0% found this document useful (0 votes)
24 views46 pages

IoT Services via SDN and Edge Computing

Tốt nghiệp Cao đẳng trở lên hoặc có các tính chỉ về lập trình. Nắm vững về các ngôn ngữ lập trình: HTML, C#, Java… Đã từng có kinh nghiệm thiết kế Website, Application, Game là một lợi thế.

Uploaded by

thinh23mse43007
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
24 views46 pages

IoT Services via SDN and Edge Computing

Tốt nghiệp Cao đẳng trở lên hoặc có các tính chỉ về lập trình. Nắm vững về các ngôn ngữ lập trình: HTML, C#, Java… Đã từng có kinh nghiệm thiết kế Website, Application, Game là một lợi thế.

Uploaded by

thinh23mse43007
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

See discussions, stats, and author profiles for this publication at: [Link]

net/publication/341657809

Complementing IoT Services Through Software Defined Networking and Edge


Computing: A Comprehensive Survey

Article in IEEE Communications Surveys & Tutorials · May 2020


DOI: 10.1109/COMST.2020.2997475

CITATIONS READS

310 5,855

7 authors, including:

Lianyong Qi Ibrar Yaqoob


Qufu Normal University Charles Sturt University
300 PUBLICATIONS 10,526 CITATIONS 139 PUBLICATIONS 16,722 CITATIONS

SEE PROFILE SEE PROFILE

Muhammad Imran Raihan Ur Rasool


BUIC Victoria University Melbourne
1,029 PUBLICATIONS 35,315 CITATIONS 68 PUBLICATIONS 1,460 CITATIONS

SEE PROFILE SEE PROFILE

All content following this page was uploaded by Wajid Rafiq on 27 May 2020.

The user has requested enhancement of the downloaded file.


IEEE COMMUNICATIONS SURVEYS & TUTORIALS 1

Complementing IoT Services through Software


Defined Networking and Edge Computing: A
Comprehensive Survey
Wajid Rafique, Lianyong Qi, Ibrar Yaqoob, Senior Member, IEEE, Muhammad Imran, Senior Member, IEEE,
Raihan ur Rasool, and Wanchun Dou, Senior Member, IEEE

Abstract—Millions of sensors continuously produce and trans- and further research directions to efficiently provide IoT services
mit data to control real-world infrastructures using complex in the SDIoT-Edge paradigm.
networks in the Internet of Things (IoT). However, IoT devices
are limited in computational power, including storage, processing, Index Terms—Edge computing, Internet of things, Software-
and communication resources, to effectively perform compute- defined networking, Software-defined IoT, network virtualization,
intensive tasks locally. Edge computing resolves the resource IoT service orchestration.
limitation problems by bringing computation closer to the edge of
IoT devices. Providing distributed edge nodes across the network
reduces the stress of centralized computation and overcomes I. I NTRODUCTION
latency challenges in the IoT. Therefore, edge computing presents
low-cost solutions for compute-intensive tasks. Software-Defined
Networking (SDN) enables effective network management by
presenting a global perspective of the network. While SDN was
R ECENT developments in the field of Ubiquitous Com-
puting (Ubicomp) advocate Mark Weiser’s prediction of
indispensable human dependence on computer systems [1].
not explicitly developed for IoT challenges, it can, however, His vision set the path for developments in the field of
provide impetus to solve the complexity issues and help in efficient Ubicomp, where mobile phones and smart devices have now
IoT service orchestration. The current IoT paradigm of massive
data generation, complex infrastructures, security vulnerabilities, become an integral part of our lives [2]. These devices are
and requirements from the newly developed technologies make equipped with a multitude of sensors, audiovisual features,
IoT realization a challenging issue. and intelligent applications. Smart devices, such as watches,
In this research, we provide an extensive survey on SDN and gadgets, bracelets, and accompanying smartphones make ubiq-
the edge computing ecosystem to solve the challenge of complex uitousness a reality [3].
IoT management. We present the latest research on Software-
Defined Internet of Things orchestration using Edge (SDIoT- Humankind has stepped into an era of Ubicomp where wear-
Edge) and highlight key requirements and standardization efforts able devices regularly log data, implement various services,
in integrating these diverse architectures. An extensive discus- and pass this information to the network at regular intervals
sion on different case studies using SDIoT-Edge computing is [2]. It has been estimated that more than 50 billion devices
presented to envision the underlying concept. Furthermore, we will connect to the internet until 2025 [4]. This exponential
classify state-of-the-art research in the SDIoT-Edge ecosystem
based on multiple performance parameters. We comprehensively increase in data generation resources poses a vital challenge
present security and privacy vulnerabilities in the SDIoT-Edge to communication technology [5]. A wide range of smart
computing and provide detailed taxonomies of multiple attack devices has been introduced in the market, including vehicles,
possibilities in this paradigm. We highlight the lessons learned wearable gadgets, measurement sensors, home appliances,
based on our findings at the end of each section. Finally, we dis- healthcare, and industrial products [3]. Internet of Things (IoT)
cuss critical insights toward current research issues, challenges,
has received immense attention from industry and academia
This work was supported in part by the National Key Research and due to the growing need for IoT devices in everyday life [6],
Development Program of China (No. 2017YFB1001801), the National Science [7]. IoT devices have been involved in providing enormous
Foundation of China under Grant No. 61672276 and No. 61872219, the
Natural Science Foundation of Shandong Province (ZR2019MF001), the Key economic contributions during the past few years. Therefore,
Research and Development Program of Jiangsu Province (No.BE2019104), extensive efforts have been put forward toward their active
and the Collaborative Innovation Center of Novel Software Technology and development and deployment [8]. The success of the Inter-
Industrialization, Nanjing University.
W. Rafique and W. Dou are with the Department of Computer Science and net lies in the interoperability and open access to multiple
Technology, Nanjing University, Nanjing, P. R. China, and also with the State hardware and software platforms [9]–[11]. However, diverse
Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, IoT architectures provoke disparate network implementations
P. R. China (e-mail: rafiqwajid@[Link]; douwc@[Link]).
Lianyong Qi is with the School of Information Science and Engineering, [12]. Thus, different data formats, communication procedures,
Qufu Normal University, Qufu, P. R. China (e-mail: lianyongqi@[Link]). and protocols pose a complex challenge that makes IoT a
I. Yaqoob is with the Department of Computer Science and Engi- vertically fragmented network system [13]. An increase in the
neering, Kyung Hee University, Yongin-si 17104, South Korea (e-mail:
ibraryaqoob@[Link]). number of connected devices introduces a massive amount of
M. Imran is with the College of Computer and Information Science, King data, which poses another challenge for today’s networks to
Saud University, Saudi Arabia (email: cimran@[Link]). handle it effectively [14], [15]. Therefore, we must develop
R. ur Rasool is with Victoria University, Melbourne, Australia (e-mail:
[Link]@[Link]). new edge technologies that classify and filter IoT big data
(Corresponding author: Wanchun Dou.) before transmitting to the central cloud data center. Similarly,
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 2

the term associated with IoT big data underlines many an- fective IoT deployment a complex task. Therefore, addressing
ticipated challenges related to data management, privacy, and these challenges to effectively reap benefits from the vital IoT
provenance [16]. infrastructure and implement ubiquitousness, in reality, is long
Edge computing renders the ability to process compute- overdue [52].
intensive tasks of the resource-limited IoT devices that cannot
be performed locally [17], [18]. It can effectively distribute
network computation and avoid peak loads in IoT networks A. Motivation of this Survey
[19]. It has gained tremendous attention over the past few The motivation of this survey comes from the realization
years, such that researchers, technology leaders, and govern- of the immense increase in IoT devices and their impact on
ments are putting their effort toward wider edge computing human life. According to the Gartner survey, the IoT-enabled
deployment [20]. It brings the computation resources closer to infrastructure will grow to 21 billion connected devices in
mobile devices to support resource-limited IoT infrastructure 2020, depicting an estimated 82% increase as compared to
to effectively perform complex computations [21]. However, the Gartner’s prediction of 2018. Furthermore, there will be
moving the computational infrastructure closer to the locality around 250 million smart vehicles on the road until 2020
brings many technical challenges related to service discovery, [60]. Moreover, IoT has been involved in generating a signif-
mobility management, and user handover [22], [23]. The icant return on investment where the revenue of IoT service
performance of the IoT applications is degraded while sending providers, vendors, and solution developers is expected to hike
data to the edge and then waiting for the response. Edge-based up-to $1 trillion in 2025 [61]. The IoT-enabled smart homes
devices have many applications, including transportation, concept has been transformed into a reality where everything
homes, healthcare, cities, and buildings [24]. Edge cloudlets performs sophisticated measurements and produces data giving
can be placed between IoT infrastructure and the central cloud rise to data generating sources. As most IoT generates personal
to support the delay-sensitive IoT applications. The central and sophisticated data, it is infeasible to send all the data
cloud infrastructure possesses powerful data centers to execute to the remote data centers for the processing, which causes
higher latency service requests [25]. security and privacy issues. Moreover, transferring all the
Communication networks weave the fabric of today’s digital data to the remote data centers may overload the commu-
world, where the significance of a network is ascertained by nication infrastructure. Edge computing provides a solution
Metcalfe’s law, which states that the value of a communication for such challenges where the computation of the resource-
network is directly proportional to the number of connected limited devices can be offloaded at the edge, which alleviates
devices [42]. Therefore, Software-Defined Networking (SDN) the challenge of traffic overload and privacy concerns. Edge
has become an important technology for network service computing provides optimal solutions for battery-constrained
provisioning due to its flexible management and programma- devices and latency-sensitive applications. Due to a rapid and
bility [26], [43]. SDN provides a layered framework where disproportional increase in the IoT infrastructure, the need
each plane operates separately, including data, control, and for smart network management techniques is increased. IoT
application planes [44]. Separation of the data and the control devices cannot be programmed to handle complex rules and
plane facilitates network administration at runtime, traffic man- customized traffic forwarding due to memory constraints. Con-
agement, network evolution, and flexible network programma- sequently, traditional networking technology suffers from pro-
bility [45], [46]. Thus, due to the widespread proliferation viding feasible solutions in handling the application-specific
of IoT and its management complexities, Software-Defined needs of IoT. Traditional network management paradigms also
Internet of Things (SDIoT) architecture has been proposed for experience scalability and modularity issues, whereas SDN
an effective management [47]–[50]. Similarly, edge computing provides centralized IoT management, resource virtualization,
brings cloud services near the edge of IoT to increase scalabil- innovation, and programmability.
ity and interoperability [51]. Novel SDN and edge-based IoT This survey provides state-of-the-art literature on the com-
implementations create a new communication perspective for munication and service technologies for un-interrupted service
effective service provisioning. The cloud services are integral orchestration from IoT. The disjoint development of the IoT
for IoT realization; therefore, SDIoT service orchestration infrastructure provokes non-standardized solutions that lever-
using edge computing has been adopted to realize Software- age security challenges, interoperability issues, QoS concerns,
Defined Internet of Things and Edge (SDIoT-Edge) framework and management problems [62]. A diverse range of application
[52]–[55]. This architecture helps in efficient IoT realization; domains also invoked multiple technology-specific standards
however, the disparate set of hardware infrastructures pose new in the IoT ecosystem; however, the underlying service pro-
challenges of communication, interoperability, management, visioning process is identical [63]. Moreover, IoT suffers
and lack of a unified architecture. Security, reliability, and from higher security threats because the security solutions
privacy of devices and data produced and transferred during deployment in IoT is challenging as compared to traditional
IoT operation also pose further challenges in the SDIoT-Edge networks due to the heterogeneity [64], [65]. Consequently, the
ecosystem [56], [57]. Communication technologies need to be data leakage concerns at the intermediate nodes during the data
evolved with the development of new infrastructures. However, transfer poses higher privacy issues. Attack vectors involving
current communication technologies lack in enduring effective IoT also increase due to the highly vulnerable nature of IoT,
communication, resource management, privacy, and security which gives rise to various devastating attacks [66]. Due to the
challenges [58], [59]. Consequently, these challenges make ef- challenges mentioned above, we design this survey to provide
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 3

TABLE I
A COMPARISON OF PREVIOUS SURVEYS ON I OT SERVICE ORCHESTRATION USING SDN AND E DGE COMPUTING .

SDIoT-Edge Edge-IoT 5G
References SDN Edge Computing IoT Virtualization Standardization
Framework Security Networks
Farris et al. [26] X X X X
Jilani et al. [27] X X X
Abbas et al. [28] X X X X X
Pawami et al. [29] X X X X X
Farhana et al. [30] X X X X
Mouradian et al. [31] X X X X
Salman et al. [32] X X X X X
Roman et al. [33] X X X X
Baktir et al. [34] X X X X X
Mao et al. [35] X X X X X X
Yu et al. [36] X X X
Alessio et al. [37] X X
Elazhary [38] X X X X
Mukherjee et al. [39] X X
Ai et al. [40] X X X
Christos et al. [41] X X X
Our Survey X X X X X X X X

a comprehensive approach in highlighting and addressing the This survey outlines the literature where SDN, IoT, and edge
significant challenges in SDIoT-Edge realization. This survey computing can collaborate and offer novel services besides
presents the current models of network virtualization and edge complementing existing applications. We propose technolog-
computing in IoT to provide a comprehensive reference to the ical grounds on all the three paradigms in developing a
researchers. comprehensive architecture where centralized management in
SDN, computation offloading in edge computing, and sophis-
ticated measurements in IoT can be integrated efficiently. A
B. Comparison With Related Survey Articles and Contribu- comparison of this survey with the already available surveys
tions of This Survey in this paradigm is presented in Table I, which demonstrates
Several surveys focusing on different aspects of virtualiza- that the available literature lacks in providing a comprehensive
tion and cloud computing for IoT have been conducted during study on the SDIoT-Edge ecosystem. Most of the available
the past few years including edge computing for IoT [27], literature discusses only individual aspects of the SDIoT-
[29], [36], [67], [28], fog computing, [37]–[39] virtualization Edge ecosystem; however, we perform a holistic study of the
[32], [34], security [26], [33], [68], and programmability [30]. literature available on the SDIoT-Edge paradigm. We include a
A few research papers address the combined perspective of comprehensive discussion on key requirements of SDN, IoT,
IoT-Edge and their application areas [52]–[55]. Most of these and edge computing that are critical in envisioning SDIoT-
researches address an individual aspect of IoT-Edge, for exam- Edge solutions. Furthermore, the standardization issues and
ple, standardization, virtualization, or security. However, there security challenges have been extensively discussed to benefit
is a lack of survey publications on the SDIoT-Edge computing the readers in understanding key vulnerabilities and limitations
ecosystem from a comprehensive perspective, including the of the current IoT ecosystem. We present the architecture,
architecture, virtualization, requirements, standardization, and requirements, applications, standardization, and security as-
security, given that this is a novel paradigm, that lies on pects of the SDIoT-Edge framework. We include taxonomies
the intersection of SDN, IoT, and Edge computing. Table I of security vulnerabilities and the possibilities of attacks in
outlines the most recent surveys on the IoT taxonomy from the the SDIoT-Edge ecosystem. Finally, a broad discussion on
perspective of SDN, edge computing, virtualization, security, the issues and challenges have been incorporated to provide
communication technologies, and architecture. The available the researchers and practitioners an insight into the future
studies provide an abstract understanding of the IoT integration research in this paradigm. We explicitly discuss key lessons
with fog computing and SDN; moreover, most of them omit a learned at the end of each section to summarize the insights
crucial infrastructure of either IoT, edge computing, or SDN. obtained from the discussion. To the best of our knowledge,
In [32], authors consider the virtualization of fog computing this is the first survey that broadly covers major aspects of
with IoT; however, they did not consider the edge computing the SDIoT-Edge ecosystem, from requirements to deployment,
paradigm, which has become crucial for latency-sensitive IoT standardization, and security. The key contributions of this
applications. survey are as follows.
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 4

TABLE II
L IST OF ACRONYMS AND THEIR EXPLANATION .

AmI Ambient Intelligence NGSON Next Generation Overlay Networks


APS Application Service Provider NIDS Network Intrusion Detection System
AR Augmented Reality NIST National Institute of Standards and Technology
AWS Amazon Web Services NOS Network Operating System
BLE Bluetooth Low Energy OCI Open Carrier Interface
BS Base Stations ONF Open Networking Foundation
C-DPI Control-Data Plane Interface OS Operating System
Co Connected Object OSGI Open Service Gateway Initiative
CoAP Constrained Application Layer Protocol PKI Public Key Infrastructure
CoRE Constrained RESTful Environment QoS Quality of Service
CSCC Cloud Standard Customer Council RAC Radio Access Networks
DDoS Distributed Denial of Service REST REpresentational State Transfer
DTLS Datagram Transport Layer Security RFC Request for Comments
EaaS Edge-as-a-Service ROLL Routing Over Low Power and Lossy Networks
EC2 Elastic Compute Cloud RPL Routing Protocol for Low Power and Lossy Networks
EPC Evolved Packet Core RSU Roadside Units
ETSI European Telecommunications Standards Institute RSUC Roadside Units Controller
HTTP Hypertext Transfer Protocol SDIoT Software-Defined IoT
I2RS Interface to Routing Systems SDIoV Software-Defined Internet of Vehicles
IETF Internet Engineering Task Force SDN Software-Defined Networking
IIoT Industrial Internet of Things SDSec Software-Defined Security
IKEv2 Internet Key Exchange SD-WAN Software-Defined Wide Area Network
IoA Internet of Everything SDWN Software-Defined Wireless Networks
IoMT Internet of Medical Things SFC Service Function Chaining
IoT Internet of Things SIoT Social Internet of Things
IoV Internet of Vehicles SLA Service Level Agreement
IP Internet Protocol SOA Service-Oriented Architecture
IPS Internet Service Provider SPEC Standard Performance Evaluation Corporation
ISO International Standard Organization SQL Structured Query Language
ISOC Internet Society TCAM Ternary Content-Addressable Memory
ITS Intelligent Transport System TCP Transmission Control Protocol
ITU International Telecommunication Union TLS Transport Layer Security
LFA Link Flooding Attack Ubicomp Ubiquitous Computing
LLDP Link Layer Discovery Protocol UDP User Datagram Protocol
LoRa Long Range VLAN Virtual Local Area Network
LPWAN Low-Power-Wide-Area Network VNF Virtual Network Function
LTE Longterm Evolution Vo Virtual Object
M2M Machine-to-Machine VR Virtual Reality
MAC Media Access Control VXLAN Virtual Extensible LAN
MEC Multi-access Edge Computing WoT Web of Things
MiTM Man in the Middle WPAN Wireless Personal Area Networks
NDN Named Data Networking WSNs Wireless Sensor Networks
NFV Network Function Virtualization WWAN Wireless Wide Area Networks

• We present the evolution of SDIoT-Edge by reporting C. Organization Of The Survey


relevant literature on IoT, SDN, and edge computing.
Moreover, the key requirements of the diverse underlying
The structure of this paper is given in Fig. 1, whereas
technologies are presented that are critical in envisioning
Table II describes the acronyms used in this research. This
the SDIoT-Edge concept.
survey is organized as follows. Section II provides the core
• We categorize the available literature on SDIoT-Edge and
definition of IoT, SDN, and edge computing, including ar-
provide a comprehensive taxonomy of the solutions using
chitecture, working principles, and components. Moreover, it
multiple performance parameters.
present the architecture of the SDIoT-Edge ecosystem, after a
• We critically discuss, analyze, and evaluate current stan-
detailed discussion on these platforms. Section III introduces
dardization efforts in SDIoT-Edge. Moreover, a detailed
the key requirements of heterogeneous platforms in SDIoT-
discussion on the key case studies using SDIoT-Edge is
Edge. Furthermore, Section IV presents a detailed taxonomy
presented.
of the current SDIoT-Edge literature in different categories.
• We discuss security and privacy issues of SDIoT-Edge
Section V discusses state-of-the-art case studies by employing
and present detailed taxonomies of the most devastating
the SDIoT-Edge architecture, whereas Section VI describes the
attack challenges that can exploit the vulnerabilities in
standardization efforts in SDIoT-Edge. Section VII categorizes
the current infrastructure.
the security and privacy concerns of SDIoT-Edge including
• Novel open research issues, challenges, limitations, and
the detailed taxonomies of different attacks. Section VIII
future research directions are presented that provide a
illustrates current issues, challenges, limitations, and future
roadmap for future research in SDIoT-Edge.
research directions, and finally, Section IX concludes the
paper.
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 5

Fig. 2. The number of publications on IoT and its convergence with edge
computing [69].

II. S OFTWARE -D EFINED I NTERNET OF T HINGS USING


E DGE C OMPUTING
This section describes essential technologies that can be
utilized for an efficient implementation of IoT using edge com-
puting and SDN. Furthermore, we present the core technolo-
gies that provide the basis for the research on the integration
of edge computing and SDN for efficient implementation of
IoT. We separately discuss the underlying architectures and
provide a detailed framework of SDIoT-Edge.

