT deployments in varying environments.These technologies are used to deploy applications in harsh and rapidly time-varying environments.
  • Advantages: Edge integration reduces latency, bandwidth usage, device power consumption, and packet overhead while improving resource utilization and storage support.Edge servers offload computation, provide storage for resource-constrained devices, and assist load balancing and failure recovery.
  • Challenges: Key challenges include security and privacy, network heterogeneity, resource management, and coordinating smart systems across distributed platforms.Heterogeneous providers, devices, applications, topologies, and physical platforms complicate seamless operation and timely management decisions.

C. Definition of Security and Privacy in the Context of EC-

EC-assisted IoT manages sensitive information across end devices, edge nodes, communication links, and cloud servers, creating security and privacy exposure. The paper surveys threats and countermeasures across these layers and organizes related work by security functions and services.

  • Security and privacy context: EC-assisted IoT handles information from low- to high-sensitivity applications, transmitted between end devices, EC nodes, and cloud infrastructure.Communication may use wired or wireless links, exposing data across multiple system levels.
  • Countermeasures: The survey discusses countermeasures and classifies related research according to security and privacy mechanisms, functions, and services.Its structure pairs attack classifications with corresponding solutions and research efforts.
  • Security and privacy context: Wireless mobile EC environments are vulnerable because the communication medium can be accessed by both authorized users and adversaries.Related surveys examine security issues in environment-perception industrial IoT and UAV-based mobile IoT applications.
  • Threat classification: The paper surveys security and privacy attacks, their sources, and their layers, including EC devices, communication links, EC nodes, and cloud servers.It also cites related surveys for each attack category.
  • Injection attacks: Hardware or software injection can enable bypassed authentication, data theft, false reporting, or compromised database integrity.Node replication is one hardware-injection form, using a malicious node with an existing authorized node’s identifier.
  • Availability threats: Flooding attacks exhaust communication, computation, or storage resources, preventing authorized users from accessing EC-assisted IoT infrastructure.This attack family includes outage attacks, sleep deprivation, and battery draining against EC nodes.

3) Distributed Denial of Service (DDoS) Attacks:

The surveyed attacks target EC-assisted IoT devices and communications through physical compromise, eavesdropping, side-channel leakage, routing manipulation, packet injection, and node compromise. These attacks can expose information, disrupt delivery, or damage system operation.

  • DDoS attacks: DDoS attacks against EC nodes include outage attacks, sleep deprivation, and battery draining, while communication-level DDoS commonly includes jamming.These attacks interrupt normal node operations, overwhelm nodes with requests, deplete batteries, or disrupt communications.
  • Physical attacks: Physical access to EC nodes can expose cryptographic information, enable circuit tampering, and permit operating-system modification.The attack requires attackers to access EC nodes or devices physically.
  • Communication attacks: Eavesdropping on communication links can reveal usernames, passwords, node identifiers, configurations, and shared-network credentials.Captured access or control information may provide crucial knowledge about the network.
  • Privacy attacks: Detecting electromagnetic or acoustic signals from medical devices can leak critical patient and device information even without data transmission.The signals themselves may reveal sensitive information.
  • Communication attacks: Routing attacks redirect or drop packets through black holes, gray holes, wormholes, or Hello Flood behavior.These malicious-node types drain all packets, drain selected packets, relocate recorded packets, or falsely claim neighbor status.
  • Communication attacks: Packet-injection attacks insert fraudulent, modified, or replayed packets that can interfere with receivers and cause system damage or failure.Attackers may inject apparently legitimate packets, alter captured packets, or replicate previously exchanged packets.
  • Node compromise: An unsecured EC node can provide attackers with control over neighboring nodes that communicate or share data with it.The exposure propagates through neighboring-node relationships.

10) Integrity Attacks Against Machine Learning:

Machine-learning components in EC-assisted IoT face causative attacks that manipulate training data and exploratory attacks that exploit vulnerabilities without changing training. The broader environment also raises data-ownership and standardization concerns.

