{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T12:54:20Z","timestamp":1784120060112,"version":"3.55.0"},"reference-count":42,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2019,1,12]],"date-time":"2019-01-12T00:00:00Z","timestamp":1547251200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/100010661","name":"Horizon 2020 Framework Programme","doi-asserted-by":"publisher","award":["731558"],"award-info":[{"award-number":["731558"]}],"id":[{"id":"10.13039\/100010661","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100010661","name":"Horizon 2020 Framework Programme","doi-asserted-by":"publisher","award":["768735"],"award-info":[{"award-number":["768735"]}],"id":[{"id":"10.13039\/100010661","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100013410","name":"INCIBE","doi-asserted-by":"publisher","award":["INCIBEI-2015-27363"],"award-info":[{"award-number":["INCIBEI-2015-27363"]}],"id":[{"id":"10.13039\/501100013410","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Industrial PhD","award":["DI-16-08432"],"award-info":[{"award-number":["DI-16-08432"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The increase of Software Defined Networks (SDN) and Network Function Virtualization (NFV) technologies is bringing many security management benefits that can be exploited at the edge of Internet of Things (IoT) networks to deal with cyber-threats. In this sense, this paper presents and evaluates a novel policy-based and cyber-situational awareness security framework for continuous and dynamic management of Authentication, Authorization, Accounting (AAA) as well as Channel Protection virtual security functions in IoT networks enabled with SDN\/NFV. The virtual AAA, including network authenticators, are deployed as VNF (Virtual Network Function) dynamically at the edge, in order to enable scalable device\u2019s bootstrapping and managing the access control of IoT devices to the network. In addition, our solution allows distributing dynamically the necessary crypto-keys for IoT Machine to Machine (M2M) communications and deploy virtual Channel-protection proxys as VNFs, with the aim of establishing secure tunnels among IoT devices and services, according to the contextual decisions inferred by the cognitive framework. The solution has been implemented and evaluated, demonstrating its feasibility to manage dynamically AAA and channel protection in SDN\/NFV-enabled IoT scenarios.<\/jats:p>","DOI":"10.3390\/s19020295","type":"journal-article","created":{"date-parts":[[2019,1,14]],"date-time":"2019-01-14T12:20:07Z","timestamp":1547468407000},"page":"295","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":44,"title":["Enabling Virtual AAA Management in SDN-Based IoT Networks \u2020"],"prefix":"10.3390","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0038-9012","authenticated-orcid":false,"given":"Alejandro","family":"Molina Zarca","sequence":"first","affiliation":[{"name":"Department of Information and Communications Engineering, University of Murcia, 30100 Murcia, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0803-1672","authenticated-orcid":false,"given":"Dan","family":"Garcia-Carrillo","sequence":"additional","affiliation":[{"name":"Department of Research and Innovation, Odin Solutions, 30820 Murcia, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7538-4788","authenticated-orcid":false,"given":"Jorge","family":"Bernal Bernabe","sequence":"additional","affiliation":[{"name":"Department of Information and Communications Engineering, University of Murcia, 30100 Murcia, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7573-6731","authenticated-orcid":false,"given":"Jordi","family":"Ortiz","sequence":"additional","affiliation":[{"name":"Department of Information and Communications Engineering, University of Murcia, 30100 Murcia, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8521-1864","authenticated-orcid":false,"given":"Rafael","family":"Marin-Perez","sequence":"additional","affiliation":[{"name":"Department of Research and Innovation, Odin Solutions, 30820 