{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T17:25:15Z","timestamp":1781112315405,"version":"3.54.1"},"reference-count":35,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2023,8,21]],"date-time":"2023-08-21T00:00:00Z","timestamp":1692576000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key R&D Program of China","doi-asserted-by":"crossref","award":["2020YFB1006003"],"award-info":[{"award-number":["2020YFB1006003"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["62172119, 62002184, 62162017"],"award-info":[{"award-number":["62172119, 62002184, 62162017"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Guangdong Key R&D Program","award":["2020B0101090002"],"award-info":[{"award-number":["2020B0101090002"]}]},{"name":"Guangxi Natural Science Foundation","award":["2018GXNSFDA281054, 2019GXNSFGA245004, 2019GXNSFFA245015"],"award-info":[{"award-number":["2018GXNSFDA281054, 2019GXNSFGA245004, 2019GXNSFFA245015"]}]},{"name":"PCNL Major Key Project","award":["PCL2021A09-4, PCL2021A02-3"],"award-info":[{"award-number":["PCL2021A09-4, PCL2021A02-3"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Internet Technol."],"published-print":{"date-parts":[[2023,8,31]]},"abstract":"<jats:p>Edge networks are providing services for an increasing number of companies, and they can be used for communication between edge devices and edge gateways. However, the performance of edge devices varies greatly, and it is not easy to upgrade low-performance edge devices. Therefore, cyber attackers can use the vulnerability of edge devices to implement advanced persistent threat attacks. This article proposes a network verification framework for edge networks that can minimize the upgrades needed to strengthen edge network security. First, the communication parties use the data transmitted by the given edge network. Our method uses our proposed PacketVerifier to attach verification information to the packet after it is sent and to verify and restore the packet before it reaches the receiver. Second, due to the performance requirements of edge networks, we design a new data processing structure, namely, a sliding window double ring, to improve the performance of strict sequential protocols in parallel validation. Finally, experimental simulations show that our parallel processing algorithm has good performance in terms of network bandwidth compared with two existing packet processing algorithms. Furthermore, the proposed packet with verification information is compatible with the existing network topology, which helps PacketVerifier establish trustworthy transmission in a zero-trust environment.<\/jats:p>","DOI":"10.1145\/3511901","type":"journal-article","created":{"date-parts":[[2022,3,25]],"date-time":"2022-03-25T06:21:15Z","timestamp":1648189275000},"page":"1-23","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["A Highly Compatible Verification Framework with Minimal Upgrades to Secure an Existing Edge Network"],"prefix":"10.1145","volume":"23","author":[{"given":"Zhenyu","family":"Li","sequence":"first","affiliation":[{"name":"Guilin University of Electronic Technology, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yong","family":"Ding","sequence":"additional","affiliation":[{"name":"Guilin University of Electronic Technology, China and Peng Cheng Laboratory, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Honghao","family":"Gao","sequence":"additional","affiliation":[{"name":"Shanghai University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bo","family":"Qu","sequence":"additional","affiliation":[{"name":"Peng Cheng Laboratory, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yujue","family":"Wang","sequence":"additional","affiliation":[{"name":"Guilin University of Electronic Technology, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jun","family":"Li","sequence":"additional","affiliation":[{"name":"China Industrial Control Systems Cyber Emergency Response Team, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,8,21]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2020.07.002"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2019.2891891"},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3015432"},{"issue":"5","key":"e_1_3_2_5_2","doi-asserted-by":"crossref","first-page":"3606","DOI":"10.1109\/TII.2019.2941724","article-title":"Authentic caller: Self-enforcing authentication in a next-generation network","volume":"16","author":"Azad Muhammad Ajmal","year":"2020","unstructured":"Muhammad Ajmal Azad, Samiran Bag, Charith Perera, Mahmoud Barhamgi, and Feng Hao. 2020. Authentic caller: Self-enforcing authentication in a next-generation network. IEEE Trans. Industr. Inform. 