  • Attack types: Causative attacks manipulate or inject misleading training data, whereas exploratory attacks exploit model vulnerabilities without altering the training process.The distinction is based on whether the attacker changes model training.
  • Data integrity attacks: Replay attacks replace current real-time data with previously recorded traffic, increasing EC-node energy and bandwidth consumption.Attackers capture and record traffic for a period before using it to replace current data.
  • Operational protection: Unencrypted log files can damage EC-assisted IoT systems, so developers should record authorization and authentication events alongside application errors.The cited logging examples include successful and unsuccessful authorization or authentication attempts.
  • Malware threats: Mobile botnets, ransomware, and IoT malware can cause data leakage or corruption and even application failure.The paper reports over 1.5 million attacks originating from mobile malware in 2017.
  • Privacy concerns: EC nodes may process personal activities, preferences, and health status, but data remains owned by information owners and may be shared without permission.This creates privacy exposure when network entities or other users receive data without owner authorization.
  • Scope and limitations: Heterogeneous devices and resources lack generally agreed frameworks and standard policies, leaving some security and privacy threats undetected.The limitation applies to EC-assisted IoT implementations involving devices from various vendors.
  • Countermeasures: The paper presents countermeasures and classifications based on security functions and services for the surveyed attack and privacy threats.The discussion organizes related solutions alongside the attacks they address.

1) Countermeasures for Malicious Hardware/Software Injection:

The survey presents layered countermeasures against malicious hardware and software injection in EC-assisted IoT, spanning detection, policy enforcement, trusted updates, encryption, and privacy protection.

  • Detection mechanisms: Side-channel signal analysis detects hardware Trojans and malicious firmware by examining timing, power, temperature, execution time, and device behavior.Trojan activation methods compare Trojan-inserted and Trojan-free circuits using outputs, behavior, and side-channel leakage.
  • Policy enforcement: Policy-violation detection identifies abnormal requests that attempt sleep deprivation or battery-draining attacks on EC nodes.
  • Secure updates: Firmware updates can be delivered remotely or directly, but both approaches require authentication and integrity protection.
  • Trust and cryptography: Trusted-node tables support sharing sensitive information, while encryption strategies protect communication protocols against eavesdropping and routing attacks.Standard encryption can impose memory, delay, and power costs on resource-constrained EC nodes.
  • Privacy protection: Traffic-pattern obfuscation prevents side-channel attacks by inserting fake packets, and distributed information storage supports anonymity by preventing any node from holding complete knowledge.

8) Decentralization:

The decentralization countermeasures distribute data, analysis, and decision-related responsibilities across EC nodes and other entities to protect privacy and reduce dependence on centralized knowledge.

  • Decentralized access control: Access-control strategies prevent attackers or malicious EC nodes from responding to requests by checking whether entities may access, control, modify, or share data.
  • Predeployment analysis: Behavioral testing applies special inputs or signals before operation to identify attacks, simulate them, evaluate impacts, and classify information for logging.
  • Distributed analytics: Statistical data analytics can mitigate attacks that inject outliers into machine-learning training datasets.
  • Encrypted aggregation: Homomorphically encrypted device data can be aggregated at EC nodes before aggregated results are sent to central cloud servers.
  • Distributed storage and learning: Secure data deduplication lets intermediaries access replicated data without learning its contents, while edge-local model training shares models instead of private training datasets.

15) Secure Data Analysis:

Secure data analysis in EC-assisted IoT relies on authentication across trust domains, decentralized transaction regulation, and classification of security research and objectives.

  • Authentication: Mutual authentication is required across different trust domains, including single-domain, cross-domain, and handover authentication.
  • Decentralization: Blockchain provides decentralized transaction rules through voting and consensus, enabling audit-level tracking and removing the need for a central trusted intermediary.
  • Literature classification: Table I classifies discussed papers according to security attacks, threats, solutions, and countermeasures.
  • Transferable research: Some security and privacy concepts, attacks, and solutions developed for centralized cloud-based IoT can also apply to or extend to EC-assisted IoT.
  • Security objectives: Security and privacy are major concerns because edge nodes storing IoT data are more vulnerable than central cloud servers, requiring mechanisms for authentication, access control, and data transmission.
  • Authentication objectives: Authentication involves assigning identities and enabling mutual verification among end users, edge devices, service providers, and data centers.