Murcia, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5525-1259","authenticated-orcid":false,"given":"Antonio","family":"Skarmeta","sequence":"additional","affiliation":[{"name":"Department of Information and Communications Engineering, University of Murcia, 30100 Murcia, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2019,1,12]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"27","DOI":"10.1145\/2677046.2677052","article-title":"Finding Your Way in the Fog: Towards a Comprehensive Definition of Fog Computing","volume":"44","author":"Vaquero","year":"2014","journal-title":"SIGCOMM Comput. Commun. Rev."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"174","DOI":"10.1145\/3126501","article-title":"HiCH: Hierarchical Fog-Assisted Computing Architecture for Healthcare IoT","volume":"16","author":"Azimi","year":"2017","journal-title":"ACM Trans. Embed. Comput. Syst."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"518","DOI":"10.1109\/TNSM.2016.2598420","article-title":"Resource Allocation in NFV: A Comprehensive Survey","volume":"13","author":"Herrera","year":"2016","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"20","DOI":"10.1016\/j.future.2018.07.039","article-title":"Research challenges in nextgen service orchestration","volume":"90","author":"Vaquero","year":"2019","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Bernab\u00e9, J.B., P\u00e9rez, J.M.M., Calero, J.M.A., Re, J.D.J., Clemente, F.J., P\u00e9rez, G.M., and Skarmeta, A.F. (2013). Security Policy Specification. Network and Traffic Engineering in Emerging Distributed Computing Applications, IGI Global.","DOI":"10.4018\/978-1-4666-1888-6.ch004"},{"key":"ref_6","unstructured":"(2019, January 11). DESEREC Project: DEpendability and Security by Enhanced REConfigurability. Available online: http:\/\/www.deserec.eu\/."},{"key":"ref_7","unstructured":"Basile, C. (2019, January 11). Policy Transformation and Optimization Techniques. Available online: https:\/\/www.secured-fp7.eu\/files\/secured_d42_policy_refinement_v0103.pdf."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Kolluru, K.K., Paniagua, C., van Deventer, J., Eliasson, J., Delsing, J., and Delong, R. (2018, January 15\u201318). An AAA solution for securing industrial IoT devices using next generation access control. Proceedings of the IEEE Industrial Cyber-Physical Systems (ICPS), St. Petersburg, Russia.","DOI":"10.1109\/ICPHYS.2018.8390799"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Zarca, A.M., Garcia-Carrillo, D., Bernabe, J.B., Ortiz, J., Marin-Perez, R., and Skarmeta, A. (2018, January 4\u20137). Managing AAA in NFV\/SDN-enabled IoT scenarios. Proceedings of the 2018 Global Internet of Things Summit (GIoTS), Bilbao, Spain.","DOI":"10.1109\/GIOTS.2018.8534551"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1016\/j.cose.2014.06.008","article-title":"Cyber situational awareness\u2014A systematic review of the literature","volume":"46","author":"Franke","year":"2014","journal-title":"Comput. Secur."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"270","DOI":"10.1504\/IJAHUC.2018.096081","article-title":"High-performance target tracking scheme with low prediction precision requirement in WSNs","volume":"29","author":"Liu","year":"2018","journal-title":"Int. J. Ad Hoc Ubiquit. Comput."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Garcia-Carrillo, D., and Marin-Lopez, R. (2016). Lightweight CoAP-Based Bootstrapping Service for the Internet of Things. Sensors, 16.","DOI":"10.3390\/s16030358"},{"key":"ref_13","unstructured":"ZigBee Alliance (2014). ZigBee IP Specification, ZigBee Alliance. ZigBee document 095023r34."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Selander, G., Mattsson, J., Palombini, F., and Seitz, L. (2018). Object Security for Constrained RESTful Environments (OSCORE), Internet Engineering Task Force. Work in Progress.","DOI":"10.17487\/RFC8613"},{"key":"ref_15","unstructured":"Selander, G., Mattsson, J., and Palombini, F. (2017). Ephemeral Diffie-Hellman Over COSE (EDHOC), Internet Engineering Task Force. Internet-Draft draft-selander-ace-cose-ecdhe-07; Work in Progress."