16, 5 (2020), 3606\u20133615.","journal-title":"IEEE Trans. Industr. Inform."},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSUSC.2020.2968589"},{"key":"e_1_3_2_7_2","doi-asserted-by":"crossref","unstructured":"T. Dierks and E. Rescorla. 2008. RFC 5246: The transport layer security (TLS) protocol version 1.2. RFC . Retrieved from https:\/\/www.rfc-editor.org\/rfc\/rfc5246.html.","DOI":"10.17487\/rfc5246"},{"key":"e_1_3_2_8_2","unstructured":"DPDK Project Group. 2021. About DPDK. Retrieved from https:\/\/www.dpdk.org\/about\/."},{"key":"e_1_3_2_9_2","unstructured":"FireEye. 2021. Threat Intelligence Reports by Industry. Retrieved from https:\/\/www.fireeye.com\/current-threats\/reports-by-industry.html."},{"key":"e_1_3_2_10_2","first-page":"1","article-title":"Combinatorial analysis for securing IoT-assisted industry 4.0 applications from vulnerability-based attacks","volume":"3203","author":"George Gemini","year":"2020","unstructured":"Gemini George and Sabu M. Thampi. 2020. Combinatorial analysis for securing IoT-assisted industry 4.0 applications from vulnerability-based attacks. IEEE Trans. Industr. Inform. 3203, c (2020), 1\u201312.","journal-title":"IEEE Trans. Industr. Inform."},{"key":"e_1_3_2_11_2","doi-asserted-by":"crossref","unstructured":"B. Gleeson A. Lin J. Heinanen G. Armitage and A. Malis. 2000. RFC2764: A framework for IP based virtual private networks. RFC . Retrieved from https:\/\/www.rfc-editor.org\/rfc\/rfc2764.html.","DOI":"10.17487\/rfc2764"},{"key":"e_1_3_2_12_2","unstructured":"Gowenfawr. 2020. How does TLS traffic impact firewalls? Retrieved from https:\/\/security.stackexchange.com\/questions\/207906\/how-does-tls-traffic-impact-firewalls."},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2019.2903342"},{"key":"e_1_3_2_14_2","unstructured":"Hyperledger. 2020. Hyperledger Fabric BlockChain. Retrieved from https:\/\/github.com\/hyperledger\/fabric\/blob\/master\/docs\/source\/blockchain.rst."},{"issue":"3","key":"e_1_3_2_15_2","first-page":"1","article-title":"Review and analysis of cryptography techniques","volume":"4","author":"Jirwan Nitin","year":"2013","unstructured":"Nitin Jirwan, Ajay Singh, and Sandip Vijay. 2013. Review and analysis of cryptography techniques. Int. J. Sci. Eng. Res. 4, 3 (2013), 1\u20136.","journal-title":"Int. J. Sci. Eng. Res."},{"key":"e_1_3_2_16_2","first-page":"1","article-title":"ShadowPLCs: A novel scheme for remote detection of industrial process control attacks","volume":"5971","author":"Junjiao Liu","year":"2020","unstructured":"Liu Junjiao, Xiaodong Lin, Chen Xin, Wen Hui, Hong Li, Hu Yan, Sun Jiawei, Shi Zhiqiang, and Limin Sun. 2020. ShadowPLCs: A novel scheme for remote detection of industrial process control attacks. IEEE Trans. Depend. Secure Comput. 5971, c (2020), 1\u201316.","journal-title":"IEEE Trans. Depend. Secure Comput."},{"key":"e_1_3_2_17_2","unstructured":"Kaspersky. 2021. Kaspersky ICS Cert. Retrieved from https:\/\/ics-cert.kaspersky.com."},{"key":"e_1_3_2_18_2","unstructured":"Kaspersky. 2021. Kaspersky ICS Cert. Threat landscape for industrial automation systems\u2014Statistics for H2 2020. Retrieved from https:\/\/ics-cert.kaspersky.com\/reports\/2021\/03\/25\/threat-landscape-for-industrial-automation-systems-statistics-for-h2-2020\/."},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.2995677"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2020.3006885"},{"key":"e_1_3_2_21_2","unstructured":"Ben Nahorney. 2019. Threats in encrypted traffic. Retrieved from https:\/\/blogs.cisco.com\/security\/threats-in-encrypted-traffic."},{"key":"e_1_3_2_22_2","unstructured":"National Institute of Standards and Technology. 2020. Zero trust architecture\u2014NIST special publication 800-207. Retrieved from https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-207.pdf."