Offloading personal security applications to the Network Edge: A mobile user case scenario

This paper discusses some challenges that user mobility imposes over the user-centric protection model against security threats. This model is based on the idea of offloading the security applications from the end user device, and placing them in a trusted network node at the network's edge. Ou...

Descripción completa

Detalles Bibliográficos
Autor: Montero, D
Tipo de recurso: artículo
Estado:Versión publicada
Fecha de publicación:2016
País:Ecuador
Institución:Universidad de Cuenca
Repositorio:Repositorio Universidad de Cuenca
OAI Identifier:oai:dspace.ucuenca.edu.ec:123456789/29104
Acceso en línea:https://www.scopus.com/inward/record.uri?eid=2-s2.0-84994158989&doi=10.1109%2fIWCMC.2016.7577040&partnerID=40&md5=6e5c0190d94817b84a36276db2140d59
http://dspace.ucuenca.edu.ec/handle/123456789/29104
Access Level:acceso abierto
Palabra clave:Fog Computing
Mobility
Nfv
Offloading
Sdn
Security
Virtualization
Descripción
Sumario:This paper discusses some challenges that user mobility imposes over the user-centric protection model against security threats. This model is based on the idea of offloading the security applications from the end user device, and placing them in a trusted network node at the network's edge. Our research perspective is particularly centered around three interrelated mobility challenges, i) the allocation of the security applications 'close' to the user, i.e., on network nodes with enhanced processing capabilities, ii) seamless mobility with negligible disruption of ongoing network connections, and iii) dynamic orchestration and management with support of security applications migration. Based on our arguments, we expose the main requirements and trade-offs to be considered in the attempt to support mobility in such environment. We propose a flexible solution that leverages Software Defined Networking, Network Function Virtualization and Computing at the Network Edge to offer a seamless on-path security protection to mobile users. Our preliminary experiments' results considering a WiFi mobile user show that seamless security migration and mobility are feasible in a simple real scenario. Vertical mobility and more complex use cases scenarios are envisioned for future research.