A. Internet of Things
IoT has become one of the most popular terms in research
and academia during the past few years [70]–[72]. Fig. 2
encompasses the number of publications in the field of IoT
and edge computing from 2011 to November 2019, depicting
the growing importance of the research in this area. Fig. 2
shows the IoT and edge computing research trends based on
the Scopus bibliographic database; it depicts an enormous
increase in the number of publications in both the fields
[69]. According to the International Telecommunication Union
(ITU), the IoT is an architecture that weaves physical and
virtual components together [73]. The IoT definition provided
by the Internet Engineering Task Force (IETF) is that it is
an Internet that can concurrently operate among TCP/IP and
non-TCP/IP protocols, whereas the things are related to the
objects that are identified by unique addresses [74]. IEEE
provides a comprehensive definition by describing the IoT as
a network that interlinks uniquely addressable physical and
virtual devices by utilizing novel communication protocols.
The things/devices in the IoT are dynamically configurable and
Fig. 1. Structure of the paper.
provide interfaces that facilitate their access over the Internet
[75]. IoT has many variants, as researchers named them during
their evolution and invention, such that it is an umbrella
term that encompasses many technologies, such as Machine-
to-Machine (M2M), Internet of Anything (IoA), Industrial
Internet of Things (IIoT), Internet of Medical Things (IoMT),
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 6

Web of Things (WoT), Social Internet of Things (SIoT), and 2) Time-based Architecture: In this architecture, the data is
Internet of Everything (IoE). transferred after a specific time interval.
The M2M concept encompasses a broad range of networked The characteristics of the IoT include size, space, time,
devices that collect sensor data and send it to the network. It intelligence, everything-as-a-service, and complex systems
constitutes any technology that enables devices to interact and [32]. The size is an important characteristic, as the IoT is
perform actions in an automated fashion [76]. The most critical composed up of a massive repository of devices around the
component of M2M is the field-deployed wireless devices globe. Fig. 3 represents the application areas of the IoT; it
having embedded sensors and RFID-wireless communication can be observed that the IoT has been used in almost all
networks with necessary wireline, including Wi-Fi, ZigBee, fields of life, e.g., industry, health, farming, communication,
WiMAX, Wireless Local Area Network (WLAN), and generic aviation, transportation, and banking that aim to facilitate
DSL. IoA goes beyond the connectivity of physical objects human lives. Diverse application areas pose a multitude of
and includes anything that generates data [77]. Cisco defines domain-specific requirements, including interoperability, com-
IoE as a networked connection of people, processes, data, and munication, and security. In this regard, special attention must
things to enhance user experience and smart decision making. be given to reliable IoT communication management. SDN
IoE creates a compound effect by all-round connectivity, has been widely deployed in current data center networks due
intelligence, and cognition [78]. The major difference that to its characteristics of centralized control, efficient resource
separates IoE from IoA and IoT is that the IoT and IoA management, and programmability [96], [97]. There is a high
may not necessarily contain people; however, IoE does contain need to use SDN for decentralized IoT network provisioning
individuals. IIoT is the extension of IoT, which enables the and management.
use of IoT in the industrial applications [79]. By leveraging
the M2M communication, big data, and machine learning,
IIoT facilitates the industries to attain better manufacturing B. Software-Defined Networking
efficiency, decision-making capability, and efficient resource SDN has emerged as an essential solution for flexible
management [80]–[82]. Extensive use of IoT in healthcare network deployment and offers efficient network management
during the past few years provokes the concept of IoMT, which by providing a centralized view of the network [97]–[101].
encompasses networked medical devices and applications that With the increasing demands of users due to the broad Inter-
enhance smart healthcare operations [83]. A few applications net access and IoT applications, network developers, service
of IoMT include remote patient monitoring, wearable inspec- providers, and network carriers have to provide up-to-date
tion devices, medication orders tracking, and smart hospital services to the users. In the same way, communication net-
beds. WoT is a refinement of IoT where the smart things are works are expanding exponentially, which makes it complex
not only connected with the Internet but also with the web to manage them. In this regard, SDN has been proposed to
resources [84]. SIoT is defined as the IoT where the things enable independence between the controller and data planes,
are capable of autonomously creating a social relationship with which equips application developers and service providers to
other objects like humans [85]. proactively manage the network resources and offer flexible
IoT studies are composed up of numerous application areas, network expansion [102], [103]. This separation also provides
such as Ubicomp, Ambient Intelligence (AmI), smart homes, efficient resource management, where network operators can
and smart cities [86], [87]. Actually, Ubicomp and pervasive configure, upgrade, and maintain network resources dynami-
computing were proposed before the IoT in the 1980s [88]. cally [104]. In addition, as the network is logically centralized,
Mark Weiser described Ubicomp as a smart environment that the controller has access to all components of the network
is invisibly interconnected using actuators, sensors, and com- where resources and traffic can be effectively managed [105].
puting objects [42], [89], [90]. This idea pioneered innovation For the practical envisioning of edge computing in IoT
in Internet technology and delved into the development of infrastructures, there is a need for a simplified architecture that
multiplatform computing. hides all the complexities of the communication and provides
IoT devices have been employed in many aspects of human a simplified view to the user. Therefore, SDN, due to its
life, and their industrial deployment is the most critical aspect widespread implementation, has become a key candidate for
because it requires a considerable amount of special effort edge service orchestration. SDN is a feasible solution for edge
depending on the environment in which it is being deployed implementation, providing flexibility and high manageability
[91], [92]. The most prominent issues faced by IoT deploy- by separating the control and data planes [106], [107]. The
ment are the privacy and security of data [26], [93] and lack control mechanism of SDN can reduce the edge computing
of standardization [94]. In this regard, the IIoT consortium architectural and implementation complexities by providing
has been constituted with the help of many state-of-the-art a novel mechanism for networking and allowing efficient
technology organizations, including Cisco, AT&T, GE, and resource management simultaneously.
Intel [95]. The paradigm of IoT covers three areas of broader In edge computing, the generated traffic needs to be routed
concepts, including the Internet, things, and semantics [32]. toward the server to complete the device service requirements
The two most widely used operational architectures of IoT [35]. As SDN is based on the flexible and intelligent control
are as follows. of the network, it can alleviate complex communication needs
1) Event-based Architecture: In this architecture, the opera- at the edge, for example, service discovery, provisioning, and
tional data is transferred when a specific event occurs. orchestration. In contrast to the traditional networks that rely
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 7

Fig. 3. IoT application areas.

on the distributed management of network elements, SDN 3) Application Plane: It consists of multiple user applica-
utilizes OpenFlow protocol to flexibly manage the network tions that talk to the controller to achieve abstraction for a
infrastructure [108]. In traditional networks, the traffic packets logically centralized controller to make coordinated decisions.
are handled by single or multiple combinations of header The Application Plane to Control Plane communication Inter-
packets, e.g., MAC address of destination, IP prefixes, multiple face (A-CPI) uses the REpresentational State Transfer (REST)
combinations of IP addresses, and UDP/TCP port numbers. Application Programming Interface (API) [110].
Alternatively, SDN architecture enables a wide range of packet The traffic is governed by the central controller, which has
features by utilizing the Control-Data Plane Interface (C- global view of the network and uses the following flow rule
DPI), a widely adopted example of which is the OpenFlow installation modes.
protocol [97]–[100], [108]. A general-purpose architecture of • Proactive Mode: In this mode, flow rules are configured in
SDN encompasses three planes, including the data, control, the data plane switches before the arrival of data packets.
and application plane. The detailed description of SDN planes In this situation, when a packet arrives at the switch, it
is discussed below. already contains the information on how to process this
flow, which limits the involvement of the controller and
1) Data Plane: It is the lowest plane in the SDN ar-
results in a faster communication.
chitecture that directly deals with the physical network in-
• Reactive Mode: In this mode, when a new flow arrives
frastructure, including switches, routers, and access points.
at the data plane switch, it performs flow rule lookup in
The controller manages these devices using the C-DPI. The
their corresponding flow tables. If no match is found,
network infrastructure and the controllers coordinate using
the switch forwards this flow to the controller in a
a secure channel, implementing different security protocols
PACKET IN message. Subsequently, the controller allo-
such as Transport Layer Security (TLS). OpenFlow is a
cates a flow rule based on the network policies and sends
highly adopted protocol deployed for C-DPI and used for
it to the switch using a PACKET OUT message. The
communication among data plane devices and the controller.
incoming rules in the future will be handled according to
2) Control Plane: It is called the brain of SDN, which the flow rule matching process by the switch.
manages the whole decision-making process of the network. • Hybrid Mode: In this mode, the controller has the ad-

It consists of a software implementation of one or more vantage of utilizing both proactive and reactive modes.
than one controller for effective control over the network. It The phenomenon behind this is that the administrator
comprises all the arrangements to enable an intercontroller, sometimes installs proactive rules in devices that the
data plane to the controller, and application plane to the controller modifies reactively to enhance optimal flow, in
controller communication. Control and functional components addition to installing new flows based on network traffic.
are available in the control logic of the controller, where the In SDN, OpenFlow switches consist of three main com-
functional components include a virtualizer and coordinator. ponents, including flow table, OpenFlow protocol, and secure
The main SDN control logic maps requirements of the network channel. The OpenFlow-enabled switches keep a variety of
applications to the commands for the data plane elements flow tables to store forwarding rules to manage network traffic.
[109]. Each flow rule has three components, including a “rule”
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 8

computation platform. In the presence of the traditional cloud,


a solution has been put forward that leverages the cloud
services and brings them closer to the devices, known as
edge computing [52], [53]. In the massive proliferation of IoT
devices, some computation can be performed at the edge rather
than transferring the whole task to the remote central cloud,
which increases latency. However, edge implementation in a
distributed environment involves considerable complexities of
mobility management, device authentication, fault-tolerance,
and data management, which can be managed by resource
virtualization. In this regard, we discuss edge enabling tech-
nologies, including Network Function Virtualization (NFV), in
the following.
1) Convergence of NFV and Edge Computing: Network
function virtualization deals with the transformation of
hardware-oriented functions, such as firewalls or DNS to the
software applications. It is an essential enabling technology for
dynamic service orchestration in IoT networks. In traditional
networks, the network functions are provided as proprietary
services [115]. These network functions are attached to a
sequenced chain known as Service Function Chaining (SFC)
Fig. 4. Hierarchy of edge and cloud infrastructure. [116], where the data traffic needs to follow the specific SFC
order to orchestrate a service [117]. For example, a service
provided by SFC is decomposed into the firewall, Deep Packet
attribute, an “action” field, and a “status.” The “rule” attribute Inspection (DPI), and load balancer. The network packets are
is used to describe the flow information based on specific forced to traverse these functions to effectively accomplish
header features, for example, source to destination delivery. the service. However, in current networks, the packets cannot
The field of “action” constitutes the forwarding information follow the strict requirements of SFC, where novel service
on receiving a specific rule, whereas the “status” entry shows provisioning techniques may require the deployment of certain
the current status of the flow. The secure channel provides middle-boxes. Due to the heterogeneous nature of current
an interface used by the controller to communicate with the networks and similar underlying nature of SDN and NFV, they
data plane devices to govern the network and transfer packets can be integrated to separate the network management function
[111]. The controller accepts PACKET IN messages from the from hardware to the software. Due to the virtualization ca-
switches for the new flows, assigns them a rule according to pabilities, NFV enables efficient network services deployment
the values in the header, and sends a PACKET OUT message at heterogeneous locations without using high-cost hardware
back to the switch. to fulfill SFC requirements. NFV can operate as a service
orchestrator in the programmable SDN paradigm where SDN
C. Edge Computing automates the service chaining by installing customized flow
The hierarchy of the edge infrastructure in the IoT paradigm rules at the forwarding stations [118], [119]. Seamless inte-
is shown in Fig. 4. This figure shows that the edge cloudlets are gration of SDN and NFV enhances network services where
placed between the cloud data center and IoT infrastructure, the network functions are implemented as software deployed
which provides intermediate offloading capabilities to the over servers. Implementing SDN and NFV over the IoT-
IoT devices [67], [112], [113]. The computation tasks that Edge will enhance the performance of SFC in latency-critical
need higher computational resources can be transferred to the applications and reduce the overhead of long-haul transmission
cloud infrastructure through edge devices [114]. The cloud delays. [120].
infrastructure contains sufficient computational and storage A minimal cloud application platform is necessary for the
resources to perform the required tasks. availability of computing, i.e., processing power, networking,
Edge-enabled devices like smartwatches, phones, and health and storage to the edge nodes to support IoT applications
bracelets have been widely introduced in the market during the [121]. In this situation, SDN and NFV technologies provide
past several years. These novel devices continuously create network services at the edge [32]. NFV brings computing in-
data logs, implement numerous services, and produce and frastructure near the edge of the devices for data-intensive and
transmit data to the network. However, most IoT devices low-latency applications. NFV replaces traditional high-cost,
are yet limited in computation capabilities and continuously vendor-specific, and specialized hardware capable enough to
need intermediate computation capabilities outside IoT. The provide services on low-cost devices for the data-intensive and
traditional cloud suffers in this situation due to the latency low-latency applications [122]. NFVs are flexible, which can
requirements of most of the IoT applications. Moreover, be launched and terminated on demand. In the same way, SDN
these devices have real-time requirements and Quality of is an optimal match for NFV from the edge to the network
Service (QoS) constraints that must be addressed by the [5]. SDN is capable of simultaneously reducing the cost and
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 9

for specialized applications and are not ready for edge cloud
because, in IoT-Edge, multiple IoT applications are deployed
in a shared edge cloudlet. There is still a need for the tools and
abstractions for distributed device management to optimize the
allocation of resources and fulfill IoT application demands.
3) Dynamic Offloading: In edge computing, the orchestra-
tor needs to continuously cooperate with IoT to handle the
offloading tasks and flexibly commit required resources [127].
The technology also lacks in providing a proper framework
for configuration, in addition to integration techniques to
optimally offload IoT applications and manage them on edge.
In this context, a virtual machine (VM)-oriented offloading
framework can be deployed and easily managed [28]. How-
ever, there is also a need to manage these VMs effectively for
specific IoT applications committed to the cloud. For such an
implementation, the solution must integrate NFV and SDN-
supported edge platforms for resource management.
4) Home Cloud: This is one of the typical examples of
SDN and NFV-enabled automated orchestration for dynamic
Fig. 5. High-level architecture of SDIoT-Edge. offloading [3], [128]. The home cloud proposes an open
framework for automated IoT applications for future edge
networks. It configures an efficient NFV and SDN architecture
enhances the programmability and flexibility of NFV due to for edge cloudlets for effective service orchestration at the
the separation of control and data planes. SDN and NFV are edge and supports dynamic offloading for IoT. Innovative
complementary resources for the effective implementation of cloud services use proprietary protocols that are closed, pri-
edge computing. The control-data plane separation enables vate, time-consuming, and are available in customized designs
ease of compatibility of NFV with the existing solutions. [58]. Similarly, these techniques are not portable on different
NFV provides the necessary infrastructure for SDN, over platforms. In such a home cloud orchestration framework, a
which it can operate. The convergence of SDN and NFV for specific northbound API has been provided to the application
edge computing brings novel research directions for innova- developers [27]. They use Service Level Agreements (SLAs)
tion toward cost-effective and fast services and application and transform them into deliverable objects that can be parsed
deployment [123]. In the future, edge implementation will to machine recognizable techniques for the allocation of re-
formulate a general perspective where the stakeholders might sources, configuration, management, and control. Finally, the
incorporate Application Service Providers (ASPs), Internet home cloud delivers core services that act as intermediaries
Service Providers (ISPs), software, and device vendors. The between edge service providers and application developers
convergence of NFV and SDN implies the upcoming fifth- to manage edge-based IoT applications for efficient service
generation (5G) networking paradigm and a trend toward delivery. This mechanism will provide characteristics of dy-
flexible software implementation. The 5G networking has been namic allocation, portability, and high scalability that are not
launched with fast video traffic, big data service capabilities, currently available in any cloud environment.
IoT processing, and providing wide adoption of Virtual Reality
(VR) applications [124]. The concept of network softwariza-
tion expresses the fact that all components of the network D. A Framework of Software-Defined Internet of Things using
are managed by the software. Therefore, enabling network Edge Computing
slicing into different logical units is imperative, where each An SDIoT-Edge architecture has been proposed in the
slice performs a different set of functionalities. literature, which deals with the IoT service orchestration issues
2) Dynamic Orchestration: Edge computing and its re- using edge computing [52]–[55]. Fig. 5 shows the architecture
alization in IoT is currently in its evolutionary phase and of SDIoT-Edge encompassing three planes including SDN
suffers from many challenges. One of the critical issues is the data, control, and an application plane [34]. In the data
effective cloud orchestration to monitor, select, control, and plane, IoT devices seek services for offloading the compute-
deploy the requirements of hardware and software resources intensive tasks. In the traditional SDN architecture, these
for application delivery [125]. However, the challenge is to planes reside at two different levels; the novelty of this archi-
provide orchestration facilities for IoT-Edge open-source cloud tecture comes from the northbound application plane, where
solutions [126], and commercially available providers such as customized northbound applications reside. These virtualized
Elastic Compute Cloud (EC2) do not provide the functionality applications decide the behavior of the control mechanism,
for IoT-Edge applications [18]. They still rely on the simple including end-to-end service orchestration [129]. Fig. 6 shows
analysis methods to assign the requests, which are prone to that the edge cloudlets are used to connect IoT devices with
errors for a sophisticated set of cloud services. Additionally, the data plane infrastructure. The SDN controller manages
most of the methods for service orchestration are customized all the components of the network, whereas the application
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 10

Fig. 7. Flow rule installation in an SDIoT-Edge network.

performance parameters. If a service has low utilization, this


module decides on migrating the VM that hosts this service
to another cloudlet.
3) Performance Tuning: The implementation of edge com-
Fig. 6. The components of SDIoT-Edge, redrawn from [34].
puting has been triggered by real-time application needs [132],
[133]. This module utilizes SDN and OpenFlow for managing
service utilization to balance or administer the load on various
plane incorporates the edge services to efficiently manage the servers.
SDIoT-Edge infrastructure. In SDN, the controller hosts dif- 4) User handover: In a diverse IoT network, devices may
ferent northbound applications to fulfill the required functions leave and enter edge cloudlets at runtime, causing service
and present a singular model to the requesting applications. disruptions due to the unavailability of handover mechanisms
Every application belonging to edge service orchestration uses [134]. This module provides forecasting information for the
northbound API and triggers events. In response to these next coverage areas and enables mechanisms for seamless
events, service requests are provided by the controller in services provisioning.
terms of commands [130]. Subsequently, these commands are The flow rule installation mechanism on the switches has
compiled and transformed to low-level OpenFlow messages been shown in Fig. 7. The figure shows that IoT initially
by the controller, which are then passed to the switches to requests the edge gateway, which then communicates with the
service the requests. data plane switch to fulfill the service request by using the
The motivation of SDIoT-Edge has been instigated by the proactive, reactive, and hybrid flow rule installation methods.
resource-limited nature of IoT devices. As the number of IoT The communication schemes in the SDIoT-Edge have been
devices is increasing exponentially with time, SDN becomes indicated with different colors.
a crucial management technology for such a huge network. A detailed SDIoT-Edge architecture is presented in Fig. 8,
SDN uses centralized network management to guide network which shows data plane, control plane, southbound commu-
traffic from the source to the destination. Hence, IoT devices nication interface, northbound RESTful API, and application
can be efficiently managed using SDN, whereas the edge plane. The data plane contains the resource-limited IoT de-
computing can provide offloading services near the resource- vices, which utilize the edge cloudlets to offload the compute-
limited IoT devices, which require a constant interaction intensive tasks. It communicates with the control plane using
among the IoT and edge infrastructure [52]–[55]. The SDIoT- the southbound interface, which employs OpenFlow protocol.
Edge architecture needs the following integral services to Moreover, the control plane uses the northbound interface,
optimally orchestrate the operational requirements of these which employs REST APIs to interact with the application
versatile architectures. plane. Network programmers can develop customized appli-
1) Service Discovery: It is possible that different IoT cations to desirably control the network traffic. The Base
devices have specialized functionalities and require various Station (BS) provides a communication interface to the edge
services from the network. Moreover, they may have no knowl- cloudlets and IoT devices. Moreover, edge cloudlets support
edge about the available edge services [19]. For example, there compute-intensive tasks on the resource-limited IoT devices.
is a need for an environment where IoT devices can make a The edge cloudlets comprise of low-capacity servers, which
request by identifying the required computation power and fulfill latency-sensitive service requests from the IoT devices.
storage [131]. This necessity is implemented by SDN, where Alternatively, the cloud data center contains sufficient re-
the service discovery module acquires information of available sources to support compute-intensive tasks at the cost of
services at the edge. higher latency. Here, SDN provides scalability for the efficient
2) Service Provisioning and Migration: This module pro- management and deployment of services compared to the
vides services onto the edge cloudlets based on different traditional approaches. For example, the group table speci-
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 11

Fig. 8. Detailed SDIoT-Edge architecture composed of three planes.

