The Internet of Things-based smart healthcare provides numerous facilities to patients and medical professionals. Medical professionals can monitor the patient's real-time medical data and diagnose diseases through the medical health history stored in the cloud database. Any kind of attack on the cloud database will result in misdiagnosis of the patients by medical professionals. Therefore, it becomes a primary concern to secure private data. On the other hand, the conventional data aggregation method for smart healthcare acquires immense communication and computational cost. Edge-enabled smart healthcare can overcome these limitations. The paper proposes an edge-enabled efficient privacy-preserving data aggregation (EEPPDA) scheme to secure health data. In the EEPPDA scheme, captured medical data have been encrypted by the Paillier homomorphic cryptosystem. Homomorphic encryption is engaged in the assurance of secure communication. For data transmission from patients to the cloud server (CS), data aggregation is performed on the edge server (ES). Then aggregated ciphertext data are transmitted to the CS. The CS validates the data integrity and analyzes and processes the authenticated aggregated data. The authorized medical professional executes the decryption, then the aggregated ciphertext data are decrypted in plaintext. EEPPDA utilizes the batch verification process to reduce communication costs. Our proposed scheme maintains the privacy of the patient's identity and medical data, resists any internal and external attacks, and verifies the health data integrity in the CS. The proposed scheme has significantly minimized computational complexity and communication overhead concerning the existing approach through extensive simulation.
{"title":"EEPPDA—Edge-enabled efficient privacy-preserving data aggregation in smart healthcare Internet of Things network","authors":"Tanima Bhowmik, Indrajit Banerjee","doi":"10.1002/nem.2216","DOIUrl":"10.1002/nem.2216","url":null,"abstract":"<p>The Internet of Things-based smart healthcare provides numerous facilities to patients and medical professionals. Medical professionals can monitor the patient's real-time medical data and diagnose diseases through the medical health history stored in the cloud database. Any kind of attack on the cloud database will result in misdiagnosis of the patients by medical professionals. Therefore, it becomes a primary concern to secure private data. On the other hand, the conventional data aggregation method for smart healthcare acquires immense communication and computational cost. Edge-enabled smart healthcare can overcome these limitations. The paper proposes an edge-enabled efficient privacy-preserving data aggregation (EEPPDA) scheme to secure health data. In the EEPPDA scheme, captured medical data have been encrypted by the Paillier homomorphic cryptosystem. Homomorphic encryption is engaged in the assurance of secure communication. For data transmission from patients to the cloud server (CS), data aggregation is performed on the edge server (ES). Then aggregated ciphertext data are transmitted to the CS. The CS validates the data integrity and analyzes and processes the authenticated aggregated data. The authorized medical professional executes the decryption, then the aggregated ciphertext data are decrypted in plaintext. EEPPDA utilizes the batch verification process to reduce communication costs. Our proposed scheme maintains the privacy of the patient's identity and medical data, resists any internal and external attacks, and verifies the health data integrity in the CS. The proposed scheme has significantly minimized computational complexity and communication overhead concerning the existing approach through extensive simulation.</p>","PeriodicalId":14154,"journal":{"name":"International Journal of Network Management","volume":"33 1","pages":""},"PeriodicalIF":1.5,"publicationDate":"2022-11-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"43858064","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Gagan Nandha Kumar, Kostas Katsalis, Panagiotis Papadimitriou, Paul Pop, Georg Carle
Time-Sensitive Networks (TSN) aims at providing a solid underpinning for the support of application connectivity demands across a wide spectrum of use cases and operational environments, such as industrial automation and automotive networks. However, handling network updates in TSN entails additional challenges, stemming from the need to perform both flow rerouting and TSN schedule reconfiguration. To address this issue, we propose a software-defined network (SDN)-based approach for low-overhead TSN network updates, exploiting segment routing over IPv6 (SRv6) for path control. To this end, we introduce the concept of TSN subgraphs in order to quickly reschedule the flows traversing the problematic area and propose a TSN-aware routing heuristic to minimize the convergence time. We further describe the control plane implementation and its integration into Mininet, which empowers us to conduct a wide range of performance tests. Our evaluation results indicate that our approach yields faster recovery and reduces significantly the number of required reconfigurations upon failures, at the expense of a small SRv6 encoding/decoding overhead.
