首页> 美国卫生研究院文献>Sensors (Basel Switzerland) >Microservice Security Agent Based On API Gateway in Edge Computing
【2h】

Microservice Security Agent Based On API Gateway in Edge Computing

机译:边缘计算中基于API网关的微服务安全代理

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Internet of Things (IoT) devices are embedded with software, electronics, and sensors, and feature connectivity with constrained resources. They require the edge computing paradigm, with modular characteristics relying on microservices, to provide an extensible and lightweight computing framework at the edge of the network. Edge computing can relieve the burden of centralized cloud computing by performing certain operations, such as data storage and task computation, at the edge of the network. Despite the benefits of edge computing, it can lead to many challenges in terms of security and privacy issues. Thus, services that protect privacy and secure data are essential functions in edge computing. For example, the end user’s ownership and privacy information and control are separated, which can easily lead to data leakage, unauthorized data manipulation, and other data security concerns. Thus, the confidentiality and integrity of the data cannot be guaranteed and, so, more secure authentication and access mechanisms are required to ensure that the microservices are exposed only to authorized users. In this paper, we propose a microservice security agent to integrate the edge computing platform with the API gateway technology for presenting a secure authentication mechanism. The aim of this platform is to afford edge computing clients a practical application which provides user authentication and allows JSON Web Token (JWT)-based secure access to the services of edge computing. To integrate the edge computing platform with the API gateway, we implement a microservice security agent based on the open-source Kong in the EdgeX Foundry framework. Also to provide an easy-to-use approach with Kong, we implement REST APIs for generating new consumers, registering services, configuring access controls. Finally, the usability of the proposed approach is demonstrated by evaluating the round trip time (RTT). The results demonstrate the efficiency of the system and its suitability for real-world applications.
机译:物联网(IoT)设备嵌入了软件,电子设备和传感器,并具有受限资源的连通性。他们需要边缘计算范例,其模块化特性依赖于微服务,以在网络边缘提供可扩展的轻量级计算框架。边缘计算可以通过在网络边缘执行某些操作(例如数据存储和任务计算)来减轻集中式云计算的负担。尽管边缘计算有很多好处,但它可能在安全性和隐私问题上引发许多挑战。因此,保护​​隐私和安全数据的服务是边缘计算中必不可少的功能。例如,最终用户的所有权和隐私信息与控制是分开的,这很容易导致数据泄漏,未经授权的数据操纵和其他数据安全问题。因此,不能保证数据的机密性和完整性,因此,需要更安全的身份验证和访问机制来确保微服务仅暴露给授权用户。在本文中,我们提出了一种微服务安全代理,以将边缘计算平台与API网关技术集成在一起,以提供一种安全的身份验证机制。该平台的目的是为边缘计算客户端提供一种实用的应用程序,该应用程序提供用户身份验证,并允许基于JSON Web令牌(JWT)的安全访问边缘计算服务。为了将边缘计算平台与API网关集成在一起,我们在EdgeX Foundry框架中基于开源Kong实施了一个微服务安全代理。为了向Kong提供一种易于使用的方法,我们实现了REST API,以生成新使用者,注册服务,配置访问控制。最后,通过评估往返时间(RTT)证明了所提出方法的可用性。结果证明了该系统的效率及其在实际应用中的适用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号