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Scott-Hayward, S., O\u2019Callaghan, G., and Sezer, S. (2013, January 11\u201313). Sdn Security: A Survey. Proceedings of the 2013 IEEE SDN for Future Networks and Services (SDN4FNS), Trento, Italy.","DOI":"10.1109\/SDN4FNS.2013.6702553"},{"key":"ref_17","unstructured":"Lopez, R., and Lopez-Millan, G. (2018). Software-Defined Networking (SDN)-Based IPsec Flow Protection, Internet Engineering Task Force. Internet-Draft draft-ietf-i2nsf-sdn-ipsec-flow-protection-03; Work in Progress."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Farris, I., Taleb, T., Khettab, Y., and Song, J.S. (2018). A survey on emerging SDN and NFV security mechanisms for IoT systems. IEEE Commun. Surv. Tutor.","DOI":"10.1109\/COMST.2018.2862350"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"2542","DOI":"10.1109\/ACCESS.2015.2499271","article-title":"Software-Defined Network Function Virtualization: A Survey","volume":"3","author":"Li","year":"2015","journal-title":"IEEE Access"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Salva-Garcia, P., Alcaraz-Calero, J.M., Wang, Q., Bernabe, J.B., and Skarmeta, A. (2018). 5G NB-IoT: Efficient Network Traffic Filtering for Multitenant IoT Cellular Networks. Secur. Commun. Netw., 2018.","DOI":"10.1155\/2018\/9291506"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Basile, C., Lioy, A., Pitscheider, C., Valenza, F., and Vallini, M. (2015, January 13\u201317). A novel approach for integrating security policy enforcement with dynamic network virtualization. Proceedings of the 1st IEEE Conference on Network Softwarization (NetSoft), London, UK.","DOI":"10.1109\/NETSOFT.2015.7116152"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"e2038","DOI":"10.1002\/nem.2038","article-title":"Enhancing IoT security through network softwarization and virtual security appliances","volume":"28","author":"Farris","year":"2018","journal-title":"Int. J. Netw. Manag."},{"key":"ref_23","unstructured":"ANASTACIA (2019, January 11). Advanced Networked Agents for Security and Trust Assessment in CPS\/IoT Architectures. Available online: http:\/\/www.anastacia-h2020.eu\/."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Ziegler, S., Skarmeta, A., Bernal, J., Kim, E., and Bianchi, S. (2017, January 6\u20139). ANASTACIA: Advanced networked agents for security and trust assessment in CPS IoT architectures. Proceedings of the 2017 Global Internet of Things Summit (GIoTS), Geneva, Switzerland.","DOI":"10.1109\/GIOTS.2017.8016285"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Farris, I., Bernabe, J., Toumi, N., Garcia-Carrillo, D., Taleb, T., Skarmeta, A., and Sahlin, B. (2017, January 18\u201320). Towards Provisioning of SDN\/NFV-based Security Enablers for Integrated Protection of IoT Systems. Proceedings of the IEEE Conference on Standards for Communications and Networking (CSCN-2017), Helsinki, Finland.","DOI":"10.1109\/CSCN.2017.8088617"},{"key":"ref_26","unstructured":"ANASTACIA (2019, January 11). D1.2 User Centred Requirements Initial Analysis. Available online: http:\/\/anastacia-h2020.eu\/deliverables\/ANASTACIA-WP1-T1.2-SOFT-D1.2-UserCentredRequirementsInitialAnalysis-v11.pdf."},{"key":"ref_27","unstructured":"ANASTACIA (2019, January 11). D2.2 Attack Threats Analysis and Contingency Actions\u2014Initial Report. Available online: http:\/\/anastacia-h2020.eu\/deliverables\/ANASTACIA-WP2-T2.2-CNR-D2.2-AttackThreatsAnalysisAndContingencyActionsInitialReport-v0.5.pdf."},{"key":"ref_28","unstructured":"ANASTACIA (2019, January 11). D2.3 Privacy Risk Modelling and Contingency\u2014Initial Report. Available online: http:\/\/anastacia-h2020.eu\/deliverables\/ANASTACIA-WP2-T2.3-MAND-D2.3-PrivacyRiskModellingAndContingencyInitialReport-v1.0.pdf."},{"key":"ref_29","unstructured":"Rigney, C., Willens, S., Rubens, A., and Simpson, W. Remote Authentication Dial In User Service (RADIUS). RFC 2865 (Draft Standard), 2000; ISSN 2070-1721. Updated by RFCs 2868, 3575, 5080, 6929. Available online: https:\/\/tools.ietf.org\/html\/rfc2865."