{"title":"SRv6-based Time-Sensitive Networks (TSN) with low-overhead rerouting","authors":"Gagan Nandha Kumar, Kostas Katsalis, Panagiotis Papadimitriou, Paul Pop, Georg Carle","doi":"10.1002/nem.2215","DOIUrl":"10.1002/nem.2215","url":null,"abstract":"<p>Time-Sensitive Networks (TSN) aims at providing a solid underpinning for the support of application connectivity demands across a wide spectrum of use cases and operational environments, such as industrial automation and automotive networks. However, handling network updates in TSN entails additional challenges, stemming from the need to perform both flow rerouting and TSN schedule reconfiguration. To address this issue, we propose a software-defined network (SDN)-based approach for low-overhead TSN network updates, exploiting segment routing over IPv6 (SRv6) for path control. To this end, we introduce the concept of TSN subgraphs in order to quickly reschedule the flows traversing the problematic area and propose a TSN-aware routing heuristic to minimize the convergence time. We further describe the control plane implementation and its integration into Mininet, which empowers us to conduct a wide range of performance tests. Our evaluation results indicate that our approach yields faster recovery and reduces significantly the number of required reconfigurations upon failures, at the expense of a small SRv6 encoding/decoding overhead.</p>","PeriodicalId":14154,"journal":{"name":"International Journal of Network Management","volume":"33 4","pages":""},"PeriodicalIF":1.5,"publicationDate":"2022-10-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1002/nem.2215","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"42985873","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"OA","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Sepehr Abbasi Zadeh, Farid Zandi, Mohammad Amin Beiruti, Yashar Ganjali
Distributed control solutions were introduced to address controller reliability and scalability issues in software-defined networking (SDN). The dynamic nature of network traffic can lead to load imbalance among controller instances. A highly loaded controller instance can be slow in responding to datapath queries and can slow down the entire control platform, as state synchronization and consensus among controller instances are performed in a cooperative manner. In this paper, we present Efficient, Resilient, Consistent (ERC), a novel protocol for migrating the load of a given switch from a controller instance to a different instance. Our protocol has three distinguishing properties compared with prior works in this area: (1) It is resilient to failures during migration, (2) it maintains consistency among all controller instances, and nevertheless, (3) it is more efficient than existing load migration protocols. Compared with state-of-the-art, ERC reduces the migration time by 23–50% depending on network load. The implicit assumed use case in the design of previous load migration algorithms (including ERC) has been the load balancing scenario. However, as this is not the only possible case, by maintaining the desirable properties of ERC, we introduce four variants of our protocol that can add to the versatility of the load migration handling. This is achieved by considering variations of role exchange between controller instances, which gives us an advantage over the fixed master–slave exchange that vanilla ERC or previous work support. We perform an extensive set of experiments to examine the impact of variable network parameters on the performance metrics of interest and to show the effectiveness of the ERC family of protocols in load migration.
{"title":"Load migration in distributed softwarized network controllers","authors":"Sepehr Abbasi Zadeh, Farid Zandi, Mohammad Amin Beiruti, Yashar Ganjali","doi":"10.1002/nem.2214","DOIUrl":"10.1002/nem.2214","url":null,"abstract":"<p>Distributed control solutions were introduced to address controller reliability and scalability issues in software-defined networking (SDN). The dynamic nature of network traffic can lead to load imbalance among controller instances. A highly loaded controller instance can be slow in responding to datapath queries and can slow down the entire control platform, as state synchronization and consensus among controller instances are performed in a cooperative manner. In this paper, we present Efficient, Resilient, Consistent (ERC), a novel protocol for migrating the load of a given switch from a controller instance to a different instance. Our protocol has three distinguishing properties compared with prior works in this area: (1) It is resilient to failures during migration, (2) it maintains consistency among all controller instances, and nevertheless, (3) it is more efficient than existing load migration protocols. Compared with state-of-the-art, ERC reduces the migration time by 23–50% depending on network load. The implicit assumed use case in the design of previous load migration algorithms (including ERC) has been the load balancing scenario. However, as this is not the only possible case, by maintaining the desirable properties of ERC, we introduce four variants of our protocol that can add to the versatility of the load migration handling. This is achieved by considering variations of role exchange between controller instances, which gives us an advantage over the fixed master–slave exchange that vanilla ERC or previous work support. We perform an extensive set of experiments to examine the impact of variable network parameters on the performance metrics of interest and to show the effectiveness of the ERC family of protocols in load migration.</p>","PeriodicalId":14154,"journal":{"name":"International Journal of Network Management","volume":"32 6","pages":""},"PeriodicalIF":1.5,"publicationDate":"2022-09-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"45857299","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}