fication facility is available in the OpenFlow versions 1.1 and mization algorithms, originally developed for the central cloud,
further [111]. This implies multiple flows to be addressed which determines the optimal location to migrate the services
by the same group identifier, which enables the group table [136]. Scalability issues may arise due to the increase in the
entry to be inserted for multiple flows. This facilitates the network size where the network services can be virtualized
process of updating a set of flows by only updating the and deployed as separate applications at the application plane
referred group entry, compared to updating every single flow of SDN.
rule. Another critical factor is that it provides the support for
Any solution for SDIoT-Edge should consider the hybrid
incorporating multiple controllers associated with version 1.2
flow rule installation strategy to address the real-time needs
and above [135]. It enables the switch to communicate with
of heterogeneous IoT infrastructure. Moreover, a promising
the controllers as a single entity, although multiple controllers
solution would be the deployment of an in-band controller
are used that may act as a master, slave, or have equal roles.
strategy where the control and data traffic share the same
link. This technique reduces cost as it is expensive to provide
E. Lessons Learned: Summary and Insights separate links (out of band controller) for data and control
This section provided an architecture of SDIoT-Edge that for a large number of switches in SDIoT-Edge [103], [137].
supports the resource-limitation problem in IoT and offers cen- The traditional client-server communication style needs to be
tralized management of the underlying heterogeneous archi- replaced with a three-tier architecture having a specific set
tecture. Although the diverse SDIoT-Edge integration seems of coordination and orchestration features. In this paradigm,
promising for IoT service orchestration; it does raise consider- an intermediate network layer can provide a communication
able concerns of security, privacy, scalability, fault-tolerance, interface among edge resources. The application plane in
standardization, and interoperability that must be addressed SDIoT-Edge can be utilized to deploy novel service require-
prior to its realization. A large number of flows and massive ments instigated by the edge infrastructure, including service
amounts of data in IoT can congest the network and increase orchestration, security, and resource management. Addition-
the cost of transporting data from IoT devices to the cloud data ally, IoT devices need continuous offloading services, where
center. Edge analytics helps in data collection and analysis the sequence of committing the task to the edge and re-
at the sensor node, IoT infrastructure, network switch, or establishment of the connection, must be handled seamlessly to
any other device avoiding unnecessary data transfer to the address the service level requirements. Moreover, the control
central cloud [80]. Edge analytics can filter the data at the channel in SDN can become a bottleneck due to centralized
devices’ edge and transfer the necessary computation to the control. The distributed control paradigm can be deployed
central cloud. Moreover, the challenges of limited storage, to address this challenge; however, it raises multiple other
energy, computational resources, mobility, handover, and QoS challenges, including communication delay, controller-state
management induce complexities in the realization of SDIoT- synchronization, and security. Hence, the effective realization
Edge. User hand over can be handled by cloud access opti- of SDIoT-Edge depends on the fulfillment of heterogeneous
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 12

requirements of multiple architectures. to ensure the reliability of edge servers and the connected
IoT devices [140]. However, traditional cloud authentication
III. R EQUIREMENTS OF S OFTWARE -D EFINED I NTERNET techniques are challenging to implement in resource-limited
OF T HINGS AND E DGE C OMPUTING E COSYSTEM edge servers. Hence, minimizing the security overhead posed
by the authentication of the network elements is a critical
In this section, we discuss the requirements of SDN, IoT,
concern. Diverse communication technologies in SDIoT-Edge
and edge infrastructures that are critical in an effective real-
encompass different security protocols, which inevitably create
ization of the SDIoT-Edge paradigm. SDIoT-Edge employs
their own local trust domains [141]. In this situation, the
the virtualization of network resources to provide services
challenge of the credentials distribution at different locations
to heterogeneous devices. The transformation of hardware-
arises to enable an efficient global trust paradigm. A solution to
based solutions toward software gives rise to low-cost IoT
these challenges can be to devise global authentication policies
applications. In this regard, the requirements in the SDIoT-
for heterogeneous networks and infrastructures. The current
Edge paradigm must be effectively envisioned before any
solutions employ a certification authority that distributes the
actual implementation. The challenge of resource limitations in
session keys to authenticate the devices in their own trust do-
IoT devices can be effectively managed by bringing resources
main. However, ensuring the privacy and security between the
closer to the edge devices using the centralized control mecha-
devices residing at different trust domains is still a challenge
nisms of SDN. Each component of SDIoT-Edge encompasses
[55], [142], [143].
different requirements; therefore, a comprehensive discussion
The versatile nature of network elements in the SDIoT-Edge
on the requirements from the perspective of SDN, IoT, and
increases the vulnerability of launching an attack on the whole
edge computing is necessary. A taxonomy of the requirements
network using a single compromised device. One of the prime
in the SDIoT-Edge is presented in Table III, which shows the
concerns at the core network is to enable seamless security at
critical requirements, challenges, and relevant solutions. We
the host network. There are many drawbacks in the existing
discuss these requirements in the following subsections.
solutions because any Network Intrusion Detection System
(NIDS) will need additional infrastructure to handle a higher
A. IoT-Edge Management Using SDN level of aggregate data rates [144]. In the same way, network
Network traffic management is one of the core factors to operators are unable to provide a global view of the network,
effectively operate the diverse SDIoT-Edge infrastructure [34], which limits the application context of the security solutions.
[138]. Therefore, high-tech enabling devices are necessary to Moreover, the approaches based on host networks depend on
control, manage, and forward the network traffic flows and Operating Systems (OS) and can sometimes lead to local op-
to alleviate the impact of network delays. The information tima solutions. Therefore, there is a need for adequate security
in SDIoT-Edge will have to traverse multiple heterogeneous measures at the network level to avoid malicious activities
networks, including radio access, backhaul network, and the from adversaries where network-level security solutions will
Internet, where traffic control, routing, load balancing, and help in ensuring global authentication.
other management activities provoke increased traffic delays.
Network scalability, manageability, and efficiency require- C. Interoperability Among Heterogeneous SDIoT-Edge Infras-
ments can be adequately addressed by SDN-oriented solutions tructure
because of the centralized management capability [139]. In this
regard, SDN-backed solutions must be optimized to deliver Large-scale IoT manufacturing raises interoperability con-
efficient administration, e.g., balancing network load, effi- cerns where market-vendors are introducing non-standardized
cient traffic management, and concise bandwidth exploitation. IoT products to generate more revenue. Although it lower
Moreover, the standardization of A-CPI and C-DPI will pro- downs the infrastructure cost; however, most of the developed
vide a solution for the IoT-Edge management issues including products are vendor-dependent and suffer from interoperability
traffic forwarding, combating network delays, load balancing, issues. A vendor-independent environment is required to over-
and heterogeneity. come the complexities caused by heterogeneous manufactur-
ing. SDN has the potential to overcome vendor-dependency
due to the continuous standardization efforts by the Open
B. IoT-Edge Authentication Networking Foundation (ONF). Therefore, distinct Wireless
The SDIoT-Edge computing concept is based on the in- Sensor Networks (WSNs) and body area networks having
teroperability among different platforms using communication different underlying hardware can operate without compli-
protocols, heterogeneous message exchange, and virtualiza- cations [122]. The heterogeneous infrastructure and underly-
tion. These novel features invoke immense authentication ing communication technologies invoke interoperability issues
issues at the source network. First of all, the traditional where network traffic traverses multiple infrastructures. For
trust and authentication mechanisms might become incapable instance, a lower-latency resource request can be handled by
due to heterogeneity in communication infrastructure [64]. pre-processing it at the edge cloudlets and then transferring
Second, the diversity in the communication technologies and the remaining task to the central cloud. In this situation, the
the softwarization of the network management will provoke data will be traversing two different communication networks.
security issues, reliability challenges, and attack vulnerabili- Therefore, a unified management paradigm is required to
ties. A unified trust and authentication mechanism is required overcome the communication heterogeneity [145]. There is
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 13

a lack of interoperability protocols that provide seamless F. Flexible Innovation in SDIoT-Edge


interaction; however, the southbound OpenFlow protocol in Due to the lack of virtualization in traditional networks,
SDN is capable of operating among diverse network elements bringing innovation becomes a challenging task [150]. These
at the data plane. Moreover, SDN and NFV can be deployed to networks are not equipped with A-CPI standardization, which
provide mobility-aware VM management, which is capable of provokes traffic management issues. SDN provides network
alleviating the interoperability concerns. Additionally, standard programmability by decoupling the control and the data plane
communication protocols development and virtualization stan- in the IoT-Edge paradigm and enables dynamic services to a
dards for IoT-Edge will further enhance the interoperability in disparate set of devices [34]. The integration of edge servers
SDIoT-Edge. and IoT devices needs dynamic management. SDIoT-Edge can
be managed at variable levels of orchestration by deploying
D. Traffic Dissemination in Multiple Devices a centralized controller equipped with northbound applica-
Traditional networks fulfill the service requests by moving tions. In the traditional networking paradigm, the deployment
the data to the cloud and then bringing back the results to the of novel protocols provokes the need for new hardware or
device. This workflow generates a massive amount of network redesigning the switch-chips, which induces more cost. For
traffic [146]. Traffic overhead can be mitigated by keeping instance, implementing Virtual Extensible LAN (VXLAN)
the data at the edge. Effective traffic dissemination reduces [151], which is a novel cloud and data center protocol,
unnecessary bandwidth utilization, traffic rerouting overhead, will require upgradation of the whole infrastructure inducing
and overcoming network congestion caused by billions of more cost and effort. Instead, software switches like Open
devices [147]. IoT generated data can be preprocessed at the vSwitch can be programmed for customized traffic forwarding.
edge, which lower downs the excessive computation load at the Moreover, OpenFlow supports VXLAN, which ensures the
central cloud. SDIoT-Edge has the ability to solve the conges- implementation of the controller accordingly. Thus, SDN
tion problem within the core network and datacenters by traffic can treat the network as a flexible software [26]. However,
distribution at different edge servers [51]. However, orches- flexible innovation requires the standardization of the A-CPI,
tration requirements of application-specific request handling which will enhance the development and deployment of novel
to route traffic according to the user’s demands require novel applications in SDIoT-Edge.
traffic dissemination techniques. Customized traffic forwarding
applications utilizing the centralized management of SDN G. Seamless Mobility of VMs on Edge Infrastructure
can alleviate the traffic dissemination challenges in SDIoT-
Edge. The requests about applications should be forwarded by Mobility is one of the key characteristics of SDIoT-Edge
comparing them with the requests received at the intermediate applications. When the user moves, the distance among the
nodes, which will lower the related cost, network load, and corresponding servers increases, which deteriorates the user
traffic delays. experience [136]. In these applications, the trajectory of the
users provides their spatial preferences to the edge servers,
which can be leveraged to improve the service orchestration
E. Lower-Latency Requirements in IoT
efficiency. Secci et al. proposed a method, which links the user
Real-time applications like online gaming, VR, and ultra- mobility with the VM mobility [136]. This method then deter-
high-definition video streaming need extremely high data mines the best location for migrating the service to enhance
access rates at lower latency. Therefore, available edge so- the user experience. However, it is designed for the central
lutions become highly vulnerable in such cases due to the cloud, which needs additional enhancements for the SDIoT-
enormous amount of data produced by the loT. Moreover, the Edge. SDN provides the control and management capabilities
use of traditional authentication mechanisms among IoT and to migrate VMs over the edge infrastructure. It is challenging
edge increases the latency in serving the requests. Traditional to migrate a VM from one data center to another while
offloading solutions also add latency in the overall service the service is running. In the same way, ensuring seamless
orchestration process where efficient offloading solutions need service provision to IoT devices and addressing the requests
to be developed to fulfill latency requirements in the IoT. simultaneously is one of the key challenges. Therefore, the
For example, Foursquare [158] and Google Now [159] need seamless transportation of VMs without disrupting the services
to provide a real-time response to the users. Lower-latency is a core requirement to improve the QoS in data centers. NFV
requirements need reliable solutions where effective backup characteristics can be leveraged to perform network slicing and
links must be provided to ensure fault-tolerance. Latency- allow mobility-aware VM migration at the edge of the devices.
sensitive applications are in high demand due to extensive
progress in IoT where the information is generated and con-
sumed locally, avoiding extra overhead on the network [148]. H. Fault-Tolerance in SDIoT-Edge
Applications, such as autonomous cars, industrial robots, and The mobility of the devices poses significant challenges in
control applications, need a quick response time, which is providing reliable services to the users [152]. Computation
as low as 10-50ms [149], [160]. Moreover, smart vehicular offloading may suffer because of the frequent changes in the
technology is still in its evolutionary phase, where the commu- network connections and wireless channels. These changes
nication delay between the request generation and the service provoke a catastrophic impact on the latency-critical and
provision has not yet been optimally minimized. compute-intensive applications [153]. For example, augmented
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 14

TABLE III
A DETAILED TAXONOMY OF THE REQUIREMENTS OF SDI OT-E DGE .

Requirements Challenges Solutions


• Traffic forwarding issues.
IoT-Edge Management • Dealing with network delays. Standardization of
using SDN [34], [138], [139] • Heterogeneous network traversal by IoT traffic. A-CPI and C-DPI
• Load balancing requirements.
• Authentication of multiple devices.
IoT-Edge • Devices’ reliability issues. Global authentication
Authentication [55], [64], [140]–[142], [144] • Multiple local trust domains. policies
• Credential distribution issues.
• Heterogeneous product manufacturing.
Interoperability among • Vendor-dependent products.
Virtualization standards
Heterogeneous • Multiple communication technologies.
for IoT-Edge
SDIoT-Edge Infrastructure [122], [145] • Lack of interoperability protocols.
• Multi-infrastructure interaction of data.
• Heterogeneous traffic routing.
Traffic Dissemination • Diverse orchestration requirements. Customized application
in Multiple Devices [51], [146], [147] • Over utilization of network resources. development
• Traffic congestion issues.
Lower-Latency • Real-time applications need lower-latency solutions.
Efficient offloading
Requirements • Authentication mechanisms are time consuming.
solutions
in IoT [148], [149] • Lack of effective offloading solutions.
• Hardware-oriented traditional solutions.
Flexible Innovation
• Lack of virtualization. Standardization of A-CPI
in SDIoT-Edge [26], [34], [150], [151]
• Lack of A-CPI standardization.
Seamless Mobility • Mobility requirements.
Mobility-aware
of VMs on • Lack of mobility-aware VM migration.
VM migration using NFV
Edge Infrastructure [136], [136] • Real-time VM handling.
• Changes in the network connections.
Fault-tolerance • Wireless channel changes.
Backup channels
in SDIoT-Edge [152], [152]–[154] • Mobility of devices.
• Lack of backup channels.
• Lack of data classification methods at edge.
Data Classification Data classification
• Aggregate decision making on data.
on Edge [155], [156], [157] techniques
• Distributed nature of data.
• .Lack of global view of data.
Lightweight
Security and Privacy [16] • Location-based privacy issues.
authentication solutions.
• Platform-specific security policies.

reality-based applications aim at providing seamless and ex- links. Moreover, fault-tolerance can be achieved by micro
citing virtual experience to the users. Failure of the video BSs or central clouds that have larger coverage to provide
streams because of the intermittent network connections may seamless edge services. However, the challenge is to pro-
upset the users. Another example is the implementation of vide efficient QoS and energy consumption for the backup
SDIoT-Edge in the military, where high-speed and ultra- links and to handle protection clouds for the single-user and
reliable communication is always required in a high-mobility multiuser edge computing. Finally, fault-detection deals with
environment, faults in this scenario can be fatal and bring information collected by intelligent inspection techniques after
disastrous consequences. Hence, the design of a fault-tolerant defined intervals or using feedback on the provided services.
SDIoT-Edge paradigm is required, which can cope with the Moreover, time-efficient channel and mobility characterization
three major challenges comprising of fault-prevention, fault- methods would ensure fault identification. The fault recovery
detection, and fault-recovery [152]. The fault prevention in approaches should work in a way that the already running
SDIoT-Edge can be ensured by employing backup offloading services are not disturbed. Moreover, the affected services
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 15

can be migrated to the fault-tolerant wireless links equipped their own policies to access the data from a different perspec-
with adaptive power distribution mechanisms. The alternative tive, which raises privacy concerns. In this regard, lightweight
techniques include migrating the processes to neighboring authentication solutions are needed to deal with the privacy
servers by using direct or ad-hoc relay nodes [154], [161]. issues at distributed IoT-Edge environments.

I. Data Classification on Edge K. Lessons Learned: Summary and Insights


A massive amount of data generated by smart devices In this section, we provided the critical requirements of
poses a challenge to its effective handling. 5G/6G networks using SDN in efficiently managing and maintaining IoT in-
can efficiently address data classification issues by providing frastructure using edge services. Edge computing platforms
real-time data analytics capabilities. Moreover, the distributed are the core components for future IoT development and
nature of data presents challenges on data classification and integration. Some examples are home robotics, smart cities,
aggregate decision making. Data need to be classified at edge smart homes, VR, autonomous cars, crowdsourcing, and M2M
nodes to save upstream bandwidth where only the mandatory communications. The implementation of SDIoT-Edge needs
data is transferred to the central cloud. The data is classified immense technical considerations of the diverse underlying
based on latency requirements; if the computation is latency- platforms. Compared with the servers in data centers, IoT
tolerant then it is transferred to the central cloud, whereas devices possess limited resources that pose limitations on
the latency-sensitive applications are executed on the edge. executing complex computations. In this regard, compute-
In this situation, the classes may correspond to ”on-edge” or intensive tasks can be offloaded to the edge nodes that will
”on-cloud” computation. The examples of data classification save energy on IoT devices and help in performing the tasks
include AR applications where edge servers need to accom- on a remote resource. However, communication protocols need
plish multiple compute-intensive tasks in a shorter period, such to be developed to enable interoperability among different
as recognizing users based on their actions using pattern recog- technologies.
nition and predicting user requests through machine learning. Resource limitations in IoT need network-level security
Data classification may be completed by multiple edge servers solutions, where additional hardware/inspection techniques are
where aggregate decision making capability is needed based required at the data plane of the SDIoT-Edge to perform
on data collected at all the servers. Therefore, data reduction the network surveillance. Additionally, security applications
and classification techniques are of paramount importance can be developed and deployed at the application plane of
to enable cost-effective solutions [155], [156]. A technique SDN. Many open-source controllers provide the facility for the
for global data classification is proposed in [157] where the application development such as Floodlight, which is an open-
training task is performed at all the local fog cloudlets, and source controller that provides the facility to gather network
then these local models are aggregated to a global model. statistics using JSON-based REST API. Data centers have
However, this solution suffers from the challenges of lower- been continuously equipped with immense resources that can
accuracy and higher computational cost. fulfill the needs of IoT. However, as the number of IoT devices
Providing a global view of data will facilitate collaborative is increasing enormously, it is infeasible to process all the data
decision making, reducing upstream bandwidth, and overhead at the data center. Therefore, data classification strategies will
of transferring computation to and from the central cloud. play a significant role in future IoT-Edge networks. The com-
There is a need to devise techniques on edge nodes that can panies employing SDIoT-Edge can set parameters on deciding,
ensure the privacy of the data where a privacy-preserved copy which information needs to be transferred to the cloud or on-
of the data is submitted back to the IoT devices on request. premise data store. Therefore, future research can be directed
in developing novel low-complexity data reduction algorithms
J. Security and Privacy to address the IoT big data challenges. Hardware development
Securing network infrastructure is one of the prime con- for powerful edge nodes can also reduce the load from the
cerns in a heterogeneous environment where multiple users, central data centers; moreover, this can also facilitate in
devices, and vendors are participating on a single platform addressing the latency-sensitive IoT requirements. Therefore,
[16]. In the same way, IoT service orchestration involves an effective realization of SDIoT-Edge needs to consider the
data transfer to the multiple concerned parties. The network requirements of SDN, IoT, and edge computing. The efficient
infrastructure is owned by different vendors; so, the control of realization of these requirements can immensely improve the
such devices should be assigned to relevant hosts providing performance of the IoT infrastructure. The available SDIoT-
services. The data is generated by IoT infrastructure and Edge implementations provide a baseline to develop efficient
transferred to the local edge servers, which limit the global service orchestration frameworks. We discuss the available
view of data to devise security mechanisms. Data interaction at solutions in the SDIoT-Edge paradigm in the next section.
different platforms raises location-based privacy issues where
the location can reveal the identity of the data originator. IV. C URRENT S OFTWARE -D EFINED I NTERNET OF T HINGS
Similarly, service providers must abide by the access of big AND E DGE C OMPUTING I MPLEMENTATIONS
data that originated from encrypted resources [162]. Service The decentralized management in traditional networks
orchestration in IoT systems is based on diverse infrastructures makes them inadaptable to the requirements of novel IoT
integration. Therefore, different device authorities will have infrastructure. The novel network technologies such as SDN
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 16

can manage the network complexities efficiently and allow in [168], where a smart home connects different appliances
the development of applications and services that meet the with the Internet using Majord’Home management framework.
demands of IoT [97]. SDN enables the flexible configuration They considered the Connected Object (Co) and a Virtual
of the data plane devices and flow management, whereas Object (Vo) that are managed by an avatar. The ISP acts
NFV provides virtualization of the resources. The potential as the Majord’Home that provides user object management
requirements of the IoT-Edge include QoS guarantee, service by virtualization. This research [168] has been extended by
layer provisioning, and big data management [163], [164]. a generic framework for any smart IoT perspective [169].
We categorize the prevailing literature on SDIoT-Edge into The Co in previous research was extended as an entity that
multiple classes based on different features. A comparison can produce, get, and disseminate data flow in the network.
of the current literature on the SDIoT-Edge environment is This framework employs one vertical as well as three hor-
provided in Table IV. We categorize the literature based izontal planes. Data plane is composed of all the Cos that
on the underlying architectural characteristics, including OS, are able to generate and receive data without the mediation
communication between the planes, distributed data handling, of routing/forwarding procedures. The control plane consists
traffic management, and fault-tolerance. We discuss all the of two sublevels, where the first level is composed of a
categories below. controller, the second level consists of a CoVo controller,
and an application plane is on top of these two planes. The
A. RESTful SDIoT Architecture vertical plane is called the management plane, which owns
multiple management modules, such as the network manager,
REST API provides a communication mechanism in the
application manager, and a Vo manager that are represented in
application and control plane in SDN. The REST communi-
the operation support layer. For the proof of their concept, they
cation concept has been extended to provide communication
tested their platform with two Bob and Lice Majord’Homes,
among different layers of SDIoT-Edge [165]–[167]. A REST-
where each of them has one Open vSwitch, which connects
ful SDIoT architecture that accompanies multiple modules,
all of the home appliances. The CoVo-based ISP controller
such as API for the northbound plane, database, processor,
acts as the gateway of Majord’Home [169]. However, the
and southbound APIs was proposed in [165]. Usually, the
use of multiple controllers induces synchronization issues and
southbound interface handles protocols, such as Hypertext
increases latency in transferring state information among all
Transfer Protocol (HTTP) and Constrained Application Layer
the controllers. Although multiple smart home solutions have
Protocol (CoAP) in SDIoT. Most of the RESTful architectures
been presented in this section, the hierarchical controllers are a
own a processor and a storage database that stores node-level
soft target for the adversaries. The adversaries can attack the
information. The southbound API provides communication
state information between the controllers, which may cause
interfaces to the control plane and data plane, whereas the
inconsistencies in the synchronization of both the controllers.
northbound REST API connects the controller and application
This strategy may provoke the smart home appliances to
plane. Wen et al. proposed a REST framework for efficient
malfunction, which may cause life-threatening issues to the
IoT implementation using SDN, which contains northbound
smart home users.
RESTful API services to communicate with the application
plane [165]. A database provides IoT data storage to retain the C. Distributed Data Services
status information of nodes, topology, and task management.
IoT has been connecting billions of distributed devices all
A processor at the control plane ensures node layout, path
over the world; therefore, a resilient distributed architecture
transmission, and optimization. A southbound REST API is
is required for a seamless operation [173]–[176]. An SDN-
utilized for communication with the data plane devices. It
based IoT architecture employing distributed data services has
performs data format transformation, parsing, and transmission
been proposed by [173]. SDN provides mobility handling,
to and from the control plane.
flexibility, and data agility; at the same time, the dynamic
However, the discussed techniques lack offloading capa-
digital system manages big data aspects. The paradigm of
bilities using the southbound OpenFlow protocol. The edge
publish/subscribe is used to provide services to the WSNs.
infrastructure can be placed at the data plane of the RESTful
This data-centric approach provides the benefits of using data
SDIoT architecture to support latency-sensitive IoT applica-
as an addressable entity because IoT services are based on the
tions. These techniques employ a central cloud for request-
dissemination of the collected data. Their architecture consists
servicing, which may become ineffective for the IoT ap-
of three-layered domains, namely, an M2M domain that uses a
plications. Although RESTful SDIoT architectures facilitate
gateway to connect heterogeneous devices, a network domain
virtualization and interoperability at southbound and north-
that comprises multiple access networks, and an application
bound interfaces, the compute-intensive and resource-limited
domain that encompasses applications of IoT. However, these
applications can be efficiently managed at the edge.
techniques suffer from security and privacy issues where the
distributed paradigm makes the device authentication a com-
B. Smart Homes plicated task. The devices in one domain can be authenticated
The smart home is one of the most important use cases of using the authorization keys. However, authentication issues
SDIoT-Edge, where many examples of smart homes have been arise when multiple edge-oriented networks interact. There-
discussed in the literature [168]–[172]. An architecture based fore, a global authentication mechanism is necessary, which
on automating a smart home using IoT has been proposed can authenticate the keys generated in multiple networks.
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 17

TABLE IV
A TAXONOMY OF THE PREVIOUS LITERATURE ON SDI OT-E DGE .

