{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,12]],"date-time":"2026-07-12T10:18:07Z","timestamp":1783851487028,"version":"3.55.0"},"reference-count":31,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2020,5,22]],"date-time":"2020-05-22T00:00:00Z","timestamp":1590105600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Cyber-Phys. Syst."],"published-print":{"date-parts":[[2020,7,31]]},"abstract":"<jats:p>The Internet of Things (IoT) is becoming a backbone of sensing infrastructure to several mission-critical applications such as smart health, disaster management, and smart cities. Due to resource-constrained sensing devices, IoT infrastructures use Edge datacenters (EDCs) for real-time data processing. EDCs can be either static or mobile in nature, and this article considers both of these scenarios. Generally, EDCs communicate with IoT devices in emergency scenarios to evaluate data in real-time. Protecting data communications from malicious activity becomes a key factor, as all the communication flows through insecure channels. In such infrastructures, it is a challenging task for EDCs to ensure the trustworthiness of the data for emergency evaluations. The current communication security pattern of \u201ccommunication before authentication\u201d leaves a \u201cblack hole\u201d for intruders to become part of communication processes without authentication. To overcome this issue and to develop security infrastructures for IoT and distributed Edge datacenters, this article proposes a user-centric security solution. The proposed security solution shifts from a network-centric approach to a user-centric security approach by authenticating users and devices before communication is established. A trusted controller is initialized to authenticate and establishes the secure channel between the devices before they start communication between themselves. The centralized controller draws a perimeter for secure communications within the boundary. Theoretical analysis and experimental evaluation of the proposed security model show that it not only secures the communication infrastructure but also improves the overall network performance.<\/jats:p>","DOI":"10.1145\/3351882","type":"journal-article","created":{"date-parts":[[2020,5,25]],"date-time":"2020-05-25T21:26:46Z","timestamp":1590442006000},"page":"1-19","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":16,"title":["A User-centric Security Solution for Internet of Things and Edge Convergence"],"prefix":"10.1145","volume":"4","author":[{"given":"Deepak","family":"Puthal","sequence":"first","affiliation":[{"name":"Newcastle University, Newcastle upon Tyne, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7986-4244","authenticated-orcid":false,"given":"Laurence T.","family":"Yang","sequence":"additional","affiliation":[{"name":"St. Francis Xavier University, Antigonish, NS, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Schahram","family":"Dustdar","sequence":"additional","affiliation":[{"name":"TU Wien, Vienna, Austria"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhenyu","family":"Wen","sequence":"additional","affiliation":[{"name":"Newcastle University, Newcastle upon Tyne, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Song","family":"Jun","sequence":"additional","affiliation":[{"name":"Chinese University of Geosciences, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Aad van","family":"Moorsel","sequence":"additional","affiliation":[{"name":"Newcastle University, Newcastle upon Tyne, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rajiv","family":"Ranjan","sequence":"additional","affiliation":[{"name":"Newcastle University, Newcastle upon Tyne, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,5,22]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"V. Lesser C. L. Ortiz Jr and M. Tambe (Eds.). 2012. Distributed Sensor Networks: A Multiagent Perspective 9. Springer Science 8 Business Media 2012. V. Lesser C. L. Ortiz Jr and M. Tambe (Eds.). 2012. Distributed Sensor Networks: A Multiagent Perspective 9. Springer Science 8 Business Media 2012."},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2010.05.010"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2013.01.010"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/2937755"},{"key":"e_1_2_1_5_1","volume-title":"Proceedings of the IEEE International Conference on Pervasive Computing and Communications Workshops (PerCom Workshops\u201917)","author":"Dorri A.","unstructured":"A. Dorri , S. Kanhere , R. Jurdak , and P. Gauravaram . 2017. Blockchain for IoT security and privacy: The case study of a smart home . In Proceedings of the IEEE International Conference on Pervasive Computing and Communications Workshops (PerCom Workshops\u201917) . 618--623. A. Dorri, S. Kanhere, R. Jurdak, and P. Gauravaram. 2017. Blockchain for IoT security and privacy: The case study of a smart home. In Proceedings of the IEEE International Conference on Pervasive Computing and Communications Workshops (PerCom Workshops\u201917). 