2) Development of Resources Efficient Authentication Mechanisms:

The survey emphasizes authentication mechanisms that accommodate constrained, distributed, and dynamically changing EC-assisted IoT environments while preserving controlled access to resources and data.

  • Authentication mechanisms: Resource-efficient authentication is needed because constrained edge devices may not support traditional complex authentication mechanisms.One proposed Edge-Fog scheme uses a single long-lived master secret key instead of PKI for mutual authentication with Fog servers.
  • Resource allocation: Security functions can be assigned to sufficiently resourced edge devices to handle computation for other edge devices.
  • Session security: Multi-factor authentication with real-time identity monitoring can maintain authenticated user sessions beyond username-and-password verification.
  • Access control: Access control requires credentials and policies because unrestricted resource access can enable illegal operations on IoT devices.
  • Access control: Transitive access through intermediate devices must be controlled to prevent malicious or unauthorized exposure of resources.
  • Scalable authorization: Dynamically evolving numbers of devices, services, and users make static access-control features obsolete and motivate scalable mechanisms.
  • Data security: Reducing data transmission in EC-assisted IoT decreases exposure to attacks, although data still requires protection during transmission, computation, and storage.

1) Data Storage Auditing and Encryption Latency:

Data outsourcing in decentralized edge environments creates risks of loss, disclosure, modification, and unauthorized access. Auditing, encryption, authentication, and adaptable security mechanisms must remain efficient despite heterogeneous device resources and latency requirements.

  • Data Storage Auditing and Encryption Latency: Data stored on edge servers may be lost, disclosed, or modified, making storage auditing a key security requirement.Auditing policies, third-party auditing, and encryption can support confidentiality and integrity, but must preserve low latency and fast response times.
  • Data Storage Auditing and Encryption Latency: Real-time transmission requires end-to-end encryption and authentication mechanisms adapted to the destination and device capabilities.The surveyed framework uses different encryption complexity for edge nodes and cloud servers.
  • Data Storage Auditing and Encryption Latency: Decentralized edge storage lacks a central authentication or authorization mechanism, increasing the difficulty of securing access to outsourced data.A surveyed layered mechanism uses multifactor access control and allows storage and retrieval without a third party.
  • Data Storage Auditing and Encryption Latency: Security services must be distributed across heterogeneous edge devices according to their resources, location, and availability.The surveyed literature distributes firewalls and intrusion detection across multiple edge devices.
  • Data Storage Auditing and Encryption Latency: Flexible, reconfigurable security solutions are needed because mechanisms suitable for one edge device or application may not apply across distributed infrastructures.A reconfigurable framework is presented as one response to this requirement.

2) Maintain Consistent Reliable Distributed Trust Information in Edge Devices:

Edge-assisted IoT distributes trust responsibilities across edge devices and servers, while privacy-sensitive data and limited device capabilities create persistent security challenges. The literature therefore emphasizes efficient trust management and lightweight cryptographic mechanisms.

  • Maintain Consistent Reliable Distributed Trust Information in Edge Devices: In EC-assisted IoT, edge devices and servers jointly establish and maintain trust information about devices, users, and applications.This differs from cloud computing, where cloud servers primarily collect information, compute, and manage trust.
  • Maintain Consistent Reliable Distributed Trust Information in Edge Devices: Moving trust evaluation from cloud servers to edge devices requires timely, accurate, and consistent updates across distributed entities.One surveyed mechanism lets edge devices perform simple direct estimations and forwards abnormal calculations to edge servers.
  • Maintain Consistent Reliable Distributed Trust Information in Edge Devices: User data, behavior, and location may be leaked, misused, or stolen when processing moves to distributed edge devices.Authorized service providers or edge data centers may also misuse personal data.
  • Maintain Consistent Reliable Distributed Trust Information in Edge Devices: Traditional highly secured trust and cryptographic schemes may exceed the storage and computation capabilities of compact battery-powered edge devices.Future work calls for lightweight algorithms and protocols that balance security, privacy, and time-sensitive QoS requirements.