Research Category Approach Used Scope Architecture


• RESTful Architecture. • SDN-oriented architecture with processor and a storage.
RESTful SDIoT Architecture
• North and southbound REST API. • Cloud support for providing virtualization services. SDIoT
[165], [166], [167].
• Centralized controller equipped with processor and storage. • REST APIs for north and southbound communication.
• Home management using trusted ISP services.
• IoT architecture for smart home management.
• IoT devices service orchestration using computation offloading.
Smart Homes [168]–[172]. • Virtualization services using centralized controller. SDIoT-Edge
• A multilayer SDN controller for granular management.
• A gateway Open vSwitch for communication.
• Data plane include an Open vSwitch to connect all the home devise.
• Data-centric approach to provide services. • Different architectural paradigms for different services.
Distributed Data
• SDN for virtualization. • Including publish/subscribe, layered, and centralized management. SDIoT
Services [173]–[176].
• Preprocessing of data before transferring. • Data classification and filtering before transferring.
• OpenStack and FlowVisor-based network partitioning. • Efficient IoT network management by allocating network resources.
Network Agility and • Preemptive flow rule installation. • Network slices are assigned to different controllers.
SDIoT-Edge
Virtualization [177]–[181]. • Open vSwitches and eNodeB for cloud support. • Ease of management and programmability using SDN.
• Edge services for compute-intensive tasks. • Efficient traffic management by proactive flow rule installation.
• NOS-based SDN controller support. • NOS extension for heterogeneous IoT management.
• SDN-WISE protocol support. • NOS having low computation power, memory, and processing.
NOS Architecture
• Customized OS for IoT. • Cloud support to offload compute-intensive tasks. SDIoT-Edge
[182]–[185].
• Support security through add-ons. • Provides kernel support other features by add-ons.
• Connectivity using bluetooth, Wi-Fi, and IEEE 802.15.4. • Provides interoperability, scalability, and connectivity.
• IoT agents learn a broader view of the network.
• The feasibility of incorporating interoperability.
• Install flow rules proactively.
Interoperability • Modularity among devices of different vendors.
• Openv Switch connect diverse set of devices.
and Traffic Engineering • SDN and NFV provide efficient IIoT management. SDIoT-Edge
• WSNs and diverse IoT devices are managed using SDIoT.
[186]–[189]. • Ubiquitous wireless broadband support by alternative routes.
• Better traffic engineering using management planes.
• Reduce packet loss using traffic management.
• Topology, admission control, and optimization planes support.
• Use of data service, control, and physical planes. • High privacy using different controllers.
• Address manageability, privacy, and scalability. • Controller for security, storage, and control.
Security Enhancement
• Separation of concerns provide granular security. • Security controller authenticates the network traffic. SDIoT
[26], [140], [190], [191].
• Traffic surveillance can be performed. • Security management using the Diffie-Hellman algorithm [192].
• Virtualization can provide effective security management. • Security management on top of underlying web-based architecture.
• Avoid faults in service orchestration. • Fault-tolerance using backup links.
• Application isolation in data transport. • Slight increase in overhead.
Fault-tolerance
• Fault detection using differential resource allocation. • Reliable service selection in VANETs. SDIoT
[152], [153], [193]–[195].
• Reliable distributed data storage. • Trust-based service provisioning.
• Authentication of IoT devices. • Reliable data transportation to and from edge.

D. Network Agility and Virtualization same physical location are considered, and the virtualization
process slices the resources into multiple logical functions.
Network agility corresponds to the programmability of the Physical resources at the same level are transferred using
modern networks, which leverages the separation of data and logical functions, whereas the user level virtualization is
control planes. It enables customized application development performed by having physical resources at different places.
at the application plane to flexibly control the network traffic. The software-defined infrastructure manager has been pro-
When addressing the SDN for IoT, an obvious challenge is to posed in [177], which utilizes OpenStack, a cloud-based
manage the communication among controllers and switches controller, and FlowVisor, which is a network controller.
[177], [178], [180], [181]. To efficiently deal with this chal- The FlowVisor carries out computation resource management,
lenge, a preemptive rule installation mechanism has been whereas the controller performs a versatile set of operations,
proposed by [179]. This work has been further fine-tuned such as network resource management, topology information
by providing the concept of a software-defined solution for collection, and managing Open vSwitches’ update process.
diverse IoT networks [186]. In this research, an IoT controller The FlowVisor layer is incorporated to allow partitioning of
interacts with the devices using the installed IoT agents. the network and allocating slices to a particular controller.
The interaction requests are recorded by the proposed IoT Tadinada et al. [180] described the benefits of using SDN
controller to learn a broader view of the underlying network for network agility, dynamicity, and flexibility to overcome
and to compute the forwarding rules that can be installed on the constraints of the traditional networks. They propose
the data plane switches. An overlay network is developed the VortiQa (an application development kit) open network
above these networks that allow a seamless collaboration director and the VortiQa open network switch by utilizing
among them. SoftInternet is a novel initiative for the future two SDN implementations for effective IoT deployment. In
software-defined Internet [178]. It provides connectivity and the first use case, a cloud-based controller manages the Open
management in a software-defined way to deal with the com- vSwitch, which acts as an IoT gateway managed by a cloud.
plexity and heterogeneity of the future Internet. The authors In the second use case, an Open vSwitch is placed on eNodeB
in [181] propose two virtualization levels, namely, an end-user (LTE radio access for indoor purposes) to offload data from
and network-level virtualization. In the later, devices at the the Evolved Packet Core (EPC) network, to provide better user
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 18

experience and decrease the operational and capital expendi- The prevailing solutions are equipped with auto-configuration
ture. The IoT gateway performs the functions of transmitting and recognition mechanisms, where switches and gateways
data among data plane devices, securing the devices, QoS dynamically perform management and configuration. The ap-
provisioning, and authorizing the devices to transport data plications, such as virtual sensors, software-defined wireless
safely among gateways and providing efficient access control. networks, and virtual cell management are utilized as use cases
Consequently, the eNodeB Open vSwitch provides separation to implement virtualization, where SDN and NFV provide
of planes and manipulates the packets in a way that they flexible IoT management [187]. The authors in [188] proposed
are not able to traverse the EPC network. The discussed an IIoT in ubiquitous wireless broadband for better traffic en-
virtualization techniques rely heavily on the hardware/software gineering in SDIoT, which includes three management phases
network infrastructure, which invokes higher capital costs. in a controller, including topology, admission control, and
These techniques may suffer from interoperability issues due optimization of location. The centralized management reduces
to the heterogeneity and vendor-specific technologies. More- packet loss by incorporating alternative route mechanisms.
over, security issues are inevitable due to the data transfer Although the traffic engineering techniques enforce optimal
among diverse platforms. path selection to control the network traffic, it becomes a single
point of failure in the in-band SDN control strategies where a
E. Network Operating System Architecture single link is used for the data and control path [103], [137].
Moreover, the available techniques suffer from interoperability
The heterogeneity is one of the main aspects of IoT. The OS
issues because of the diversity of communication protocols,
in IoT hides the complexities of heterogeneous components
each having domain-specific requirements. Therefore, stan-
and provides a generalized view to the developers by using
dardized communication protocols are necessary to deal with
network-level protocols, such as IPv6 [196] and 6LowPAN
interoperability issues.
[197]. The main characteristics of IoT-OS should be to provide
the ability to connect a massive number of heterogeneous
devices [182]–[185]. A Network Operating System (NOS) G. Security Enhancement
manages the heterogeneity in the network paradigm and en- IoT security is one of the prime concerns due to the un-
ables the use of different applications for a different set of availability of specialized security mechanisms in IoT devices.
network devices. In this regard, the authors in [182] proposed The research in IoT security has received immense attention
an OS for IoT to extend the NOS-based SDN controller, which during the past several years [26], [140], [190], [191]. To
employs the support of the SDN-WISE protocol that enhances address the issues of manageability, privacy, and scalability
the characteristics of SDN for WSNs. A programmable archi- in IoT, an architecture consisting of three planes, namely, data
tecture for SDIoT has been proposed in [183], using three service, control, and a data plane, has been proposed in [190],
layers of the controller to avoid a single point of failure. [191]. The data plane is composed of infrastructure devices,
TinySDN has been proposed and includes multiple controllers whereas the control plane has been divided into blocks that
over a WSN [198]. However, the authors do not explain the include Software-Defined Security (SDSec), software-defined
intercontroller communication and the selection process of controller, IoT controller, and software-defined storage. SDSec
the controllers. An SDN-WISE-based network OS has been performs data authentication and forwards it to the data
proposed in [185]. This OS treats the IoT network in a unified collector for processing. The data collector then forwards
way by providing a generic abstraction for the disparate IoT it to the IoT controller, which computes the path to the
networks. To connect diverse devices and networks, there destination and update rules. The authors in [191] propose
is a need to develop abstractions for network elements and a novel SDN-oriented WoT architecture that deals with the
communication protocols. Therefore, a unified OS can con- limitations of security, data, and things management. They em-
nect versatile networks in SDIoT-Edge. However, the update ploy Diffie-Hellman method [192] on top of underlying web-
patching, solution maintenance, and rollback are prime issues based architecture, which effectively hides the complexities of
in the current OS for low-powered devices. It is challenging to management and provides security. This architecture consists
update IoT solutions at remote locations having non-reliable of three planes, including access, control, and application
Internet connections and computational resource constraints. plane, to offer data access, control, and application services
The Internet and power failure spoil the update installation to the underlying network. The current security enhancement
where effective rollback mechanisms should be developed. strategies are either reactive, or they require higher compu-
Thus the development of a lightweight OS is necessary for tational resources to ensure security, which makes them hard
constrained devices where rollback, maintenance, and update to implement in the SDIoT-Edge. However, developing low-
patching issues are particularly addressed. cost proactive solutions is challenging in the resource-limited
SDIoT-Edge paradigm. Therefore, network security solutions
F. Interoperability and Traffic Engineering developed as flexibly deployable software at the application
plane of SDIoT-Edge can be extremely beneficial [200], [201].
As IoT networks are composed of heterogeneous devices,
efficient traffic engineering can provide optimum routes and
reduce network overhead [186]–[189]. The current literature H. Fault-Tolerance
regarding this paradigm discusses the feasibility of incorpo- SDIoT-Edge amplifies the service orchestration capabilities
rating interoperability among devices of different vendors. where the negligible bugs at a smaller scale or in the testing
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 19

TABLE V
A DETAILED TAXONOMY OF SDI OT-E DGE SOLUTIONS WITH REFERENCE TO DIFFERENT PERFORMANCE PARAMETERS .

Solution/
Research Category Scalability Security Offloading Application Domain Cloud Domain Feature
Architecture
RESTful Architecture [165] Low Low X Smart manufacturing - Framework REST services
RESTful SDIoT
Adaptive Transmission Optimization [166] Medium Low X Smart manufacturing Fog Solution Optimized communication
Architectures
Autonomic Computation Offloading [167] X General purpose IoT Edge/Fog Solution Computation offloading
Majord’Home [168] Low Low X Home networks Edge Framework Smart homes
HomeCloud Auto configuration [172] Low Low X Smart homes Cloud Solution Home appliances
SDLAN for Smart Environments [169] Smart Homes Low Medium X Smart environments Edge Solution Centralized control
IoT Big Data Analytics [170] Medium Low X Smart homes Fog Solution Data-intensive tasks
Smart Environments in IoT [171] Low Low X Smart environments Fog Solution Social IoT
Publish/Subscribe-enabled [173]SDN High Low X General purpose IoT Cloud Architecture Distributed control
Cross-layer Access Control [174] Distributed Data Medium High X General purpose IoT - Solution Security among layers
PICO Middleware [175] Services Medium Medium X Smart grids Central cloud Architecture Heterogeneous environment
Middlebridge for IoT [176] Low Low WoT Central cloud Solution Application layer middleware
Network virtualization [199] Low Low WSNs - Architecture Network virtualization
Software-Defined Infrastructure [177] Low Low Heterogeneous networks Central cloud Solution Flexible resource provision
Network Agility and
Smart Internet Provisioning [178] Low Low X Heterogeneous networks Central cloud Architecture Service-aware network control
Virtualization
Scalability for IoT [180] Medium Medium X Smart environments Edge Architecture Mobility management
Pre-emptive Flow Installation [179] Low Low Smart environments - Solution Efficient flows
NOS for IoT [182] Medium Low - SDN-WISE - Solution NOS for IoT
Programmable Architecture for IoT [183] NOS architecture High Medium X SDN Fog Solution Multiple controllers
Unified Control of Sensors [185] High Medium X WSNs Cloud Solution Unified control
Empowering IoT using SDN [186] Low Low SDIoT - - Traffic engineering
Interoperability and
SDIoT with NFV [187] Low Low SDIoT - Architecture Virtualization in IoT
Traffic
SDN for IIoT [188] High High X Smart manufacturing Cloud Architecture Reliability and security
Engineering
Containerized IoT Services [189] Medium Medium X Multi-access edge Edge Solution Virtualization in IoT
Secure SDIoT [190] Medium High X SDIoT cloud Cloud Architecture Storage and security
Virtualized Computation in IoT [140] Security Enhancement High High X 5G-enabled IoT Fog Solution Virtualization in IoT
WoT-SDN [191] High High X WoT Cloud Solution Scalable and secure WoT
CEFIoT [152] Low High X WSNs Edge/Central cloud Architecture Failure avoidance
Fault-Tolerant Data Storage [153] High High X Large-scale networks Edge Solution Fault-tolerant IoT-Edge
Reliable Multi-service Delivery [193] Fault-Tolerance High High X Vehicular networks Fog Solution Misbehavior detection
SIoTFog [194] High High X Large-scale networks Fog Solution Byzantine resilient IoT-Fog
Fog Computing for IoT [195] Medium Medium X Large-scale networks Fog Solution Bloom filtering to authenticate

paradigm (e.g., straggler [202]) might invoke debilitating as fog nodes. The breadth-first search and two Byzantine fault-
impact on system reliability. Fault-tolerance is an essential tolerant resource allocation strategies are used to distribute
characteristic in SDIoT-Edge due to the intermittent network fog node’s workload capacities to the requesting IoT users.
connectivity, resource limitation, heterogeneity, and harsh de- Authors in [195] use a certification authority to authenticate
ployment environments [152]. It is extremely necessary to en- the IoT devices to ensure fault-tolerance in IoT-Fog. The IoT
sure end-to-end delivery during data processing and transmis- devices use digital certificates issued by a specific certification
sion to and from the edge nodes. CEFIoT architecture [152] authority where a central fog node is responsible for certificate
uses application isolation, data transport, and multi-cluster revocation using bloom filtering.
management to ensure fault-tolerance in IoT applications. The Although the proposed approaches ensure fault-tolerance,
layered architecture of CEFIoT offers compute-placement on they induce more traffic delays during traffic inspection. Every
edge or cloud without code modifications. Similarly, energy- checkpoint adds a latency value to the data transfer; however,
efficiency and data reliability should be modeled in an inte- avoiding faults is imperative in the current information-centric
grated manner for the latency-sensitive IoT applications [203]. networks.
An energy-efficient distributed data storage method ensuring
Along with the solutions mentioned above, many state-
explicit data-reliability has been proposed in [153]. This
of-the-art edge architectures have also been proposed in the
technique adaptively reconfigures the system parameters in
literature. The ENORM framework provides edge computing
an energy-efficient way while ensuring continuous reliability.
facilities by bringing the computation resources close to the
Zhang et al. [193] propose a fault-tolerant framework for
edge of devices. It is composed of a manager that manages
trust-based service provisioning in vehicular networks using
edge nodes, a monitor, and a hardware layer that includes
integrated adversarial behavior detection. Fog computing is
the host OS and applications to communicate with the edge
capable of analyzing and storing related data in vehicular
of the devices [204]. The Open Carrier Interface (OCI) is
networks while retaining the dynamic trust weights based on
an open-source edge computing framework that provides an
attribute parameters of every vehicle. The weights are then
abstraction layer for the edge services [205]. This framework
incorporated into the proposed service delivery framework,
offers an interface for the network providers to enable edge
which contains trustworthy vehicle selection for misbehavior
computing. It is composed of global and local OCI, a resource
detection. A Byzantine fault-tolerant network to enhance trans-
manager, and an OCI library. The EdgeX Foundry project was
mission and processing efficiency using resource strategies
started by the Linux Foundation to develop an edge computing
for IoT-Fog computing has been proposed in [194]. It is a
framework [206]. The primary purpose of this project is to
three-tier heterogeneous IoT-Fog model consisting of routers
provide edge services for IoT ecosystems. This project uses
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 20

embedded devices such as gateways to support IIoT. An edge extra overhead of latency constraints and the abstraction of
computing framework for IoT was proposed by Eurotech a singular cloud. Moreover, the location-awareness must be
[207]. It can provide services to the devices developed using addressed explicitly because of the mobile nature of IoT
the Open Service Gateway Initiative (OSGi) and modular devices. Standardized test-beds for IoT experimentation are
IoT framework. The Edge-as-a-service framework has been highly needed, which can provide actual results. Finally,
presented for the distributed cloud in [208]. It consists of a we have discussed multiple proposals to solve the service
discovery platform that identifies edge devices and makes them orchestration problem in IoT; however, there is still a need to
available for service provisioning, where a service provider develop real solutions that explicitly address these problems.
facilitates the offloading requests.

I. Lessons Learned: Summary and Insights V. C ASE S TUDIES


Table V classifies the literature on SDIoT-Edge using eight SDIoT-Edge enables efficient resource management using
different parameters. The category parameter corresponds to programmability, computation offloading, and dynamic con-
the broad classification of the proposed techniques discussed trol. In this section, we discuss the use cases of SDIoT-Edge,
in this section. The scope and architecture of these techniques including smart cities and intelligent healthcare. We select
are also presented in Table IV. The scalability shows how these two case studies because of their higher influence in
the solution performs when exposed to higher workloads or facilitating human lives where the smart cities enable sustain-
an increased number of devices. The IoT infrastructure has able living standards, whereas intelligent healthcare ensures a
been growing tremendously; therefore, scalable solutions are healthy lifestyle using smart healthcare infrastructure.
required for the future needs of IoT. The offloading parameter
corresponds to the computation offloading capability in the
A. Smart City
solution. The application domain illustrates the application
area, for which the architecture has been proposed. The cloud The miniaturization of the sensory technologies provoked
domain demonstrates the provisioning of cloud infrastructure, immense development in the smart cities [160], [209]. Smart
including edge, fog, and the central cloud paradigm. In the cities facilitate the citizens to enjoy a secure, autonomous,
last two columns, we show that the current research provides a and reliable lifestyle using the smart infrastructure. Compute-
solution or only proposes an architecture, whereas the feature intensive applications in smart cities produce an immense
column demonstrates a key aspect of the solution. The best amount of data that needs latency-aware computation tech-
solution for SDIoT-Edge should be highly scalable, provide niques. SDIoT-Edge efficiently manages smart city infras-
high security, and should support computation offloading ca- tructure by addressing the requirements of fault-tolerance,
pabilities using the edge infrastructure. latency, security, and reliability. Smart cities can get extensive
As mentioned in the above discussion, there are numerous benefits from SDIoT-Edge including flexible innovation, traffic
proposals for the effective adoption of IoT-Edge infrastructure dissemination on multiple devices, infrastructure management,
that have been proposed. However, the improved features and and interoperability among heterogeneous devices. In this
diversity of the devices increase complications and hinder their section, we provide two detailed use cases of the smart cities,
adoption. Though the provided abstractions are comprehensive including Intelligent Transportation Systems (ITS), and smart
for small IoT architectures, there is still a need to develop homes in the following.
scalable and secure solutions for the SDIoT-Edge ecosystem. 1) Intelligent Transportation Systems : IoT enables a novel
SDN provides the basis to re-visit the deployment of network paradigm of the Internet of Vehicles (IoV) infrastructure,
functions. It promotes the idea of the softwarization of the which utilizes edge computing to offer novel services for
infrastructure, which supports heterogeneity and dynamicity. transportation systems. In an ITS, IoV connects different
The gateway switches managed by SDN can operate as ingress vehicles with the Roadside Units (RSU) and the other vehicles
hardware to support the connected IoT infrastructure. SDN using sensors and geofencing technologies. IoV leverages the
enhances IoT network management functions to cater to the edge cloudlets for service provisioning and orchestration. In
challenge of high scalability. Although it provides efficient this paradigm, SDN enables virtualization of the resources,
management, centralized control poses issues of throughput, which transform hardware-oriented services into software-
latency, availability, and single point of failure of the network. based solutions. Tremendous research has been currently per-
Even though numerous ideas and solutions toward wider formed on smart vehicles in academia and industry [210]. ITS
implementation of IoT are conceived, the novel complexities has been currently used with battery-powered smart vehicles
of the disparate infrastructure hinder their adoption. It has to provide Eco-friendly transportation services. A use case
become relatively easy to develop novel solutions for IoT. of pay-per-charge has been adopted in Germany, which uses
However, novel solutions need to consider standardization crowdsourcing to charge the battery-powered vehicles [211].
and existing solutions to enhance interoperability among the This ITS ecosystem requires the integration of smart charging
prevalent devices. The existing solutions lack in addressing stations, vehicles, and payment facilities with the cloud. Smart
all the critical aspects of IoT to enhance seamless service vehicles can assess the nearest charging station and book an
provisioning and prompt support. A distributed service provi- appointment on a mutually acceptable charging price. The
sioning solution can be considered to overcome the resource- charging price can be paid using the smart online transaction
limitations in the edge cloudlets. However, this may cause without a significant interference of the user. In this situation,
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 21

SDIoT-Edge comes into play to support the whole ecosys-


tem by handling runtime transactions and charging stations’
appointments at the edge. These vehicles use the installed
sensors to perform most of the tasks autonomously. Edge
computing provides the capability to perform surveillance with
a 360-degree view of the vehicles from the other vehicles and
geofencing boundaries. The sensing capabilities provided by
the brake sensors, measurement sensors, and positions sensors
enable appropriate decision-making abilities for the controllers
to take countermeasures.
Fig. 9 shows an ITS paradigm in a smart city. We can
observe the RSUs, which provides the communication ser-
vices to the driving vehicles. The Roadside Unit Controllers
(RSUC) manage the RSUs and are controlled by distributed
controllers presenting a logically single view of the SDN
controller. The distributed SDN controllers in the ITS provides
services of traffic management, edge resource discovery, and
mobility management. The BSs shown in the figure facilitate
the accessibility to the edge services. Edge computing in
this architecture provides efficient low-latency services to
the users. The ITS has been equipped with the OpenFlow
protocol, which is governed by the distributed controllers
at the control plane. The vehicles are equipped with long-
distance 5G/6G/WiMax connections for the communication.
The ITS ecosystem enables communication with the fueling
stations, payment endpoints, and the emergency infrastructure
connected by the Internet backbone. A hybrid communication
procedure has been utilized where the distributed controllers
send the abstract rules to the RSUC, whereas the precise
control has always been decided by the control plane. The
vehicles continuously communicate with each other using sta- Fig. 9. A smart city paradigm using SDIoT-Edge ecosystem.
tus messages as well as with the geofencing and surveillance
infrastructure. The controllers maintains a global connectivity
graph using the information propagation from the RSUC vices in smart homes produces a massive amount of data,
and the BS, which facilitates a centralized decision-making and the real-time analytics of the data can provide immense
capability. opportunities in realizing smart city concepts [48]. For exam-
Communication in the ITS includes control and data traffic. ple, the fire stations of a smart city can monitor the real-time
Edge computing provide low-latency services to the request- status of the homes and provide rapid response in case of an
ing ITS applications. SDN in ITS provides virtualization, emergency. Similarly, smart hospitals can monitor the patient’s
whereas BSs and RSUC can handle the hypervisor for VM daily routine in smart homes and propose remedial prescrip-
management, which enables portability and efficient resource tions to patients. These opportunities enable a significant cost
utilization. The application plane in the SDN enables mobility- reduction and improved living standards.
aware VM management. Vehicles in the ITS are continuously Smart homes are usually composed of sensors equipped in
moving and need to distribute the offloaded tasks considering the appliances. The categories of components in smart homes
the service mobility and topology changes. ITS employs can be physical systems, communication, and context-aware
the Service-Oriented Architecture (SOA) for the low-level components. The physical systems consist of the home appli-
message exchange. The controller, BS, and RSUCs provide ances equipped with sensors that are capable of capturing and
services according to the installed software. For instance, forwarding sophisticated measurements. The communication
consider a task that needs to be performed in an ITS that may systems provide connectivity in the smart home ecosystems,
need operations at different endpoints in the system. Here, whereas the contextual systems provide intelligent decision-
the SDN controllers manage the services at different service- making capabilities that have been moderated by the rules
providing platforms and stores the results. Finally, the control provided by the administrators.
plan incorporates the results of all the subtasks and provides Fig. 9 also shows a use case of a smart home in a smart city
the cumulative results back to the request originator. scenario that uses edge computing infrastructure for offloading
2) Smart Homes : The available smart homes’ use cases the latency-sensitive tasks. The home appliances are connected
provide the framework for future living in a smart city with the gateway that further connects to the distributed
paradigm. Many companies have been working on prototype controllers and the edge infrastructure. The smart home is
solutions for smart homes. The interaction among smart de- connected to the fire stations and hospitals, which communi-
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 22

cate using the wireless infrastructure. Smart home applications


continuously generate data, where the analysis of the data
provides opportunities for understanding the dynamics of the
homes. As smart home appliances do not contain sophisticated
data storage capabilities, they need cloud storage services.
The edge nodes are capable of processing the data streams
continuously from smart homes and providing storage at the
edge of the devices. Moreover, it offers processing capabilities
in near real-time. The unification of edge computing in smart
homes solves the challenge of latency-sensitive computations,
which was previously caused by the transport protocol of the
cloud [170], [212].