618--623."},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2011.291"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCE.2017.2714744"},{"key":"e_1_2_1_8_1","volume-title":"Proceedings of the 3rd ACM Conference on Computer and Communications Security. 31--37","author":"Steiner M.","unstructured":"M. Steiner , G. Tsudik , and M. Waidner . 1996. Diffie-Hellman key distribution extended to group communication . In Proceedings of the 3rd ACM Conference on Computer and Communications Security. 31--37 . M. Steiner, G. Tsudik, and M. Waidner. 1996. Diffie-Hellman key distribution extended to group communication. In Proceedings of the 3rd ACM Conference on Computer and Communications Security. 31--37."},{"key":"e_1_2_1_9_1","unstructured":"Cloud Security Alliance (CSA). Retrieved from https:\/\/cloudsecurityalliance.org\/ group\/software-defined-perimeter. Cloud Security Alliance (CSA). Retrieved from https:\/\/cloudsecurityalliance.org\/ group\/software-defined-perimeter."},{"key":"e_1_2_1_10_1","first-page":"1","article-title":"2011. A mobile and portable trusted computing platform","volume":"1","author":"Nepal S.","year":"2011","unstructured":"S. Nepal , J. Zic , D. Liu , and J. Jang . 2011. A mobile and portable trusted computing platform . EURASIP J. Wirel. Commun. Netw. 1 , ( 2011 ), 1 -- 19 . S. Nepal, J. Zic, D. Liu, and J. Jang. 2011. A mobile and portable trusted computing platform. EURASIP J. Wirel. Commun. Netw. 1, (2011), 1--19.","journal-title":"EURASIP J. Wirel. Commun. Netw."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCC.2016.63"},{"key":"e_1_2_1_12_1","volume-title":"Proceedings of the 14th IEEE Consumer Communications 8 Networking Conference (CCNC\u201917)","author":"Minoli D.","unstructured":"D. Minoli , K. Sohraby , and J. Kouns . 2017. IoT security (IoTSec) considerations, requirements, and architectures . In Proceedings of the 14th IEEE Consumer Communications 8 Networking Conference (CCNC\u201917) . 1006--1007. D. Minoli, K. Sohraby, and J. Kouns. 2017. IoT security (IoTSec) considerations, requirements, and architectures. In Proceedings of the 14th IEEE Consumer Communications 8 Networking Conference (CCNC\u201917). 1006--1007."},{"key":"e_1_2_1_13_1","volume-title":"Proceedings of the 4th International Conference on Cyber Security and Cloud Computing (CSCloud\u201917)","author":"Mukherjee B.","unstructured":"B. Mukherjee , R. Neupane , and P. Calyam . 2017. End-to-end IoT security middleware for cloud-fog communication . In Proceedings of the 4th International Conference on Cyber Security and Cloud Computing (CSCloud\u201917) . 151--156. B. Mukherjee, R. Neupane, and P. Calyam. 2017. End-to-end IoT security middleware for cloud-fog communication. In Proceedings of the 4th International Conference on Cyber Security and Cloud Computing (CSCloud\u201917). 151--156."},{"key":"e_1_2_1_14_1","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1002\/dac.3477","article-title":"2018. Cryptanalysis of an identity based authenticated key exchange protocol","volume":"31","author":"Hatri Y.","year":"2018","unstructured":"Y. Hatri , A. Otmani , and K. Guenda . 2018. Cryptanalysis of an identity based authenticated key exchange protocol . Int. J. Commun. Syst. 31 , 3 ( 2018 ), 1--8. Y. Hatri, A. Otmani, and K. Guenda. 2018. Cryptanalysis of an identity based authenticated key exchange protocol. Int. J. Commun. Syst. 31, 3 (2018), 1--8.","journal-title":"Int. J. Commun. Syst."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2017.62"},{"key":"e_1_2_1_16_1","volume-title":"Proceedings of the 37th International Conference on Distributed Computing Systems (ICDCS\u201917)","author":"Miettinen M.","unstructured":"M. Miettinen , S. Marchal , I. Hafeez , N. Asokan , A. Sadeghi , and S. Tarkoma . 2017. IoT sentinel: Automated device-type identification for security enforcement in IoT . In Proceedings of the 37th International Conference on Distributed Computing Systems (ICDCS\u201917) . 2177--2184. M. Miettinen, S. Marchal, I. Hafeez, N. Asokan, A. Sadeghi, and S. Tarkoma. 2017. IoT sentinel: Automated device-type identification for security enforcement in IoT. In Proceedings of the 37th International Conference on Distributed Computing Systems (ICDCS\u201917). 2177--2184."},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2017.284"},{"key":"e_1_2_1_18_1","volume-title":"Proceedings of the International Conference on Communications Workshop. 1871--1876","author":"Al-Ayyoub M.","unstructured":"M. Al-Ayyoub , Y. Jararweh , E. Benkhelifa , M. Vouk , and A. Rindos . Sdsecurity: A software defined security experimental framework . In Proceedings of the International Conference on Communications Workshop. 1871--1876 . M. Al-Ayyoub, Y. Jararweh, E. Benkhelifa, M. Vouk, and A. Rindos. Sdsecurity: A software defined security experimental framework. In Proceedings of the International Conference on Communications Workshop. 1871--1876."