2) Comprehensive Trust Management Frameworks:

Heterogeneous edge infrastructures create multiple trust domains that require distributed encryption, mutual authentication, and scalable access control. The survey identifies unified, privacy-preserving, and resource-compatible frameworks as continuing research needs.

  • Comprehensive Trust Management Frameworks: Heterogeneous edge infrastructures create multiple trust domains and complicate trust modeling and evaluation across functional entities.Some trust processing has moved from cloud servers to edge nodes because certain edge entities can perform complex tasks.
  • Comprehensive Trust Management Frameworks: Cryptographic schemes must support efficient distributed encryption across heterogeneous trust domains at the network edge.Authentication should assign unique identities and enable mutual authentication among edge entities.
  • Comprehensive Trust Management Frameworks: Privacy-preserving data updates and trust establishment must support new edge entities without requiring third-party knowledge.The survey also calls for dynamic and scalable trust evaluation mechanisms.
  • Comprehensive Trust Management Frameworks: A universal fine-grained trust mechanism should support heterogeneity, scalability, and mobility while remaining implementable on resource-limited IoT devices.Conventional sophisticated trust algorithms may not run directly on tiny edge devices.
  • Comprehensive Trust Management Frameworks: Unified security and privacy mechanisms, standards, platforms, and policies are needed to orchestrate schemes across heterogeneous hardware and software.The desired mechanisms should support integrity and interoperability while resisting security threats.
  • Comprehensive Trust Management Frameworks: Secure privacy-preserving authentication, auditing, and access control remain open problems because users may fear exposure of their actions, locations, or identities.The survey frames simultaneous secure access and user privacy as requiring further investigation.
  • Comprehensive Trust Management Frameworks: Blockchain-based architectures can restrict interactions to trusted devices, while hybrid SDN-blockchain designs can combine decentralized security with continuous network monitoring.Permissioned blockchain and blockchain-based authentication remain proposed research directions.
  • Comprehensive Trust Management Frameworks: Traditional cloud-oriented security methods may not be feasible at the edge because distributed heterogeneous nodes have substantially different computation and storage powers.This constrains efficient data storage, auditing, backup, recovery, and privacy mechanisms.

7) Joint Design:

Future EC-assisted IoT security must jointly address mobility, handover, authentication, scalability, security, and privacy. The survey also highlights adaptive privacy analytics and secure machine learning as open directions for heterogeneous edge environments.

  • Joint Design: Security schemes should jointly design mobility, handover, authentication, scalability, security, and privacy for rapidly changing edge networks.Edge devices may move geographically or join and leave the network quickly, requiring adaptive real-time mechanisms.
  • Joint Design: Machine learning models such as deep learning, reinforcement learning, and deep reinforcement learning may detect and predict malicious applications and adversarial activities at the edge.They are also proposed for intelligent security and privacy mechanisms, including anomaly detection.
  • Joint Design: Distributed and federated learning must prevent private training datasets from leaking during collaborative data analysis.Resource and software heterogeneity makes collaborative learning more susceptible to exposing participants’ training data.
  • Joint Design: Edge data collection can expose privacy-sensitive information such as daily routines, resident counts, and personal habits.Attackers may obtain such information by compromising smart meters and edge devices.
  • Joint Design: Privacy-preserving analytics should automatically and adaptively identify the sensitivity of edge-user data while remaining lightweight.Suggested directions include Privacy by Design, Software Defined Privacy, and SDN-based privacy-preserving routing.
  • Joint Design: The survey synthesizes EC-assisted IoT architecture, attacks, countermeasures, security mechanisms, classifications, and open research directions.Its scope spans security and privacy issues across IoT network layers and security services and objectives.
Loading 2008.03252v1…