B. Intelligent Healthcare
SDIoT-Edge can be extensively used in the healthcare
industry to control diseases, perform skilled diagnoses, and
help in executing complex surgical treatments (e.g., spinal
surgery) at remote locations. It facilitates sensors to collect
medical data and assist in critical decision making [213].
It addresses the critical healthcare requirements of latency,
fault-tolerance, traffic dissemination, data classification, and
security. It supports the mobility of healthcare and AR in-
frastructure by providing mobility-aware VM migration. The
immense amount of data generated by intelligent healthcare
infrastructure can be adequately managed by edge cloudlets.
It invokes the AR concept to perform medical treatments at
remote locations. Moreover, SDIoT-Edge supports innovation
in intelligent healthcare by application development to flexibly Fig. 10. A smart healthcare paradigm employing medical sensors at the data
plane including AR, patient management, and other IoT sensors.
manage critical healthcare traffic. We provide SDIoT-Edge use
cases in healthcare in the following.
1) Smart Health Monitoring Systems: Smart healthcare
is envisioned by offering low-cost and effective real-time The real-time data processing needs can be handled using edge
healthcare facilities ubiquitously. Smart health monitoring is computing.
a promising field that lies on the intersection of medical In SDIoT-Edge, the sensor nodes record and transmit data
informatics, public healthcare, and cognitive capabilities using to the edge cloudlets using BS. SDN and edge computing
the IoT. The SDIoT-Edge-enabled smart healthcare system has can collaborate to execute latency-critical tasks from hetero-
been shown in Fig. 10. This architecture supports medical de- geneous medical devices. The gateways are used as central
vices to share data using gateways, whereas the edge cloudlets hubs between medical devices and the edge cloudlets. SDN
provide offloading services to the resource-limited healthcare and edge computing empower the healthcare network to
devices. The smart health monitoring system uses the concept maintain mobility, scalability, low-latency, and load balancing
of ubiquitous computing and ambient intelligence that is aug- to develop remote healthcare systems. SDIoT-Edge provides
mented in the personalized healthcare systems. Smart health extensive capabilities in smart healthcare for infrastructure and
monitoring is associated with the wellbeing of humans by data management. However, because of the critical nature of
smart decision making based on collected data from biomedi- latency-sensitive data in healthcare, deciding the local and
cal sensors, genomics, wearable sensors, and social media. The remote execution of tasks is imperative where hierarchical
data from biomedical sensors is critical, which needs prompt computation partitioning techniques can be employed for deci-
processing to support intelligent decision making. The smart sion making. Network resources can be virtualized using SDN
health monitoring systems connect tiny nodes having sensing and NFV, where the latency-sensitive resource requests can be
and actuating capacities embedded inside or outside the human processed at the edge. Personalized resources can be allocated
body. As the data generation and processing devices have according to the health status of the patient using intelligent
been immensely increased, the smart healthcare data needs disease analysis. The issue of mobility and scalability arise
to be retrieved, updated, and transferred efficiently. SDN in due to a significant number of mobile medical devices, which
healthcare provides heterogeneous infrastructure management can be managed using mobility management and resource
where the traffic from a large number of sensors can be discovery services in SDIoT-Edge. There is an immense poten-
efficiently directed using the OpenFlow protocol. Moreover, tial of SDIoT-Edge in the healthcare technology where smart
the network programmability of SDN facilitates data transfer healthcare infrastructure can interact for aggregated decision
among medical devices manufactured by different vendors. making, which will enhance the patient monitoring and overall
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 23

healthcare facilities. to the next maintenance. By using a system dashboard, the


2) Augmented Reality in healthcare: AR-enabled smart managers can make decisions and adjust the values to prolong
healthcare facilities support users by offering smart medical the maintenance schedule of industrial components. The same
care, remote live support, smart web-based AR features, and data is available to the on-sight technicians in the form of AR
patient monitoring facilities. The AR example using SDIoT- solutions with maintenance instructions. Technicians and the
Edge has been shown in Fig. 10, which presents the communi- experts collaborate through three dimensional AR animations
cation of the AR system with the controller using the wireless remotely.
gateways. Edge cloudlets are deployed near the edge of AR to
support latency-sensitive data transfer to and from the AR ap-
plications. The application plane provides mobility-aware AR C. Lessons Learned: Summary and Insights
management for seamless service orchestration. AR supports The big data generated by smart infrastructure in SDIoT-
medical specialists to inspect the patient, ask questions, and Edge needs real-time treatment, which suffers from uncertain
prescribe the medicines remotely. SDIoT-Edge can effectively provenance challenges. Traditional data processing techniques,
enhance AR implementation in the medical industry. Currently, such as Structured Query Language (SQL), fails in this
hospitals are digitizing the medical process; for instance, the paradigm. Therefore, machine learning techniques can be
patient’s body can be digitally mapped for surgery or even applied to the generated data to ascertain key insights that
venipuncture using AR. SDIoT-Edge can be used to manage help in critical decision making [214]. Consequently, data
patients’ medical records, their current health status, and time management is critical in the smart infrastructure as the quality
to the next medical checkup. A software dashboard is utilized of any smart system depends on precise decision-making
by the doctor, who receives information from the sensors capability. Moreover, the data generated by the smart city
attached to the patient’s body to make real-time decisions. infrastructure needs cost-effective solutions closer to smart
The same data is available to the on-sight medical staff in devices. The pre-processing of the data needs to meet the
the form of AR solutions with diagnosis instructions. The latency requirements, as the data from the surveillance in-
doctor and the support staff collaborate using AR to provide frastructure, healthcare measurements, and transaction records
medical services to the patients. AR requires latency-sensitive need real-time processing. This requirement can be fulfilled
solutions that can be provided by the edge infrastructure. On- by the edge computing infrastructure. Data in smart cities
sight sensors use edge cloudlets near them to process latency- and healthcare comes from heterogeneous resources at high
sensitive applications. Heterogeneity in the infrastructure can volumes and velocity where edge computing may operate as
be handled by the virtualization offered by SDN and NFV. a pre-processing resource. Similarly, smart healthcare requires
The controller in SDIoT-Edge uses OpenFlow messages to performance integration, and virtualization services to support
drive the network traffic and ensure end-to-end information the latency-critical and compute-intensive tasks of AR. Fur-
delivery. Hence, smart sensors, edge cloudlets, and SDN offer thermore, the protocols in the smart infrastructure need to
extensive support for AR applications in healthcare. be aligned with the available M2M, and WSN standards as
AR requires compute-intensive computing capabilities due the development of novel protocols involve higher costs and
to having CPU and GPU-intensive AR algorithms. A novel interoperability issues.
signaling architecture is required to predict AR demands to This section provided two case studies using the SDIoT-
support real-time network adaptation for varying resource Edge for seamless service orchestration, including smart cities
demands of AR applications. The AR computation in SDIoT- and smart healthcare. Besides the tremendous achievements
Edge is distributed on several nodes comprising of access in the smart city domain, enormous challenges still exist, in-
points, BS, gateways, traffic aggregation points, routers, and cluding heterogeneity in communication infrastructure, diverse
switches, etc. Here, the BSs are composed of the digital signal QoS requirements, and scalability issues. In this regard, the
processors customized according to their workloads. SDIoT- Software-Defined Internet of Vehicles (SDIoV) architecture
Edge distributes the load at one BS to a nearby BS using can provide effective management in the heterogeneous IoV
centralized traffic management. Moreover, AR applications paradigm. Vehicles in the IoV change locations from one RSU
use hardware from different vendors and employ different to another, which needs mobility-aware service provisioning.
communication protocols that can effectively be handled by Moreover, the security of IoV is vital, which can have dam-
SDN. The SDN controller can program the compute-intensive aging consequences. For instance, an adversary can access the
traffic from the AR sources using the OpenFlow protocol to vehicle and modify the lane information, which might result in
the edge cloudlets’ proximity. Moreover, the REST API at accidents. Edge cloudlets in smart healthcare might be placed
the northbound interface of the SDIoT-Edge is capable of in the eNodeB or near user equipment. The eNodeB needs to
providing an interface for application development to forward provide coverage to a large number of users, which require
traffic in a customized way. higher computational power, whereas placing edge nodes near
Moreover, SDIoT-Edge can be used to support AR in the the user equipment will require less computational resources;
industry by explicitly focusing on human-machine interac- however, it will impact the coverage. Data in IoV suffers from
tions. This paradigm includes AR to enhance physical and intense spatial and temporal variations that may congest edge
sensory experiences through digital graphics and computer- computing BS. Moreover, the dynamic resource provisioning
generated simulations. AR technology can be used to keep the might suffer from under-load or overload resource utilization,
track record of industrial products, their efficiency, and time which provokes QoS, performance degradation, and loss of
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 24

revenue. The resources in the edge computing are virtualized


to fulfill the application needs. However, the VM energy
consumption of the idle state is 60% than that of the active
state; so, underutilization of the resources must be avoided.
Future smart cities and healthcare will produce an immense
amount of data that will need efficient management, where
edge computing and the central cloud will play a pivotal
role. However, there is still a need for seamless integration of
distributed edge cloudlets and the central cloud for continuous
service orchestration, which can be achieved by standardiza-
tion efforts. There is a need to devise protocols at different
levels of SDIoT-Edge for efficient resource delivery.

VI. S OFTWARE -D EFINED I NTERNET OF T HINGS AND


E DGE C OMPUTING S TANDARDIZATION
Fig. 11. The IoT protocol stack.
Standardization is a key enabling factor to achieve high
adoption due to the complexity in the integration of diverse
platforms. A comprehensive standardization framework is
required for the effective realization of IoT in the current
communication-intensive paradigm [215]. During the start of long-distance IoT communication at lower bit rates. Long
Internet technology, TCP/IP was an essential standard toward Range (LoRa) is an LPWAN technology based on the spread
the revolution of the Internet. However, by analyzing TCP/IP spectrum modulation technique. It is a non-cellular LPWAN
from the IoT perspective, we can find that most of its protocols wireless communication network protocol that operates in the
at different layers are not implementable in IoT [216]. The license-free spectrum like 169 MHz, 433 MHz, 868 MHz
computation resource constraint must be considered before (Europe), and 915 MHz (North America) supporting long-
any IoT standardization. Moreover, an extensive study from all range communication with lower power consumption. It dis-
prospects must be performed before any IoT standardization tinguishes itself from Wireless Wide Area Network (WWAN),
because the security element in the most widely used IP pro- which was designed to provide connectivity to the businesses
tocol has not yet been utilized due to the high cost associated carrying more data, which consumes more power.
with it. We discuss the separate standardization measures in
the SDIoT-Edge ecosystem. Table VI presents the standards Various IoT standards have been developed including IEEE
in SDN, IoT, and Edge computing, their characteristics, and [218], Thread Group [219], and Open Interconnected Con-
application scope. The characteristics correspond to the type sortium [220], [221]. Any protocol for IoT standardization
of requirements that the protocol can address in the heteroge- must consider resource limitation of the IoT infrastructure.
neous SDIoT-Edge computing. Various working groups have been devised to standardize IoT
communication protocols that are adaptable to the current
TCP/IP paradigm. CoAP and Constrained RESTful Environ-
A. Internet of Things Standardization
ments (CoRE) are the prevailing examples of such protocols,
IoT comprises of low-cost and resource-limited devices as where CoAP is a lightweight HTTP version, whereas CoRE
compared to the traditional computing infrastructure. Most is a RESTful API for the application layer of IoT [222].
of the IoT devices possess lower energy and employ low- The Datagram Transport Layer Security (DTLS) is one such
end microcontrollers with limited memory. The traditional secure transport-level protocol that is suitable for resource-
Internet protocols are not supported by these devices, which limited IoT devices employing User Datagram Protocol (UDP)
pose a greater challenge on the communication of IoT. Re- for transport layer communication [223]. The Routing Over
cently several IETF working groups have been created to Low Power and Lossy Networks (ROLL) working group has
address these challenges. Fig. 11 shows the IoT protocol stack designed a novel protocol for IPv6 for Low Power and Lossy
representing protocols at different layers [217]. It shows the Networks (RPL) at the Internet layer of the IoT protocol stack.
communication standards at all the layers that are responsible In the same way, IEEE has developed 802.15.4, constituting
for the service orchestration. IETF standardization efforts have MAC, and the physical layer of the TCP/IP protocol. Bluetooth
played a key role in establishing light-weight communication Low Energy (BLE) is a standard that is characterized by
protocols for the IoT, deployed over the prevailing IP network. low energy and the use of a fair data rate, which makes it
IEEE 802.15.4 standard has been designed for the Wireless appropriate for IoT applications [224].
Personal Area Networks (WPANs), which defines the interac-
tion among the physical and media access control layers under The protocols mentioned above may further increase com-
the low-resource constraints, as shown in Fig. 11. For instance, plexity and not yield improvement for IoT; hence, there is a
6LoWPAN is a lightweight protocol that ensures the delivery need for dedicated communication platforms designed after
of IPv6 packets over the IEEE 802.15.4 wireless networks. the consideration of the challenges and needs of the IoT
Similarly, Low-Power-Wide-Area Network (LPWAN) supports infrastructure.
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 25

TABLE VI IEEE have developed SDN standards [123].


S TANDARDIZATION EFFORTS IN I OT, SDN, AND E DGE COMPUTING . IEEE has been widely involved in developing standards
Technology Standards Characteristics Applications Scope for the SDN/NFV ecosystem. Such an effort to standard-
• Application specific ize the services life-cycle is the Next Generation Overlay
service provisioning
CoAP, CoRE,
• Authentication
Networks (NGSON) standard, which defines the protocols
MQTT, AMPQ, Application layer
XMPP
• Flexible innovation for service composition [225], self-organizing management
• VM mobility
IoT • Security and privacy
[226], and content delivery [227]. A framework as a reference
• Data transfer has already been developed for collaborative and customer-
UDP, DTLS • Traffic dissemination Transport layer
• Data classification
centric service delivery. IEEE standard for SDN/NFV security
RPL(RoLL) • Traffic dissemination
Internet layer
[228], performance [229], and reliability [230] defines security,
6LoWPAN • Data transfer performance, and reliability models. Each model includes
IEEE 802.15.4 • Physical connectivity
Network/link layer standard terminology, analytics, and essential components of
IEEE 802.15.4 PHY/ • Interoperability
Physical Radio • Fault-tolerance SDN/NFV. The IEEE standard for software-defined quantum
• Southbound
communication communication defines an interface to quantum communica-
C-DPI
OpenFlow • Interoperability
communication tion devices for the reconfiguration and implementation of
• Flexible innovation
SDN
• VM mobility diverse protocols [231]. Moreover, SDN bootstrapping proce-
• Northbound dures [232], SDN-based middleware solutions for control and
communication
• Flexible innovation management networks [233], recommended best practices for
A-CPI
REST API • Fault-tolerance
communication
network reference model, and functional description of IEEE
• VM mobility
• Security and privacy
802 access network standard [234] have also been developed
• Authentication by IEEE.
• Southbound
communication
Extensive NFV standardization efforts are going on where
C-DPI
OVSDB • Interoperability
communication
IETF RFC 7665 was published in 2015, describing the frame-
• Flexible innovation
• VM mobility
work to create and maintain SFC operations [235], [236]. ETSI
• OpenFlow switch NFV working group was formulated in 2012 to standardize
communication the virtualization of network functions and define a frame-
OpenFlow
• Interoperability
OF-CONFIG configuration work to overcome the challenges of the novel architecture.
• Flexible Innovation
of switches
• VM Mobility Moreover, ETSI has published more than 50 group reports
• Security and privacy
• Cloud services on security, service orchestration, and use cases [119]. Two
at edge within RAN working groups, IETF and IRTG, in the Internet Society
in 5G and 6G
Multi-access edge • Fault-tolerance Edge-device (ISOC) are working on SDN standards. Two further working
Edge
computing • Latency-sensitive communication groups, i.e., Interface to Routing Systems (I2RS) and SFC,
applications
Computing
• Traffic dissemination
have been working on SDN standardization under the IFTF
• Data classification organization. In the same way, IRTG has been involved in
• Resource visibility
and control
publishing Request for Comments (RFC) titled “Software-
• Localized command Defined Networking: Layers and Architecture Terminology”
control, and processing
OpenFog
• Autonomy Cloud-IoT
standard [165]. The ITU-T has four working groups SG11,
reference
architecture
at all levels resource-provision SG13, SG15, and SG16 that are working on SDN standard de-
• Orchestration and velopment projects. Furthermore, various open-source projects
analytics
• Virtualization and are being developed, including an open network operating
multi-tenant system, OpenDaylight, Open vSwitch, OPNFV, and Floodlight
• Mobility support
• Decreases latency Parallel open SDN controller [145].
Mist computing • Higher efficiency computation IPsec protocol is a fundamental component of the Software-
• Minimal connectivity on IoT
• Privacy-preserving Defined Wide Area Networks (SD-WAN). It protects IP traffic
at the network level. The Internet Key Exchange (IKEv2) is a
key management protocol that is used in collaboration with the
B. Software-Defined Networking and Network Function Virtu- IPsec protocol. However, it suffers from scalability challenges
alization Standardization due to the increase in IPsec entities. A flow-based solution
develops security associations to defend against unauthorized
OpenFlow is one of the first SDN standards released by access and scalability challenges [237]. ONF has also formed
the Open Networking Foundation (ONF), which defines the a working group to standardize the northbound interface of
interaction of the controller with the forwarding devices [111]. SDN [238]. It will accelerate the whole SDIoT-Edge paradigm
OpenFlow is governed by the SDN controller; it is a powerful because a northbound interface is integral in accomplishing
protocol that enables the management of forwarding tables of the application-to-control plane communication. SDIoT-Edge
the remote network switches. Efforts in the standardization intends to employ the prevailing standards devised by ONF for
of SDN and NFV have not been performed by a single entity, northbound and southbound interfaces. It enforces a distinct
where many organizations, open development institutions, and separation among the control and data planes by following the
industry consortiums, including ETSI, IETF, ONF, 3GPP, and reference ONF architecture, where the flows are controlled by
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 26

the flow entries at the data plane devices. overloading is inevitable, which can induce huge costs for the
network operators. ETSI ISG proof of concept [254] proclaims
that the success of edge computing lies in continuous coordina-
C. Edge Standardization
tion with the central cloud. Therefore, a continuous interaction
Edge computing for IoT service requirements is a vital among the central cloud and edge computing is imperative for
paradigm; however, there is a need to standardize edge com- seamless service orchestration in edge paradigm.
puting services, including identification of risks, responsibili-
ties, and relationships during its operation. Recently, multiple
efforts in cloud standardization have been performed, includ-
ing IEEE Standard Association [239], ITU [240], ISO [241], D. Lessons Learned: Summary and Insights
NIST [242], [243], and Cloud Standard Customer Council
(CSCC) [244]. Numerous working groups are involved in edge In this section, we have presented current efforts in the stan-
computing standardization; one of them is the MEC, which dardization of Edge, IoT, and SDN infrastructure. There are
is an initiative in the industry specification group within the several standardization bodies, forums, and corporations that
European Telecommunications Standards Institute (ETSI) that are working on the standardization of the smart infrastructure.
mainly works on edge computing [245]. The standardization However, a joint effort in this scenario is still missing. We have
aims at modifying specifications for uniting IT and telecom illustrated that merely connecting many things to the Internet
efforts at the level of the Radio Access Network (RAN). In does not disseminate into smart infrastructure; there is a need
the same way, the OpenFog consortium developed by giant to develop relevant communication standards and protocols.
tech companies is working on creating an architecture for SDN offers communication services independent of device
applying fog in the IoT area [246]. Mist computing standard vendors due to the extensive standardization efforts by ONF. It
has also been introduced by Cisco to perform computation at is capable of managing heterogeneous networks where sensors
the extreme edges of the IoT infrastructure [247]. It allows from different vendors can be operated in a single network.
the computation at dispersed nodes of autonomous systems, OpenFlow is capable of supporting interoperability among the
which is extended through the edge to the IoT devices [248]. data plane devices. Although edge computing is not directly
Edge standards need to be developed for the diverse set of associated with SDN, the requirements of edge servers can
operating platforms that have evolved from public and private be mapped to the characteristics of SDN, which makes it
partnerships in providing IoT-Edge services. Challenges in a promising solution for edge computing. The northbound
edge standardization arise from non-standardized operating RESTful interface in the SDIoT-Edge has the same level of
environments. Therefore, the need to benchmark edge nodes significance as the southbound OpenFlow interface. Seamless
still exists based on standard metrics provided by different communication among the applications at the application plane
researchers [249]–[251] and organizations such as the Standard and the controller in SDIoT-Edge needs vendor-independent
Performance Evaluation Corporation (SPEC) [252]. interfaces. Therefore, standardization of the northbound in-
Table VI shows the edge computing standards including terface will significantly enhance network management using
multi-access edge computing, OpenFog reference architecture, customized applications.
and mist computing. An ISG within ETSI has been organized, Immense computational and network resources are required
which published GS MEC-IEG 006 standard in 2017, focusing to achieve a smart transformation that can be provided by SDN
on the service deployment using edge, [253]. This standard and edge computing. Therefore, standardization of SDIoT-
defines functional and non-functional performance metrics’ Edge is a key challenge in its implementation as the early IoT
improvement using edge computing. The capabilities of newly products have been expeditiously developed by equipping sen-
developed technologies for edge computing are tested on the sors to collect and transmit data. However, with an extremely
ETSI ISG MEC proof of concept framework [254] where the large increase in IoT products, standardization has become
edge video service orchestration [255], service delivery, and a key challenge to gain optimum benefits. Currently, key
service chaining [256] are some of the examples. technologies are present; however, most of the future work lies
The next-generation networks must be capable of satisfying in the standardization of the diverse platforms in SDIoT-Edge.
the imperative requirements of latency, energy efficiency, Many parallel efforts have been going on in the standardization
bandwidth, and continuous mobility. These requirements can that lacks a coordinated effort. Rapid development in this field
be fulfilled by radio access technology using edge computing also poses challenges to standardization. Similarly, most of the
and the core network management using SDN. OpenStack IoT solutions only consider a limited operational paradigm to
is a tool for cloud management that supports the centralized reduce the time to market and increased benefits. Large-scale
management of SDN. Although there are immense efforts in solutions need immense investments; moreover, the return
the standardization of edge computing, many challenges still on investment cannot be guaranteed during the development
exist, which are directives for further efforts. The services’ process, where most of the business owners opt to avoid risks.
complexity and management become a challenge due to the There is a need for the development of a standardization body
involvement of multiple third-party stakeholders, including that includes representatives from different vendors and service
application developers, device manufacturers, and network providing agencies. The research in the SDIoT-Edge paradigm
operators. Although the standardization efforts are extensively is in its emerging phase; hence, many opportunities exist in
going on, the failure of the edge computing servers due to developing standards, protocols, and operational environments.
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 27