},{"issue":"11","key":"e_1_3_2_23_2","first-page":"1","article-title":"Improving energy efficiency on SDN control-plane using multi-core controllers","volume":"14","author":"Oliveira Tadeu F.","year":"2021","unstructured":"Tadeu F. Oliveira, Samuel Xavier-De-souza, and Luiz F. Silveira. 2021. Improving energy efficiency on SDN control-plane using multi-core controllers. Energies 14, 11 (2021), 1\u201320.","journal-title":"Energies"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2020.3009103"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2021.01.018"},{"key":"e_1_3_2_26_2","unstructured":"David E. Sanger Clifford Krauss and Nicole Perlroth. 2021. Cyberattack Forces a Shutdown of a Top U.S. Pipeline. Retrieved from https:\/\/www.nytimes.com\/2021\/05\/08\/us\/politics\/cyberattack-colonial-pipeline.html."},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2018.2857811"},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.101666"},{"key":"e_1_3_2_29_2","unstructured":"Vmware. 2021. VMware ESXi. Retrieved from https:\/\/www.vmware.com\/products\/esxi-and-esx.html."},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.2197\/ipsjjip.26.662"},{"issue":"7","key":"e_1_3_2_31_2","doi-asserted-by":"crossref","first-page":"5510","DOI":"10.1109\/JIOT.2020.3030689","article-title":"A trust-evaluation-enhanced blockchain-secured industrial IoT system","volume":"8","author":"Wu Di","year":"2021","unstructured":"Di Wu and Nirwan Ansari. 2021. A trust-evaluation-enhanced blockchain-secured industrial IoT system. IEEE Internet Things J. 8, 7 (2021), 5510\u20135517.","journal-title":"IEEE Internet Things J."},{"issue":"5","key":"e_1_3_2_32_2","doi-asserted-by":"crossref","first-page":"4016","DOI":"10.1109\/JIOT.2020.2978286","article-title":"LVPDA: A lightweight and verifiable privacy-preserving data aggregation scheme for edge-enabled IoT","volume":"7","author":"Zhang Jiale","year":"2020","unstructured":"Jiale Zhang, Yanchao Zhao, Jie Wu, and Bing Chen. 2020. LVPDA: A lightweight and verifiable privacy-preserving data aggregation scheme for edge-enabled IoT. IEEE Internet Things J. 7, 5 (2020), 4016\u20134027.","journal-title":"IEEE Internet Things J."},{"issue":"5","key":"e_1_3_2_33_2","doi-asserted-by":"crossref","first-page":"817","DOI":"10.1049\/cje.2016.06.004","article-title":"A parallel processing and synthesis structure for improving access security and efficiency in SDN environment","volume":"25","author":"Zhang Peng","year":"2016","unstructured":"Peng Zhang, Xiangning Chen, Yun Ge, and Jin Lin. 2016. A parallel processing and synthesis structure for improving access security and efficiency in SDN environment. Chinese J. Electr. 25, 5 (2016), 817\u2013823.","journal-title":"Chinese J. Electr."},{"key":"e_1_3_2_34_2","first-page":"166","article-title":"Power IoT security protection architecture based on zero trust framework","author":"Zhang Xiaojian","year":"2021","unstructured":"Xiaojian Zhang, Liandong Chen, Jie Fan, Xiangqun Wang, and Qi Wang. 2021. Power IoT security protection architecture based on zero trust framework. In Proceedings of the IEEE 5th International Conference on Cryptography, Security and Privacy (CSP\u201921). 166\u2013170.","journal-title":"Proceedings of the IEEE 5th International Conference on Cryptography, Security and Privacy (CSP\u201921)"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2927538"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2019.2933482"}],"container-title":["ACM Transactions on Internet Technology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3511901","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3511901","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T17:48:50Z","timestamp":1750182530000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3511901"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,8,21]]},"references-count":35,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2023,8,31]]}},"alternative-id":["10.1145\/3511901"],"URL":"https:\/\/doi.org\/10.1145\/3511901","relation":{},"ISSN":["1533-5399","1557-6051"],"issn-type":[{"value":"1533-5399","type":"print"},{"value":"1557-6051","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,8,21]]},"assertion":[{"value":"2021-04-12","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-01-17","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-08-21","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}