},{"key":"e_1_2_1_19_1","volume-title":"Proceedings of the 3rd International Conference on Future Internet of Things and Cloud (FiCloud\u201915)","author":"Darabseh A.","unstructured":"A. Darabseh , M. Al-Ayyoub , Y. Jararweh , E. Benkhelifa , M. Vouk , and A. Rindos . 2015. SDDC: A software defined datacenter experimental framework . In Proceedings of the 3rd International Conference on Future Internet of Things and Cloud (FiCloud\u201915) . 189--194. A. Darabseh, M. Al-Ayyoub, Y. Jararweh, E. Benkhelifa, M. Vouk, and A. Rindos. 2015. SDDC: A software defined datacenter experimental framework. In Proceedings of the 3rd International Conference on Future Internet of Things and Cloud (FiCloud\u201915). 189--194."},{"key":"e_1_2_1_20_1","first-page":"3","article-title":"2017. SEEN: A selective encryption method to ensure confidentiality for big sensing data streams","volume":"5","author":"Puthal D.","year":"2017","unstructured":"D. Puthal , X. Wu , S. Nepal , R. Ranjan , and J. Chen . 2017. SEEN: A selective encryption method to ensure confidentiality for big sensing data streams . IEEE Trans. Big Data 5 , 3 ( 2017 ). DOI:10.1109\/TBDATA.2017.2702172 10.1109\/TBDATA.2017.2702172 D. Puthal, X. Wu, S. Nepal, R. Ranjan, and J. Chen. 2017. SEEN: A selective encryption method to ensure confidentiality for big sensing data streams. IEEE Trans. Big Data 5, 3 (2017). DOI:10.1109\/TBDATA.2017.2702172","journal-title":"IEEE Trans. Big Data"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2011.2156790"},{"key":"e_1_2_1_22_1","first-page":"2","article-title":"2018. Pricing for profit in internet of things","volume":"6","author":"Ghosh A.","year":"2018","unstructured":"A. Ghosh and S. Sarkar . 2018. Pricing for profit in internet of things . IEEE Trans. Netw. Sci. Eng. 6 , 2 ( 2018 ). DOI:10.1109\/TNSE.2018.2796592 10.1109\/TNSE.2018.2796592 A. Ghosh and S. Sarkar. 2018. Pricing for profit in internet of things. IEEE Trans. Netw. Sci. Eng. 6, 2 (2018). DOI:10.1109\/TNSE.2018.2796592","journal-title":"IEEE Trans. Netw. Sci. Eng."},{"key":"e_1_2_1_23_1","volume-title":"http:\/\/www.cs.ox.ac.uk\/people\/cas.cremers\/scyther\/. Accessed","year":"2018","unstructured":"Scyther. http:\/\/www.cs.ox.ac.uk\/people\/cas.cremers\/scyther\/. Accessed in February 2018 . Scyther. http:\/\/www.cs.ox.ac.uk\/people\/cas.cremers\/scyther\/. Accessed in February 2018."},{"key":"e_1_2_1_24_1","volume-title":"http:\/\/www.contiki-os.org. Accessed","year":"2018","unstructured":"Contiki operating system. http:\/\/www.contiki-os.org. Accessed in February 2018 . Contiki operating system. http:\/\/www.contiki-os.org. Accessed in February 2018."},{"key":"e_1_2_1_25_1","volume-title":"Proceedings of the 31st IEEE Conference on Local Computer Networks. 641--648","author":"Osterlind F.","unstructured":"F. Osterlind , A. Dunkels , J. Eriksson , N. Finne , and T. Voigt . 2006. Cross-level sensor network simulation with COOJA . In Proceedings of the 31st IEEE Conference on Local Computer Networks. 641--648 . F. Osterlind, A. Dunkels, J. Eriksson, N. Finne, and T. Voigt. 2006. Cross-level sensor network simulation with COOJA. In Proceedings of the 31st IEEE Conference on Local Computer Networks. 641--648."},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.5555\/820264.820485"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSG.2012.2212730"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2013.2295032"},{"key":"e_1_2_1_29_1","first-page":"1","article-title":"2008. Scalable and efficient key management for heterogeneous sensor networks","volume":"45","author":"Kausar F.","year":"2008","unstructured":"F. Kausar , S. Hussain , L. T. Yang , and A. Masood . 2008. Scalable and efficient key management for heterogeneous sensor networks . J. Supercomput. 45 , 1 ( 2008 ), 44--65. F. Kausar, S. Hussain, L. T. Yang, and A. Masood. 2008. Scalable and efficient key management for heterogeneous sensor networks. J. Supercomput. 45, 1 (2008), 44--65.","journal-title":"J. Supercomput."},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2015.11.026"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2016.08.093"}],"container-title":["ACM Transactions on Cyber-Physical Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3351882","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3351882","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:13:03Z","timestamp":1750201983000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3351882"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,5,22]]},"references-count":31,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2020,7,31]]}},"alternative-id":["10.1145\/3351882"],"URL":"https:\/\/doi.org\/10.1145\/3351882","relation":{},"ISSN":["2378-962X","2378-9638"],"issn-type":[{"value":"2378-962X","type":"print"},{"value":"2378-9638","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,5,22]]},"assertion":[{"value":"2019-01-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2019-07-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-05-22","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}