VII. S ECURITY AND P RIVACY IN S OFTWARE -D EFINED limitation, and increased attack space. We explicitly discuss
I NTERNET OF T HINGS USING E DGE C OMPUTING these attack vulnerabilities in the next section.
E COSYSTEM
Security and privacy are the most important issues in B. Security Vulnerabilities
the SDIoT-Edge paradigm [257]. SDIoT-Edge incorporates a
diverse set of devices composed of a multitude of vendors, all The distributed nature of edge cloudlets in the SDIoT-
having different mechanisms to deal with security challenges. Edge reveals novel security risks that were not present in the
Therefore, addressing the security and privacy of SDIoT-Edge centralized cloud. SDIoT-Edge deals with heterogeneous enti-
poses a vital challenge. Similarly, IoT and edge devices are ties, including virtualization platforms, multiple IoT variations,
limited in computing resources; therefore, providing special- distributed systems, and wireless networking technologies.
ized security arrangements becomes a difficult task. Many To ensure security, we need to safeguard all the involved
security vulnerabilities exist in SDIoT-Edge that can be lever- platforms using a security solution. Due to the distributed
aged by attackers. We discuss security and privacy by critically nature of infrastructure and mobility of devices, autonomous
considering the vulnerabilities arise due to the integration security solutions are required, which induce lower-latency as
of heterogeneous platforms in SDIoT-Edge. A major threat compared to the centralized security solutions. The network
emerges because of the resource limitation, which invokes endpoints are prone to security challenges where an attacker
increased attack space in SDIoT-Edge. We categorize the can easily access the devices and install malicious software
SDIoT-Edge attacks based on the STRIDE framework, which to generate attacks. Data processing on edge causes privacy
provides a systematic terminology to classify the attacks. Fig. leakage issues due to multi-device interactions. Moreover,
12 shows the taxonomy of the attack vulnerabilities in SDIoT- lack of standardization and competition among the firms to
Edge [258]. Moreover, a taxonomy of attacks based on the introduce novel IoT devices for market survival is contributing
STRIDE framework has been presented in Table VII. immensely in increasing the security risks. The authentication
mechanisms at different levels of SDIoT-Edge is one of the
typical security problems in heterogeneous networks. For
A. Threat Modeling Using STRIDE Framework instance, a smart temperature meter in smart homes can be
We have performed threat modeling in SDIoT-Edge using distinguished by a separate IP address. An adversary can
the STRIDE attack modeling framework developed by Mi- manipulate this device, report false information, and tamper
crosoft [259]. It constitutes six security aspects, including data, which will disrupt temperature management in the smart
spoofing, tampering, repudiation, information disclosure, DoS, home.
and elevation of privileges that are critical in any network Limited computation power in these devices makes them
setting. We map the SDIoT-Edge vulnerabilities using the vulnerable to be exploited as bots for a diverse set of attacks,
STRIDE framework and analyze their consequences. Table VII including Distributed Denial of Service (DDoS) [269]–[273],
discusses the taxonomy of STRIDE using attack definition, Man in the Middle (MiTM) [258], location-based privacy
security services affected by the attack, and the consequences concerns [142], [274], [275], and Link Flooding Attacks (LFA)
of these attacks on SDIoT-Edge. Security solutions need to be [276], [277], [278], [279], [280]. SDIoT-Edge nodes are highly
developed by considering the STRIDE attack taxonomy, which prone to DDoS attacks due to the lack of resources to imple-
provides an overview of the security aspects in SDIoT-Edge. ment a local security solution to defend against these attacks
Spoofing attacks capture the information among connecting [33], [281]–[283]. In addition to these challenges, LFA can
hosts, which can provoke vital data loss and illegal access exploit weaknesses of SDIoT-Edge and flood important links
to critical information. Tampering attacks are directed toward in a variety of ways, including policy switch attacks [201],
the data integrity in SDIoT-Edge, causing illegal data access, OpenFlow channel attacks [200], [284], and data plane re-
cross-service irregularities, and malicious updates of the au- source saturation attacks [272]. The OpenFlow channel attacks
thentication keys. The repudiation attacks cause anomalies in can disconnect C-DPI in SDIoT-Edge by using link flooding
the IoT-Edge authentication, which invoke inconsistencies in and DDoS. The policy switches in SDIoT-Edge manage the
data transfer at the edge and malicious device accountability policy of the network, including the firewall and security [285].
issues. The information disclosure attacks target the vital in- LFA on the policy switch causes the disruptions in per-packet
formation exchanged between the smart infrastructures, which consistency, security, and privacy. DDoS attacks on the data
may include healthcare, vehicular, and fire-safety data. The plane cause flow table memory saturation in the SDN switches
DoS attack can have devastating outcomes on SDIoT-Edge [286]. This attack sends a flood of flows to the switches
where several use cases can be presented, e.g., flow table that causes packet miss in the switch flow table and trigger
overflow, C-DPI, A-CPI, application plane, control plane, and a new flow rule installation. Multiple flow rule installation
data plane attacks. In the elevation of privilege attack, an IoT requests cause limited Ternary Content-Addressable Memory
device maliciously accesses unauthorized resources, which can (TCAM) in the switches to overflow and disrupt the network
spoof the information and provoke other information leakage communication. Strong NIDS can be developed for a specific
issues. edge node and can be deployed on similar nodes. In the same
Although the STRIDE framework encompasses an extensive way, lightweight solutions against flooding attacks can also
attack taxonomy, there are still other attack vulnerabilities that be developed specifically, providing defense against MiTM-
arise specifically due to the multi-device interaction, resource spoofing attacks.
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 28

TABLE VII
SDI OT-E DGE ATTACK TAXONOMY BASED ON THE STRIDE FRAMEWORK .

Threat Definition Affected Services Attack Examples


• Malicious services [260].
• Malicious information [261].
Spoofing Impersonating Edge-IoT data spoofing
• Critical information access [194].
• Unauthorized access e.g., MiTM [258], [262].
• Modifying critical data in edge [263].
• Authentication key update [140].
Data integrity in
Tampering Malicious data update • Integrity attack on user data [142].
SDIoT-Edge
• Illegal access [264].
• Cross-service attack [41].
IoT-Edge device • Repudiation on device accountability [265].
Repudiation IoT repudiation
authentication • Edge data access [266].
• Data leakage on edge [16].
• Data theft on IoT-Edge interface [267].
Information Service confidentiality
Information theft • Communication spoofing [66], [258], [262].
Disclosure in SDIoT-Edge
• Digital signature attack on IoT [258], [262].
• Device’s signature access [223].
• Flow table overflow [268].
• C-DPI attack [200], [201].
IoT-Edge service
DoS Service unavailability • A-CPI attack [269].
orchestration
• Application plane attack [269].
• Control plane attack [270].
• Resources access by unauthorized IoT [68].
Elevation of Privilege Unauthorized access Authorization
• Impersonating [262].

C. Countermeasures, Solutions, and Security Protocols [288]. Data protection during the transmission process can be
efficiently achieved using the SDN’s capability of VLAN ID
Data transfer in SDIoT-Edge suffers from immense attack
to separate traffic in different VLAN groups, which can further
vulnerabilities. Attacks like worm propagation, sniffer attacks,
be mitigated. Homomorphic encryption techniques can be used
and resource saturation attacks can be launched to congest
to solve the challenge of data modification on distributed
the network resources or bring down the controllers. Edge
edge nodes [289]. Authors in [290] propose privacy-preserving
computing utilizes a variety of different networks, including
public auditing to protect data stored in the cloud via third-
wireless, Wi-Fi, and ultra-dense networks, which introduce im-
party auditors. Two authentication protocols (i.e., for the
mense management traffic. Thus isolation of management and
same and different access privileges) are designed to verify
data traffic poses challenges of data management. Moreover,
file search results. Finally, a third-party auditor ensures the
adversaries can utilize this data to generate DoS attacks.
security of the data storage, where the auditor itself uses
Developing on-device security solutions for IoT is hard homomorphic encryption and random mask for protection.
because of the resource limitations [287]. The programmability IPSec is a security protocol that is used to protect network
characteristic of SDN can be used to develop network-level traffic in SD-WAN [237].
security solutions. SDN provides the capability to program the
network for customized traffic forwarding and network policy Security vulnerabilities arise while transferring data to and
enforcement. Recently, a few techniques have been proposed from the edge nodes in the SDIoT-Edge. Verifiable computa-
to use SDN’s programmability feature to secure IoT [200], tion [291] uses compute-nodes to offload the task. A public
[201]. For instance, the Floodlight open-source controller encryption key is generated by the IoT where key-value,
provides the flexibility to deploy custom security applications and computation can be compared to authenticate the data
[284]. It is easy to analyze network traffic due to centralized [292]. Trust between edge nodes and the end devices must be
traffic management in SDN, which is an imperative character- available to ensure security; where Clemens et al. proposed
istic for developing security solutions. Different mechanisms a trust-based authentication solution to solve this challenge
can be used to detect the malicious traffic (e.g., machine [293]. This method ensures the authentication using integrity
learning, bloom filtering), which can then be mitigated by measurement and attestation to verify integrity evidence from
customized flow rule installation on the forwarding devices edge devices. Echeverria et al. proposed a trust identity
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 29

Fig. 13. An example of the MiTM attacks on the OpenFlow channel of


Fig. 12. Attack taxonomy in the SDIoT-Edge ecosystem. SDIoT-Edge.

devices act as readily available objects that can be manipulated


solution in disconnected environments using identity-based
for DDoS attacks. The most devastating DDoS in SDIoT-Edge
cryptography and secure key exchange. This solution provides
includes the following.
application, OS, network, and site-level controls, which can
• Flow-table overflow attacks
efficiently safeguard the disconnected environments [294].
• Controller process attacks
• OpenFlow agent attacks
D. Privacy Concerns
The first DDoS attack against smart home-based IoT devices
IoT and edge nodes can be manipulated in vehicular net- was observed in 2014 when the attackers broke into one
works, which can be transformed into adversaries to spread hundred thousand IoT devices by sending malicious emails
disinformation to the vehicles driving through the edge node’s targeting the enterprises and individual customers around the
range [295], [296]. The user location can be exposed using world [299]. During the past several years, DDoS attacks have
IoT devices when they offload their data on edge nodes, become a routine in the IoT infrastructure, where more than
for example, wearable devices send data to the edge, which 550 attacks have been observed per year, generating a peak
performs the computation and may further forward this data traffic load of 800 Gbps at a time. These attacks are growing
to the cloud [297]. During the data transmission, edge nodes rapidly, and the yearly growth of 150% is observed that has
and central cloud can ascertain the location of the user even incurred a cost of approximately 30,000$ per hour [300]. The
in the presence of anonymity solutions. Fake, comprised, and most severe is the Mirai malware attack, which had blocked
manipulated IoT and edge nodes are threats to the network access to the IoT services and ISPs in the U.S by injecting
infrastructure due to the difference in trust models being Mirai malware in the IoT devices. This malware manipulated
used in different devices that require a massive investment the IoT devices into bots that attacked important servers [283],
in trust management [298]. Similarly, it is challenging to [301]–[304].
develop blacklists for these suspicious devices in a massively IoT networks are prone to DDoS attacks because they are
distributed paradigm. not supported by the policy mechanisms for traffic handling. In
Individuals are usually reluctant to share their personal in- the same way, the devices connected by the SDIoT-Edge net-
formation; however, with more IoT-Edge deployment, personal work are heterogeneous in nature, employing different compu-
information is exposed to unnecessary individuals. Privacy tation and battery capacities. Limited computation resources in
breaches such as those arising from the exploitation of credit IoT makes the deployment of state-of-the-art security solutions
card information leaks at payment on edge nodes, in addition a challenging task. The availability of service provisioning has
to customers’ health information by the pharmacies, financial also been limited and only a specific number of requests can
information by the insurance companies, and travel informa- be fulfilled at a certain time. Another vulnerable nature of
tion at the refueling stations can be easily exposed in SDIoT- IoT is that it is designed as an open framework for multiple
Edge. Consequently, there is a need for comprehensive privacy connected devices; therefore, considerably less control exists
mechanisms to secure user data leakage in SDIoT-Edge. over simplified connected objects. The workflow in IoT is also
dependent on multiple devices that can have a cascading effect
E. DDoS Attacks on the attack area during DDoS.
In the SDIoT-Edge paradigm, most of the devastating at-
tacks are the DDoS attacks. IoT comprises a heterogeneous F. MiTM Attacks
range of devices; hence, the manufacturers often use this as an In the MiTM attacks, the adversary intercepts the commu-
excuse to provide adequate security measures. Therefore, IoT nication channel between two hosts and access, modify, or
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 30

replace the ongoing traffic [262]. The victims continue the


regular interaction believing that the communication channel
is protected. The aim of the MiTM attack is to compromise
confidentiality, integrity, and availability of the network by
eavesdropping, intercepting, and spoiling the network traffic.
In SDIoT-Edge, the OpenFlow channel can become the target
of the MiTM attacks where the information exchanged be-
tween the switches and the controller can be intercepted by a
smart adversary.
Cheng et al. [258] and Stohmenovic [305] propose the
feasibility of MiTM attacks against the cloud and IoT infras-
tructure. A considerable number of IoT devices suffer from
the challenge of firmware update attacks where the adversary
updates the IoT device’s firmware using a legitimate update
method. If there is a device with such a vulnerability: 1) the ad-
versary comprehends the device by firmware modification; 2) Fig. 14. An example of LFA in the SDIoT-Edge paradigm.
then deploys a client certificate at the gateway and OFSwitch
claiming that both the nodes need to use this certificate for
the future communication; 3) the adversary then spoofs the ability to congest specific links connected to important nodes.
communication between the controller and OFSwitch; and 4) LFAs are dangerous in SDIoT-Edge because they use low-
launches MiTM attack. Cheng et al. [258] present the idea rate traffic to flood important servers. This traffic behaves the
of an SDN-based centralized controller and fog computing to same as the legitimate traffic; so, detection and defense against
alleviate MiTM attacks. They investigate MiTM attacks on the LFA become a complex challenge. Different variations of LFA
OpenFlow channel and provide defense using Bloom filters in exist, such as Coremelt [307], Crossfire [308], and Spamhaus
order to examine stealthy malicious updates in the packets. [309]. Fig. 14 shows that IoT nodes can be exploited to send
However, the problem with their approach is that if all the low-rate traffic toward decoys, which can disrupt the network
switches in the path of a flow are comprehended, then this and shut it down in extreme conditions. The figure shows
approach becomes invalid. Fig. 13 shows the sequence of pos- that LFA causes four types of vulnerabilities in SDIoT-Edge
sibilities of MiTM attacks on the SDIoT-Edge infrastructure. networks, which are as follows.
To avoid MiTM attacks, lightweight encryption/decryption • OpenFlow channel attacks
schemes are needed to authenticate the devices prior to serving • Policy switch cut-off attacks
the requests. The figure shows that four types of attacks are • Intra controller attacks
possible in this scenario, as given in the following. • Flow-table overflow attacks

• MiTM-spoofing attacks In the open flow channel attacks, the adversary can manipulate
• Topology poisoning attacks IoT devices to send low-rate traffic toward the switches to
• Flow modification attacks cause a packet miss. Furthermore, the switch will send the
• Information theft attacks traffic packets to the controller, which can cause flooding on
In the MiTM-spoofing attacks, the attacker can intercept the the OpenFlow channel. This attack has the ability to disconnect
OpenFlow channel and modify the victim’s switch forwarding the OpenFlow channel from the rest of the network. The
table using spoofing techniques such as ARP spoofing. The policy consistency is an essential characteristic in the SDNs
Link Layer Discovery Protocol (LLDP) packets are utilized by to provide seamless services that are performed by the policy
the controller in order to learn the topology of the network. switch in the network. A smart adversary can cause flooding
The attacker can customize the LLDP packets by modifying on the policy switch links in order to disconnect them from
the maximum length and output port in a PACKET OUT mes- the rest of the network. In the same way, the switches are
sage. The switch will not be able to access the message due to equipped with low-size storage known as TCAM to maintain
the malicious modifications and will respond by sending a fake flow tables. The adversary can send a flood of low-rate packets
topology to the controller. In the flow modification attacks, the to the target switch causing a packet miss that triggers the
attacker redirects traffic from a host to an irrelevant host by installation of new flow rules [268]. Consequently, after a
modifying flows. Similarly, during the process of redirecting significant rule installation, a point will come when the TCAM
network traffic, the adversary has the ability to collect vital memory will be exhausted. Therefore, LFA has the ability
information over the network, causing vital information loss. to disrupt communication in SDIoT-Edge; therefore, adequate
security must be provided in order to defend these potentially
devastating attacks.
G. LFAs
LFA has been involved in causing an outage in the major
Internet infrastructures [306]. The adversary can exploit se- H. Lessons Learned: Summary and Insights
curity limitations in the IoT devices and launch devastating In summary, the IoT-Edge infrastructure suffers from many
LFA on the Internet infrastructure. Flooding attacks have the security threats that can leverage the resource limitation of
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 31

these devices. Research in IoT-Edge has been in its evo- for specific operating conditions. Hence, they are not able
lutionary phase; in this regard, the solution developers and to handle dynamic workloads as they are not developed to
industry must put extensive efforts into realizing the underly- provide generic computation resources. Several solutions to
ing threats before providing any solution for the SDIoT-Edge address this problem have been provided by industry, including
ecosystem. We have provided a taxonomy of the attacks in Nokia’s solutions for edge computing [323], OCTEON Fusion
SDIoT-Edge by considering the vulnerabilities that arise due [324], and Cisco’s IOx [325]; however, these solutions are
to the integration of heterogeneous infrastructure. The lack dependent on the use of specific hardware and may not
of standardization and immense product delivery needs have be suitable for heterogeneous environments. Virtualization
instigated core security risks in IoT that pose a severe threat techniques using SDN, NFV, and VMs can be exploited for
to the network infrastructure. The lack of real-time simulation dynamic workload handling, platform integration challenges,
for IoT experiments poses a challenge for the researchers and compatibility issues at the BSs. Further, VM caching
to develop effective security solutions. The vulnerabilities of techniques can be exploited for swift integrations in future.
the controller in SDN have been well established and can Consequently, the need for resource provision at edge nodes
become a critical challenge in the SDIoT-Edge paradigm. is still a challenge in the SDIoT-Edge ecosystem. A scalable
Research on providing a solution for the IoT devices can be solution for IoT resource provision at the edge, employing
of great benefit to the current network paradigm. The security SDN can be an impactful research direction in this paradigm.
strategies must also consider a holistic approach that leverages Due to the lower computation power at the edge nodes,
the benefits of multiple solutions to cater to the security the requesting devices may suffer from resource under-
issues in IoT. For example, researchers proposed solutions provisioning, which can be addressed by employing distributed
against OpenFlow channel DDoS attacks, data-plane attacks, edge computing. In this paradigm, multiple edge nodes can
and controller attacks separately. However, a comprehensive cooperate in providing services where SDN can address
security mechanism that incorporates the characteristics of all communication management issues. SDN applications in the
the solutions can be extremely beneficial for the SDIoT-Edge. context of Software-Defined Wireless Networks (SDWN) can
provide the baseline to implement such solutions.
VIII. O PEN I SSUES AND F UTURE R ESEARCH D IRECTIONS
Edge computing is continuously being deployed for SDIoT B. Cloud Service Discovery for Internet of Things
service orchestration. It is a novel paradigm that has been
Edge device discovery in a heterogeneous and decentralized
creating widespread opportunities for efficient resource de-
IoT environment is challenging because it needs special ar-
ployment, interoperability, and management. However, multi-
rangements to search specific edge nodes over the network.
ple areas in SDIoT-Edge still need to be addressed adequately.
The exponential growth of IoT devices and massive data
This section provides insights toward open research issues and
generation provoke data management issues, where novel
future research directions. Table VIII provides the current chal-
techniques will be required to handle heterogeneous workloads
lenges in the SDIoT-Edge paradigm and suggests guidelines
and diverse infrastructure. This challenge can be addressed
to solve these issues.
using distributed data management techniques [310] where
storage using Luby Transform [311] provides a use case
A. Resource Provision at Edge Nodes deployment. Seamless service provisioning in a heteroge-
Traditional cloud computing provides powerful resources to neous environment is also a key challenge, where proactive
address compute-intensive tasks. Applications that can tolerate fault-tolerant mechanisms are required to deal with failover
latency and cost associated with transferring and receiving situations. IoT devices need special arrangements for edge
back the computation can successfully utilize the central cloud. service discovery as they lack compute-intensive processing
However, IoT devices are resource-limited with real-time pro- capabilities; therefore, research in rapid service discovery
cessing needs to control sophisticated infrastructure. Moreover, needs special attention.
the mobility requirements, throughput, big data needs, low- Using edge services to fulfill widespread IoT demands,
latency, precise control, and data aggregation pose a challenge requires the use of switches, routers, gateways, and BSs that
on the use of traditional cloud computing. Therefore, the are owned by the public and private organizations, which
computation processing can be brought at the edge of IoT provoke workflow execution, management, and integration is-
to address these challenges. sues. However, different institutions may have organizational-
Edge cloudlets are placed between IoT and the central cloud level security parameters that need to be standardized for
using communication infrastructure, including switches, gate- disparate firms providing services. Subsequently, as several
ways, access points, routers, and BSs. Heterogeneous commu- infrastructures from different organizations are collaborating
nication paradigms and multiple platforms provoke resource to provide services, there is a need to furnish standardized
provisioning challenges and integration issues. Edge nodes pricing models for service provisioning.
contain limited resources as compared to the central cloud; For efficient edge cloud service discovery, the edge of
therefore, intelligent decision making is needed to identify the the network should be incorporated in the communication
services, which can be handled at the edge and those that ecosystem where the edge cloudlets will be accessible to the
should be transferred to the central cloud. The workload at IoT devices, which can offload the compute-intensive tasks.
BSs is handled by the signal processors that are configured Another solution to this challenge is using ETSI MEC stage
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 32

TABLE VIII
A DETAILED DISCUSSION ON O PEN CHALLENGES AND SOLUTION GUIDELINES .