},{"key":"ref_30","unstructured":"Fajardo, V., Arkko, J., Loughney, J., and Zorn, G. (2019, January 11). Diameter Base Protocol. RFC 6733 (Proposed Standard), 2012; ISSN 2070-1721. Updated by RFC 7075. Available online: https:\/\/tools.ietf.org\/html\/rfc6733."},{"key":"ref_31","unstructured":"Aboba, B., Simon, D., and Eronen, P. (2019, January 11). Extensible Authentication Protocol (EAP) Key Management Framework. Available online: https:\/\/tools.ietf.org\/html\/rfc5247."},{"key":"ref_32","unstructured":"Forsberg, D., Ohba, Y., Patil, B., Tschofenig, H., and Yegin, A. (2019, January 11). Protocol for Carrying Authentication for Network Access (PANA). RFC 5191 (Proposed Standard), 2008; ISSN 2070-1721. Updated by RFC 5872. Available online: https:\/\/tools.ietf.org\/html\/rfc5191."},{"key":"ref_33","first-page":"1424","article-title":"A CoAP-Based Network Access Authentication Service for Low-Power Wide Area Networks: LO-CoAP-EAP","volume":"17","author":"Kandasamy","year":"2017","journal-title":"Sensors"},{"key":"ref_34","first-page":"1","article-title":"Distributed capability-based access control for the internet of things","volume":"3","author":"Jara","year":"2013","journal-title":"J. Internet Serv. Inf. Secur. (JISIS)"},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"55780","DOI":"10.1109\/ACCESS.2018.2872787","article-title":"A Trust and Priority Based Code Updated Approach to Guarantee Security for Vehicles Network","volume":"6","author":"Liu","year":"2018","journal-title":"IEEE Access"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"1763","DOI":"10.1007\/s00500-015-1705-6","article-title":"TACIoT: multidimensional trust-aware access control system for the Internet of Things","volume":"20","year":"2016","journal-title":"Soft Comput."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Shelby, Z., Hartke, K., and Bormann, C. (2019, January 11). The Constrained Application Protocol (CoAP). RFC 7252, 2014. Available online: https:\/\/tools.ietf.org\/html\/rfc7252.","DOI":"10.17487\/rfc7252"},{"key":"ref_38","unstructured":"Ohba, Y., and Yegin, A. (2019, January 11). Definition of Master Key Between Pana Client and Enforcement Point. RFC 5807 (Proposed Standard). Available online: https:\/\/tools.ietf.org\/html\/rfc5807."},{"key":"ref_39","unstructured":"Kivinen, T., Hoffman, P., Kaufman, C., Nir, Y., and Eronen, P. (2019, January 11). Internet Key Exchange Protocol Version 2 (IKEv2). RFC 7296 (Proposed Standard). Available online: https:\/\/tools.ietf.org\/html\/rfc7296."},{"key":"ref_40","unstructured":"Mehta, D., Mady, A.E.D., Boubekeur, M., and Shila, D.M. (2018, January 16\u201320). Anomaly-Based Intrusion Detection System for Embedded Devices on Internet. Proceedings of the Tenth International Conference on Advances in Circuits, Electronics and Micro-electronics, Venice, Italy."},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Osterlind, F., Dunkels, A., Eriksson, J., Finne, N., and Voigt, T. (2006, January 14\u201316). Cross-Level Sensor Network Simulation with COOJA. Proceedings of the 2006 31st IEEE Conference on Local Computer Networks, Tampa, FL, USA.","DOI":"10.1109\/LCN.2006.322172"},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Hernandez-Ramos, J.L., Carrillo, D.G., Mar\u00edn-L\u00f3pez, R., and Skarmeta, A.F. (2015, January 14\u201316). Dynamic security credentials PANA-based provisioning for IoT smart objects. Proceedings of the 2015 IEEE 2nd World Forum on Internet of Things (WF-IoT), Milan, Italy.","DOI":"10.1109\/WF-IoT.2015.7389153"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/19\/2\/295\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T12:25:34Z","timestamp":1760185534000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/19\/2\/295"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,1,12]]},"references-count":42,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2019,1]]}},"alternative-id":["s19020295"],"URL":"https:\/\/doi.org\/10.3390\/s19020295","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,1,12]]}}}