Challenges Causes Guidelines


• Hardware-independent solutions
• Dynamic workload handling at BS.
e.g., SDN/NFV, VMs.
Resource Provision • Compatibility issues at BS.
• Virtualization at different layers.
at Edge Nodes • Platform integration issues.
• VM management using overlays at BS.
• Lack of virtualization capabilities.
• VM caching for rapid future integrations.
• Edge nodes discovery in heterogeneous networks.
• Service discovery using ETSI MEC
• Data management issues.
stage 3 level APIs [29].
Cloud Service Discovery • Production, partitioning, classification,
• Use of data distribution service [310][310].
for IoT and delivery of data.
• Storage using Luby Transform [311].
• Workflow related issues.
• Interoperability of the services using [29].
• Workflow execution, fault-tolerance, and integration.
• Networking among heterogeneous devices. • Softwarization of services NFV/OpenFlow.
Heterogeneous • Heterogeneous infrastructures for services. • Customized VM management at the edge cloudlets.
Service Architecture • Heterogeneous security and privacy challenges. • Multi-innovation using current networking and IPv6.
• Data naming issues. • Employing the NDN technique for naming.
• Lack of edge services marketplace. • Development using the central cloud example.
• Nonavailability of standards and SLAs. • Seamless coordination among edge cloudlets.
Provision of
• Lack of efficient resource utilization. • Handling temporal variation in service demands.
a Marketplace
• Lack of coordination among edge cloudlets. • Low-cost service borrowing from edge cloudlets.
• Distributed request handling challenges. • Auction-based service-provisioning [312], [313].
• Realization of wireless SDN.
• Protocols and standards for wireless SDN.
• Wireless separation of C-DPI has not been optimized.
5G/6G • Novel high spectrum-capable hardware.
• Effective spectrum sharing.
Networks • Device accessibility using 5G/6G high coverage.
• Heterogeneous message exchange
• Synchronization protocols for message exchange.
and resource over-provisioning.
• Lack of resources to handle compute-intensive
• Lightweight machine learning algorithms to perform
libraries and algorithms.
Lightweight Algorithms data classification and partitioning [155], [156].
• Energy consumption in the data processing.
for IoT-Edge nodes • Apache Quarks [314] provides a baseline.
• Traditional algorithms need higher
• Data filtering before delivering data to the cloud.
computation resources.
• Resource-limitation in IoT-Edge nodes. • Novel lightweight OS development.
Lightweight OS for • Rapid deployment issues over diverse platforms. • Enhancement in the Docker-based solutions.
IoT-Edge nodes • Missing essential OS components in IoT-Edge. • Development of lightweight components in the IoT.
• Updates and maintenance issues. • Reliable updates patching and rollback.
• Unified architecture for different devices.
• Multiplatform synchronization.
• Standards and protocols for
• Communication heterogeneity during
interoperability [9]–[11].
service orchestration.
Unified Architectures • Coordinator-based solution for
• Distributed integration among
resource sharing and scheduling [315].
edge computing and IoT.
• Mobility-aware architecture for
• Mobility of IoT e.g., smart vehicles.
service orchestration [316].
• Lack of trusted administering capabilities
• Privacy-preserving techniques
in IoT-Edge.
e.g., differential privacy [318].
• Data transfer among heterogeneous platforms.
Security Handling • Authenticating gateways at multi-levels [319].
• Data leakage issues.
Mechanisms • Homomorphic encryption for security [289].
• Constraints on high-cost encryption algorithms
• Provision of lightweight cryptography solutions.
i.e., 1024-bit RSA [317].
• Blockchain-based solutions [320], [321].
• Resource constraints.
• Increased attack surface. • Network solutions using SDN [284].
• Lack of resources increases vulnerability. • Edge-based IoT device authentication [263].
Eavesdropping, Flooding,
• Non-availability of IoT security solutions. • Secure frameworks in SDN [200], [201].
and DDoS Attacks
• Security element is neglected for higher performance. • Use of authentication for a secure connection.
• Simplified communication models. • Standardized network protocols for security.
• Controller-switch communication delay. • Seamless communication between
• Central management causes single point of failure. controller and data plane devices.
Controller Bottleneck • Scalability of a single controller. • Distributed controllers with abstraction.
• The OpenFlow channel vulnerability • Virtualization using NFV and VM management.
caused by flooding flows. • OpenFlow channel security [322].
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 33

3 level APIs, which use token endpoint URI for communi- MAC addresses to ensure mobility-aware device discovery.
cation [29]. Moreover, public cloud resources are available However, this technique requires a globally unique device-
for service discovery and orchestration like EC2 and Amazon identification, which is not user-friendly.
Web Services (AWS). However, there is a lack of similar
platforms for edge computing services discovery. Edge-as- D. Provision of a Marketplace
a-service (EaaS) has been proposed as a first effort in this
Similar to a cloud marketplace, there is still a need to
paradigm by Blesson et al. [116]. A discovery protocol is
develop an edge marketplace where edge services can be
used, which identifies the edge nodes and makes them publicly
acquired as pay-per-demand and pay-per-use pricing standards
available using a controller. This platform owns a three-
of the central cloud. Edge computing has been tremendously
tier architecture where the discovery layer is at the bottom,
involved in providing services to the latency-sensitive IoT
whereas the top layer constitutes the application servers. There
devices, which suffer from the nonavailability of standards
is still a need to develop edge discovery mechanisms to publish
and SLAs to develop a marketplace. Due to the heterogeneity
the edge services, which can be utilized by any requesting
in the edge infrastructure providers, lack of coordination
device on a pay as per use pricing model.
becomes an inevitable situation that results in unbalanced
resource utilization. The temporal variation in the resource de-
C. Heterogeneous Service Architecture mands can be analyzed to provide resources to the requesting
stations. Moreover, coordination strategies among distributed
Supporting heterogeneous infrastructures, devices, and di-
edge cloudlets should be developed, which can deal with the
verse service demands are critical challenges in SDIoT-Edge.
resource overprovisioning challenges. Edge cloudlets can be
This architecture integrates a diverse combination of platforms,
utilized to provide services in terms of VMs, where resource
servers, network topologies, and protocols. It constitutes a
requests over the distributed edge nodes can be addressed via
heterogeneous architecture causing complexities to program,
a collocated market. The edge market place should have the
operate, manage, and secure applications operating on different
capability to provide on-demand and on-path services for the
platforms and locations. Security challenges can be handled by
customers. As the edge cloudlet resources are limited, they
providing network-based solutions, which provide an efficient
cannot provide boundless services to the requesting stations.
way to secure resource-limited IoT devices.
More often, the demand for a resource can exceed as compared
The distributed edge nodes possess sufficient resources
to the available resources. Therefore, a scheduling mechanism
to handle service requests at the resource-limited devices’
is needed to allocate the resources to the incoming requests
edge. The application developers face challenges in application
from the customers, especially for the latency-sensitive appli-
development for end-to-end service orchestration in a hetero-
cations [328]. Moreover, these applications cannot be trans-
geneous SDIoT-Edge paradigm. Although a few techniques
ferred to other distributed edge cloudlets due to the QoS
address the challenge of programmability in edge computing,
requirements, which pose a challenge on distributed request
they did not consider the specific IoT characteristics [316],
handling. Hence, the market place for edge computing should
[326], [327]. The device discovery is complex in IoT-Edge as
be devised considering the fact that the resource provisioning
the IoT devices are unaware of the nearby edge platforms.
over the edge cloudlets is distributed and uncoordinated. A
Moreover, the edge nodes need to deploy multiple server-
solution to this challenge would be the deployment of auction-
side programs; however, the deployment and management of
based service provisioning to the requesting stations based on
these programs is another challenge because of the distributed
the strategies developed in [312], [313].
nature of edge nodes. These challenges can be addressed
Moreover, immense challenges still remain in developing
by virtualization services provided by SDN/NFV and VM
SLAs and pricing standards for such a diverse marketplace.
management.
These challenges may include the allocation of resources over
The versatility in the service architecture also poses a
time to the requesting applications and the pricing mecha-
challenge on data management, where different storage servers
nisms to service the requests. Therefore, a pricing model can
having different operating systems increase complexities in file
be assigned to every edge cloudlet considering on-demand,
naming, resource allocation, and reliability management. The
decentralized, and uncoordinated requests.
naming convention of data becomes another critical issue, due
to the generation of data by multiple resources, where the
URI and DNS schemes are not suitable for the dynamic edge E. 5G/6G Networks
networks and IoT. The IP-based naming conventions are not 5G/6G networks are key enablers for the SDIoT-Edge,
applicable for multi-source and multi-task edge nodes as they which offer a high-speed communication spectrum that can
induce huge implementation costs. Schemes like Named Data support the need for seamless interaction among different
Network (NDN) [327] provide a hierarchical naming strategy platforms. Although 5G networks have been increasingly de-
for the distributed networks, which is easy for the network ployed as a communication resource, an effective realization of
owner to manage. However, it requires extra proxy servers wireless SDN is still a challenge where the wireless separation
in the network to integrate heterogeneous communication of C-DPI has not yet been optimized. In this regard, the
protocols. Additionally, it needs source hardware information, development of standards and protocols for the wireless SDN
which increases privacy and security issues. The MobilityFirst will provoke immense opportunities using 5G/6G in SDIoT-
technique [316] separates the device-identity from the IP and Edge. Device-to-Device (D2D) communication using spectrum
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 34

sharing is expected to grow using 5G/6G technology. However, As the systems deploying IoT devices are increasing con-
D2D communication in SDIoT-Edge needs high spectrum tinuously, resource constraints like data management, low
hardware and interference management to optimally utilize the processing capabilities, smaller memory, and lower battery
throughput and provide reliable communication. The conver- power are posing a critical challenge on the performance of
gence of 5G/6G, edge computing, IoT, and SDN with AI can these systems. In this situation, lightweight algorithms for data
provide analytics capabilities to enable better user experience filtering, classification, and partitioning (e.g., [155], [156]) are
in communication, digital content access, automotive IoT, needed to operate on resource-limited devices. Moreover, data
smart homes, and VR. Moreover, edge analytics and AI give filtering can be performed before transmitting the data to the
rise to autonomous networks that enhance the user experience. cloud to reduce network resource consumption. Traditional
However, spectrum sharing and energy harvesting become a compute-intensive algorithms may become invalid in the IoT
critical challenge in SDIoT-Edge. Further research in 5G/6G context; for instance, the RSA 1024-bit cryptography algo-
implementation in SDIoT-Edge will provide novel spectrum rithm cannot be deployed in the IoT context. The resource
sharing solutions, which can considerably enhance the cov- limitation in IoT requires lightweight security solutions that
erage where the high-speed switches at the data plane and can operate on IoT infrastructure. Similarly, lightweight VM
edge resources can interact seamlessly. Further, there is a dire management techniques are required to orchestrate distributed
need of the service infrastructure that can optimally harvest the edge cloudlets’ services. IoT realization is based on devising
capabilities provided by highspeed 5G/6G communication. connections and operating with heterogeneous infrastructure
In order to optimally utilize the benefits provided by where IoT devices are often operated autonomously. Similarly,
high-speed 5G/6G communication, there is a need for high- data produced by the IoT is used to control sophisticated
spectrum capable hardware on both ends (e.g., client and infrastructure. Therefore, lightweight data classification algo-
carrier). In the high device density paradigms, the 5G/6G rithms are required to process the data. Lightweight algorithms
networks are capable of providing context-aware middleware are necessary to enable seamless connection, computation
solutions that can overcome the challenges of scalability, offloading, interoperability, and security among the heteroge-
heterogeneity, and mobility. They support the realization of neous architecture. Moreover, resource limitation in IoT needs
autonomous networks, which can provide fault-tolerance dur- the development of lightweight algorithms, OS, and solutions
ing dynamic network changes. Although 5G/6G networks that deal with scarce resources.
provide faster communication, the network scalability is still
a major issue as managing state information of large-scale
G. Lightweight Operating Systems for Software-Defined Inter-
IoT devices requires heterogeneous message exchange, which
net of Things and Edge Computing Nodes
needs synchronization protocols. Although solutions for cloud
services provision for IoT over 5G/6G communication chan- In SDIoT-Edge, the cloud service nodes lack enough
nels have been proposed, energy-efficient resource provision, resources as compared to central cloud servers; therefore,
security, privacy, and VM management are still key challenges lightweight OS for edge nodes is required to enable effi-
in SDIoT-Edge [138], [329], [330]. 5G/6G networks can cient offloading services. The ideal characteristics for edge
support wireless-NFV for the entire network, which has the OS include less boot time, rapid deployment over diverse
capability to simplify the service orchestration in the SDIoT- platforms, multitasking, less resource consumption, and fewer
Edge paradigm. 5G/6G networks, with the help of NFV, aim at startup delays [332], [333]. Technologies such as Docker [146]
providing scalable cloud resources using customized network can provide such services; however, these container-based
slicing for IoT applications. Though 5G/6G networks are key solutions can hardly provide rapid deployments over diverse
enablers for the SDIoT-Edge, trusted communication over the platforms.
high-speed network in the presence of eavesdroppers is a There is a high demand for lightweight OS for low-cost
significant challenge. sensor technologies like 5G/6G and advanced LTE. Con-
sidering the lower memory footprints in the IoT and edge
infrastructure, any OS must be portable, needs lower com-
F. Lightweight Algorithms for the Internet of Things and Edge putational resources, support heterogeneous deployment, and
Nodes should seamlessly integrate with other solutions, and already
Lightweight algorithms and libraries become imperative available IoT software.
when there are constraints on computational power, battery Moreover, the resource-limitation requirements in the IoT,
life, memory, and storage. As edge nodes and IoT devices need special attention from OS developers to eliminate the
encompass fewer computation resources, for example, the Intel compute-intensive elements from the operating systems. The
T3K processor on an edge node supports four core CPUs developers usually provide novel packages that are often called
having a meager memory that is not capable of supporting snaps. The snaps are software package-images, which can be
cloud-level services such as Apache Spark [331], with an 8- downloaded from the multiple network resources instead of an
core CPU, supports 8 GB of memory for operation. Alter- app store. Any OS for IoT should support low-end IoT devices,
natively, Apache Quarks [314] enables real-time analytics on which suffer from low-computational constraints. Therefore,
edge nodes; however, it only provides basic data filtering and there is still a need to develop a lightweight OS for IoT and
aggregation capabilities that are not sufficient for current edge edge nodes, which consider the modularity, scheduling, mem-
nodes. ory allocation, and network buffer management constraints.
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 35

Furthermore, there is a strong need to develop effective environment, each edge node stores the credentials of every
maintenance and update mechanisms for SDIoT-Edge solu- IoT device, which creates inefficient utilization of resources;
tions. The update patching suffers from reliable installation similarly, a centralized credential repository on a powerful
issues, due to the presence of resource-limited infrastructure. edge node results in communication overhead on the network.
For example, power failure during update patching creates To deal with these issues, blockchain technology has recently
anomalies in the device operation. Therefore, effective rollback been proposed, which provides efficient storage for growing
mechanisms should be developed for updates’ patching in the records [267], [336]–[339]. Blockchain in IoT can gage the
resource-limited devices [334], [335]. SOA provides software security problems being faced by IoT devices as blockchain
services through message exchange between different layers allows only trusted participants to interact with each other
of IoT, which can be used to develop effective solutions for [340]–[342]. A blockchain-based data-sharing framework uses
the updates and maintenance challenges. compute-efficient proof-of-collaboration, transaction filtering,
and offloading to reduce storage overhead for robust commu-
H. Unified Architectures nication [338]. EdgeChain is a security framework that uses
permissioned blockchain and the underlying currency mech-
Current research in platform and framework development
anism to securely associate edge cloud resources pool with
has been targeted toward fulfilling specific requirements. How-
the IoT devices [321]. Edge nodes can be used to store a log
ever, many similar requirements arise due to diverse IoT
file of records in a distributed manner. This blockchain-based
infrastructure that needs to be addressed for efficient solution
log implementation stores the information of the edge nodes’
development including multiplatform synchronization, com-
behavior using exchanged messages between edge nodes and
munication heterogeneity, distributed integration, and mobility.
IoT devices. If an edge or IoT device misbehaves, other edge
Consequently, there is a need to develop a unified architecture
nodes can discover its behavior easily. A decentralized security
for versatile devices that will encourage interoperability, ease
architecture using SDN blockchain, edge, and fog computing
of synchronization, and leverage standardization. We have
is proposed in [320]. In this architecture, SDN offers contin-
discussed many solutions in this paper; however, most of
uous monitoring of the network, whereas blockchain provides
the available architectures do not consider the prevailing IoT
decentralized security to avoid a single point of failure. In
demands, which makes it complex to develop an adaptable
addition, blockchains can be used to develop authentication
solution. Generalization among different IoT solutions, such
mechanisms for IoT devices and edge nodes. Blockchains can
as architectures, protocols for interoperability (e.g., [9]–[11]
be utilized to develop a secure layer among edge nodes and
), and devices will leverage interoperability among IoT for
IoT infrastructure to ensure security and privacy.
novel applications.
Alternatively, symmetric and asymmetric algorithms can be
The existing solutions hardly provide distributed integration
developed to handle security issues. However, both of these
among edge computing nodes and the IoT infrastructure. A
algorithms suffer from potential drawbacks as the symmetric
unified architecture using a coordinator might be employed
solutions lack in providing sufficient authentication, whereas
where the function of the coordinator could be periodically
the asymmetric solutions contain larger key sizes and consume
querying the edge nodes regarding the available resources, job
more memory. Therefore, there is still a need to develop
status, and scheduling. The coordinator can provide seamless
cryptography solutions that offer lower-key size, increased
operation among distributed edge cloudlets such as discussed
processing speed, and need fewer computation resources.
in [315]. The location-awareness of the IoT also poses chal-
Moreover, many device designers use less-secure Bluetooth
lenges as the computation offloading and transferring results
or Zigbee for the connection where the adversaries can
back to the IoT (For example, IoV) needs location assessment
break through the Bluetooth passwords and mac addresses
of the underlying device. Therefore, a unified architecture
on Zigbee. Therefore, the device designers need to employ
employing the mobility-awareness is needed to effectively
standardized Public Key Infrastructure (PKI) authentication
orchestrate IoT services [316].
methods and utilize standard network protocols like TCP/IP
to enhance security from the nodes to the edge infrastructure.
I. Security Handling Mechanisms
Edge nodes and IoT devices are part of a decentralized
architecture where nodes can join and leave the network at any J. Eavesdropping, Flooding, and DDoS Attacks
time. This characteristic makes SDIoT-Edge a security bottle- The attack surface for DDoS and flooding attacks has
neck, where no single entity acts as a trusted administrator been increased due to the development of a huge number
and controls the security of the infrastructure. Data transfer of smart devices. As the IoT devices contain a small mem-
among these heterogeneous devices in the absence of security ory, the implementation of device-specific security solutions
solutions creates data leakage issues. The resource constraints becomes a challenge. It makes IoT vulnerable to different
pose limitations on employing encryption algorithms like attacks, including eavesdropping, flooding, and DDoS [65].
1024-bit RSA [317]. The distributed privacy-preserving tech- The security of the Internet depends on securing the whole
niques like differential privacy can solve the challenge in the Internet infrastructure; so, the network connectivity of attack-
multiplatform paradigm. An example of distributed authen- vulnerable IoT devices exposes the global network toward
tication is the gateway authentication at multi-levels [319] attacks. Internet entities, such as hosts, servers, and the service
and the homomorphic encryption [289]. In the distributed infrastructure contain limited resources that can be saturated
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 36

by a finite number of users. This fact increases the possibility single point of failure. In this situation, enhanced virtualization
of DDoS and LFA in the SDIoT-Edge. Moreover, simpli- of network resources using NFV and VM management has
fied communication models of IoT and non-availability of the potential to provide an abstraction of a single controller.
security solutions create increased vulnerability of attacks in Moreover, security solutions can be developed to secure
SDIoT-Edge. Lack of resources poses limitations on compute- the OpenFlow channel from flooding attacks [322]. Another
intensive security solutions; therefore, security frameworks can latency requirement is instigated by the difference between
be developed at the application plane to secure SDIoT-Edge the architectural positioning of the control and data plane.
[200], [201]. However, they pose overhead on the network due The latency of flow setup is associated with the duration of
to the extra packet inspection and mitigation processes. Device the switch packet processing, the round trip time among the
authentication using auxiliary edge infrastructure can provide a controllers, and the time taken by the controller in handling
solution to authenticate resource-limited IoT devices. EdgeSec the request. Higher time consumption in the controller-switch
[343] and ReSIoT [344] ensure security against eavesdropping communication, directly affects the flow setup latency, result-
attacks, which offloads the security function to the edge ing in prolonged time delays in updating (e.g., add, delete,
cloudlets. However, it becomes riskier when edge nodes are update) the flow rules. This setup causes congestion in the
down, making the IoT devices prone to attacks. Furthermore, network and ultimately triggers the failure. A well-organized
as IoT devices collect imperative data and transfer it to synchronization between the data and control plane enhances
the edge nodes for processing, the possibilities of eavesdrop the control of the network in handling failover issues.
attacks increases. Although the eavesdropping attacks can be SDN provides the basis to revisit the deployment of network
secured using the edge nodes, there is still a need to secure functions. It promotes the idea of softwarization that supports
the communication channels. The development of lightweight heterogeneity and dynamicity. Alternatively, the centralized
security protocol for the edge nodes and end devices has great management poses issues of throughput, latency, availability,
potential in future research. Moreover, enhanced authentication and single point of failure of the network. Unified architectures
of IoT and standardization of network security protocols will for SDIoT-Edge are needed where service provision, security,
help in securing SDIoT-Edge from eavesdropping, flooding interoperability, and pricing can be effectively handled. More-
and DDoS Attacks. over, security solutions for the diverse SDIoT-Edge ecosystem
need to be developed considering constraints from the diversity
and resource limitations in the infrastructure.
K. Controller Bottleneck
In the SDIoT-Edge paradigm, SDN provides scalability by
IX. C ONCLUSION
leveraging the performance of the controller, where many
studies are available that address the performance of SDN Programmable networks enable flexible network evolution
controllers based on different workloads, architectures, and and management that leverage the SDN characteristics of
implementations. These studies perform an evaluation of the separation of the control and data plane. A massive increase in
SDN controller based on different metrics, including link IoT infrastructure has been observed due to the advancements
utilization, path installation time, flow rule installation, the in the field of wireless sensor networks. IoT weaves the
throughput of the controller, and latency, which corresponds fabric of the current smart world infrastructure; however, the
to the delay in completing a flow request [54], [264], [345]– resource-limited IoT devices bring novel challenges of service
[347]. Nevertheless, centralized management in SDIoT-Edge orchestration, management, scalability, and heterogeneity. In
provides immense opportunities and benefits; however, key this context, SDN provides virtualization for effective IoT
challenges of a single point of failure, OpenFlow channel implementation, whereas edge computing acts as a gateway
vulnerabilities caused by flooding flows, and scalability issues between latency-sensitive IoT infrastructure and the traditional
are associated with this integration. One of the main aspects cloud. Although SDN adaptation with the IoT networks seems
of the scalability of the SDN controller is achieved by the promising, there are still many challenges that need to be
separation of planes, which instigates the mechanism of con- addressed for an efficient implementation of the SDIoT-Edge.
trolling the data plane devices from a different location. As The most critical challenge is the integration of the hetero-
devices at the data plane cannot decide traffic flow, a seamless geneous infrastructure, where the trust, security, and privacy
communication mechanism is necessary between the controller among the computation endpoints needs to be established.
and data plane devices to efficiently manage the network This survey proposed SDN and edge computing for effective
traffic. This presents a communication overhead between the IoT service orchestration and infrastructure management. We
controller and data plane devices depending on the architecture provide extensive discussion on the areas where SDN can be
of the network, in addition to applications at the application beneficial for efficient IoT implementation using edge comput-
plane. ing. A taxonomy of the available literature has been discussed
The controller is a central component of the network that based on different performance metrics, which can support
can be overloaded with extensive flow rule installation re- researchers in selecting the relevant solutions according to
quests. This forging of the network flows on the controller their demand. We propose that the standardization in SDIoT-
make it a bottleneck due to the limitation of the computation Edge needs extensive consideration due to the heterogeneity
resources, e.g., memory and processing power. To address this in the infrastructure. The security and privacy vulnerabilities
challenge, distributed controllers can be deployed to avoid the arising from the multi-device exposure of data are vital threats
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 37

to the effective realization of SDIoT-Edge. We postulate that [22] R. Olaniyan, O. Fadahunsi, M. Maheswaran, and M. F. Zhani, “Op-
the attack vectors in IoT are greater than the traditional portunistic edge computing: Concepts, opportunities and research chal-
lenges,” Future Gener. Comput. Syst., vol. 89, pp. 633 – 645, 2018.
networks due to the lack of security solutions. SDIoT-Edge is [23] E. Ahmed, A. Ahmed, I. Yaqoob, J. Shuja, A. Gani, M. Imran, and
the key enabling factor for future generation computing sys- M. Shoaib, “Bringing computation closer toward the user network: Is
tems because of intense demand for smart devices. Therefore, edge computing the solution?” IEEE Commun. Mag., vol. 55, no. 11,
pp. 138–144, 2017.
security, privacy, integration, and standardization requirements [24] A. H. Sodhro, S. Pirbhulal, and V. H. C. de Albuquerque, “Artificial
need to be adequately established for an effective SDIoT-Edge intelligence driven mechanism for edge computing based industrial
realization. applications,” IEEE Trans. Industrial Informatics, In press, 2019.
[25] E. Jonas, J. Schleier-Smith, V. Sreekanti, C.-C. Tsai, A. Khandelwal,
Q. Pu, V. Shankar, J. Carreira, K. Krauth, N. Yadwadkar et al., “Cloud
programming simplified: A berkeley view on serverless computing,”
R EFERENCES arXiv preprint arXiv:1902.03383, 2019.
[26] I. Farris, T. Taleb, Y. Khettab, and J. Song, “A survey on emerging sdn
[1] M. Weiser, “Comput. 21st century,” IEEE Pervasive Comput., vol. 1, and nfv security mechanisms for iot systems,” IEEE Commun. Surveys
no. 1, pp. 19–25, 2002. Tuts., vol. 21, no. 1, pp. 812–837, 2019.
[2] Q. Ni, I. Cleland, C. Nugent, A. B. G. Hernando, and I. P. de la Cruz, [27] J. Pan and J. McElhannon, “Future edge cloud and edge computing for
“Design and assessment of the data analysis process for a wrist-worn internet of things applications,” IEEE Internet Things J., vol. 5, no. 1,
smart object to detect atomic activities in the smart home,” Pervasive pp. 439–449, 2018.
Mobile Comput., vol. 56, pp. 57 – 70, 2019. [28] N. Abbas, Y. Zhang, A. Taherkordi, and T. Skeie, “Mobile edge
[3] G. Wilson, C. Pereyda, N. Raghunath, G. de la Cruz, S. Goel, computing: A survey,” IEEE Internet Things J., vol. 5, no. 1, pp. 450–
S. Nesaei, B. Minor, M. Schmitter-Edgecombe, M. E. Taylor, and 465, 2018.
D. J. Cook, “Robot-enabled support of daily activities in smart home [29] P. Porambage, J. Okwuibe, M. Liyanage, M. Ylianttila, and T. Taleb,
environments,” Cognitive Syst. Research, vol. 54, pp. 258 – 272, 2019. “Survey on multi-access edge computing for internet of things real-
[4] “50 billion connections 2020,,” 2018. [Online]. Available: ization,” IEEE Commun. Surveys Tuts., vol. 20, no. 4, pp. 2961–2991,
[Link] 2018.
[5] L. Atzori, J. Bellido, R. Bolla, G. Genovese, A. Iera, A. Jara, [30] F. Javed, M. K. Afzal, M. Sharif, and B. Kim, “Internet of things
C. Lombardo, and G. Morabito, “Sdn&nfv contribution to iot objects (iot) operating systems support, networking technologies, applications,
virtualization,” Comput. Netw., vol. 149, pp. 200 – 212, 2019. and challenges: A comparative review,” IEEE Commun. Surveys Tuts.,
[6] B. Afzal, M. Umair, G. A. Shah, and E. Ahmed, “Enabling iot platforms vol. 20, no. 3, pp. 2062–2100, 2018.
for social iot applications: Vision, feature mapping, and challenges,” [31] C. Mouradian, D. Naboulsi, S. Yangui, R. H. Glitho, M. J. Morrow, and
Future Gener. Comput. Syst., vol. 92, pp. 718 – 731, 2019. P. A. Polakos, “A comprehensive survey on fog computing: State-of-
[7] B. W. Wirtz, J. C. Weyerer, and F. T. Schichtel, “An integrative public the-art and research challenges,” IEEE Commun. Surveys Tuts., vol. 20,
iot framework for smart government,” Government Inf. Quarterly, no. 1, pp. 416–464, 2018.
vol. 36, no. 2, pp. 333 – 345, 2019. [32] O. Salman, I. Elhajj, A. Chehab, and A. Kayssi, “Iot survey: An sdn
[8] A. Chaudhary and P. Tomar, “Big data and iot applications in real life and fog computing perspective,” Comput. Netw., vol. 143, pp. 221 –
environment,” in Proc. Handbook of Research Big Data IoT, 2019, pp. 246, 2018.
1–21. [33] R. Roman, J. Lopez, and M. Mambo, “Mobile edge computing, fog et
[9] S. Habib, J. Qadir, A. Ali, D. Habib, M. Li, and A. Sathiaseelan, al.: A survey and analysis of security threats and challenges,” Future
“The past, present, and future of transport-layer multipath,” J. Network Gener. Comput. Syst., vol. 78, pp. 680–698, 2018.
Comput. Appl., vol. 75, pp. 236 – 258, 2016. [34] A. C. Baktir, A. Ozgovde, and C. Ersoy, “How can edge computing
benefit from software-defined networking: A survey, use cases, and
[10] J.-P. Vasseur and A. Dunkels, “Chapter 3 - why ip for smart objects?”
future directions,” IEEE Commun. Surveys Tuts., vol. 19, no. 4, pp.
in Interconnecting Smart Objects with IP, J.-P. Vasseur and A. Dunkels,
2359–2391, 2017.
Eds. Boston: Morgan Kaufmann, 2010, pp. 29 – 38.
[35] Y. Mao, C. You, J. Zhang, K. Huang, and K. B. Letaief, “A survey
[11] M. A. Gallo and W. M. Hancock, “Chapter 3 - the internet and tcp/ip,”
on mobile edge computing: The communication perspective,” IEEE
in Networking Explained (Second Edition), 2nd ed., M. A. Gallo and
Commun. Surveys Tuts., vol. 19, no. 4, pp. 2322–2358, 2017.
W. M. Hancock, Eds. Woburn: Digital Press, 2002, pp. 55 – 138.
[36] W. Yu, F. Liang, X. He, W. G. Hatcher, C. Lu, J. Lin, and X. Yang, “A
[12] M. Aly, F. Khomh, Y.-G. Guéhéneuc, H. Washizaki, and S. Yacout, “Is survey on the edge computing for the internet of things,” IEEE Access,
fragmentation a threat to the success of the internet of things?” IEEE vol. 6, pp. 6900–6919, 2018.
Internet Things J., vol. 6, no. 1, pp. 472–487, 2019. [37] A. Botta, W. De Donato, V. Persico, and A. Pescapé, “Integration
[13] Z. Xu, L. Chao, and X. Peng, “T-rest: An open-enabled architectural of cloud computing and internet of things: a survey,” Future Gener.
style for the internet of things,” IEEE Internet Things J., In press, 2019. Comput. Syst., vol. 56, pp. 684–700, 2016.
[14] X. Xu, Q. Liu, Y. Luo, K. Peng, X. Zhang, S. Meng, and L. Qi, “A [38] H. Elazhary, “Internet of things (iot), mobile cloud, cloudlet, mobile iot,
computation offloading method over big data for iot-enabled cloud- iot cloud, fog, mobile edge, and edge emerging computing paradigms:
edge computing,” Future Gener. Comput. Syst., vol. 95, pp. 522–533, Disambiguation and research directions,” J. Network and Comput.
2019. Appl., vol. 128, pp. 105 – 140, 2019.
[15] L. Tu, S. Liu, Y. Wang, C. Zhang, and P. Li, “An optimized cluster [39] M. Mukherjee, L. Shu, and D. Wang, “Survey of fog computing:
storage method for real-time big data in internet of things,” J. Super- Fundamental, network applications, and research challenges,” IEEE
comput., pp. 1–17, 2019. Commun. Surveys Tuts., vol. 20, no. 3, pp. 1826–1857, 2018.
[16] K. R. Sollins, “Iot big data security and privacy vs. innovation,” IEEE [40] Y. Ai, M. Peng, and K. Zhang, “Edge computing technologies for
Internet Things J., In press, 2019. internet of things: a primer,” Digital Commun. Netw., vol. 4, no. 2,
[17] A. J. Ferrer, J. M. Marquès, and J. Jorba, “Towards the decentralised pp. 77–86, 2018.
cloud: Survey on approaches and challenges for mobile, ad hoc, and [41] C. Stergiou, K. E. Psannis, B.-G. Kim, and B. Gupta, “Secure integra-
edge computing,” ACM Comput. Surveys, vol. 51, no. 6, p. 111, 2019. tion of iot and cloud computing,” Future Gener. Comput. Syst., vol. 78,
[18] M. Satyanarayanan, “The emergence of edge computing,” Comput., pp. 964–975, 2018.
vol. 50, no. 1, pp. 30–39, 2017. [42] J. Hendler and J. Golbeck, “Metcalfe’s law, web 2.0, and the semantic
[19] L. Baresi, D. Mendonça, M. Garriga, S. Guinea, and G. Quattrocchi, web,” Web Semantics: Sci., Serv. Agents World Wide Web, vol. 6, no. 1,
“A unified model for the mobile-edge-cloud continuum,” ACM Trans. pp. 14–20, 2008.
Internet Technol., vol. 19, no. 2, p. 29, 2019. [43] S. Khan, A. Gani, A. W. A. Wahab, M. Guizani, and M. K. Khan,
[20] S. Wang, Y. Zhao, L. Huang, J. Xu, and C.-H. Hsu, “Qos prediction “Topology discovery in defined networks: Threats, taxonomy, and state-
for service recommendations in mobile edge computing,” J. Parallel of-the-art,” IEEE Commun. Surveys Tuts., vol. 19, no. 1, pp. 303–324,
Distrib. Comput., vol. 127, pp. 134 – 144, 2019. 2017.
[21] E. Ahmed and M. H. Rehmani, “Mobile edge computing: Opportuni- [44] K. Poularakis, Q. Qin, E. M. Nahum, M. Rio, and L. Tassiulas,
ties, solutions, and challenges,” Future Gener. Comput. Syst., vol. 70, “Flexible sdn control in tactical ad hoc networks,” Ad Hoc Netw.,
pp. 59 – 63, 2017. vol. 85, pp. 71–80, 2019.
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 38

[45] A. M. Zarca, J. B. Bernabe, R. Trapero, D. Rivera, J. Villalobos, [68] I. Stellios, P. Kotzanikolaou, M. Psarakis, C. Alcaraz, and J. Lopez, “A
A. Skarmeta, S. Bianchi, A. Zafeiropoulos, and P. Gouvas, “Security survey of iot-enabled cyberattacks: Assessing attack paths to critical
management architecture for nfv/sdn-aware iot systems,” IEEE Internet infrastructures and services,” IEEE Commun. Surveys Tuts., vol. 20,
Things J., In press, 2019. no. 4, pp. 3453–3495, 2018.
[46] A. Akhunzada and M. K. Khan, “Toward secure defined vehicular [69] Scopus. [Online]. Available:
networks: Taxonomy, requirements, and open issues,” IEEE Commun. [Link]/search/[Link]?display=basic. Accessed May
Mag., vol. 55, no. 7, pp. 110–118, 2017. 29, 2019.
[47] N. M. Freris et al., “A software-defined architecture for control of iot [70] P. P. Ray, “A survey on internet of things architectures,” J. King Saud
cyberphysical systems,” Cluster Comput., pp. 1–16, 2017. University-Comput. and Inf. Sci., vol. 30, no. 3, pp. 291–319, 2018.
[48] Y. Jararweh, M. Al-Ayyoub, E. Benkhelifa et al., “An experimental [71] A. H. Ngu, M. Gutierrez, V. Metsis, S. Nepal, and Q. Z. Sheng, “Iot
framework for future smart cities using data fusion and software defined middleware: A survey on issues and enabling technologies,” IEEE
systems: the case of environmental monitoring for smart healthcare,” Internet Things J., vol. 4, no. 1, pp. 1–20, 2017.
Future Gener. Comput. Syst., In press, 2018. [72] J. Gubbi, R. Buyya, S. Marusic, and M. Palaniswami, “Internet of
[49] I. Haque, M. Nurujjaman, J. Harms, and N. Abu-Ghazaleh, “Sdsense: things (iot): A vision, architectural elements, and future directions,”
An agile and flexible sdn-based framework for wireless sensor net- Future Gener. Comput. Syst., vol. 29, no. 7, pp. 1645–1660, 2013.
works,” IEEE Trans. Veh. Technol., vol. 68, no. 2, pp. 1866–1876, [73] R. Minerva, A. Biru, and D. Rotondi, “Towards a definition of the
2019. internet of things (iot),” IEEE Internet Initiative, vol. 1, pp. 1–86, 2015.
[50] I. Alam, K. Sharif, F. Li, Z. Latif, M. M. Karim, B. Nour, S. Biswas, [74] G. M. Lee, P. Jungsoo, K. Ning, and C. Noel, “The internet of things
and Y. Wang, “Iot virtualization: A survey of software definition & - concept and problem statement,” July 2011. [Online]. Available:
function virtualization techniques for internet of things,” arXiv preprint [Link]/html/draft-lee-iot-problem-statement-02.
arXiv:1902.10910, 2019. [75] S. Debroy, P. Samanta, A. Bashir, and M. Chatterjee, “Speed-iot:
[51] M. Satyanarayanan, P. Simoens, Y. Xiao, P. Pillai, Z. Chen, K. Ha, Spectrum aware energy efficient routing for device-to-device iot com-
W. Hu, and B. Amos, “Edge analytics in the internet of things,” IEEE munication,” Future Gener. Comput. Syst., vol. 93, pp. 833 – 848, 2019.
Pervasive Comput., vol. 14, no. 2, pp. 24–31, 2015. [76] P. K. Verma, R. Verma, A. Prakash, A. Agrawal, K. Naik, R. Tripathi,
[52] Y. Jararweh, M. Alsmirat, M. Al-Ayyoub, E. Benkhelifa, A. Darabseh, M. Alsabaan, T. Khalifa, T. Abdelkader, and A. Abogharaf, “Machine-
B. Gupta, and A. Doulat, “Software-defined system support for en- to-machine (m2m) communications: A survey,” J. Netw. Comput. Appl.,
abling ubiquitous mobile edge computing,” Comput. Journal, vol. 60, vol. 66, pp. 83–105, 2016.
no. 10, pp. 1443–1457, 2017.
[77] I. Bojanova, G. Hurlburt, and J. Voas, “Imagineering an internet of
[53] S. Almajali, H. B. Salameh, M. Ayyash, and H. Elgala, “A framework anything,” Comput., vol. 47, no. 6, pp. 72–77, 2014.
for efficient and secured mobility of iot devices in mobile edge
[78] “The internet of everything global public sector eco-
computing,” in Proc. 3rd IEEE Int. Conf. Fog Mobile Edge Comput.
nomic analysis,” Accessed on September 28, 2019. [On-
(FMEC), 2018, Barcelona, Spain, pp. 58–62.
line]. Available: [Link] us/about/business-
[54] R. Sairam, S. S. Bhunia, V. Thangavelu, and M. Gurusamy, “Netra:
insights/docs/[Link]
Enhancing iot security using nfv-based edge traffic analysis,” IEEE
[79] D. McFarlane, “Industrial internet of things applying iot in the
Sensors J., In press, 2019.
industrial context,” Accessed on September 28, 2018. [Online]. Avail-
[55] M. Uddin, T. Nadeem, and S. Nukavarapu, “Extreme sdn framework
able: [Link]
for iot and mobile applications flexible privacy at the edge,” Heart,
[Link]
vol. 200, p. 250, 2019.
[80] B. Chen, J. Wan, Y. Lan, M. Imran, D. Li, and N. Guizani, “Improving
[56] S. Misra and N. Saha, “Detour: Dynamic task offloading in software-
cognitive ability of edge intelligent iiot through machine learning,”
defined fog for iot applications,” IEEE J. Sel. Areas Commun., vol. 37,
IEEE Netw., vol. 33, no. 5, pp. 61–67, 2019.
no. 5, pp. 1159–1166, 2019.
[57] A. J. Kadhim and S. A. H. Seno, “Maximizing the utilization of fog [81] H. Tang, D. Li, J. Wan, M. Imran, and M. Shoaib, “A reconfigurable
computing in internet of vehicle using sdn,” IEEE Commun. Letters, method for intelligent manufacturing based on industrial cloud and
vol. 23, no. 1, pp. 140–143, 2019. edge intelligence,” IEEE Internet Things J., In press, 2019.
[58] J. Dizdarević, F. Carpio, A. Jukan, and X. Masip-Bruin, “A survey of [82] M. H. ur Rehman, I. Yaqoob, K. Salah, M. Imran, P. P. Jayaraman,
communication protocols for internet of things and related challenges and C. Perera, “The role of big data analytics in industrial internet of
of fog and cloud computing integration,” ACM Comput. Surveys, things,” Future Gener. Comput. Syst., vol. 99, pp. 247–259, 2019.
vol. 51, no. 6, p. 116, 2019. [83] D. V. Dimitrov, “Medical internet of things and big data in healthcare,”
[59] I. Yaqoob, I. A. T. Hashem, A. Ahmed, S. A. Kazmi, and C. S. Hong, Healthcare Inf. Research, vol. 22, no. 3, pp. 156–163, 2016.
“Internet of things forensics: Recent advances, taxonomy, requirements, [84] D. Zeng, S. Guo, and Z. Cheng, “The web of things: A survey,” JCM,
and open challenges,” Future Gener. Comput. Syst., vol. 92, pp. 265– vol. 6, no. 6, pp. 424–438, 2011.
275, 2019. [85] R. M.S., S. Pattar, R. Buyya, V. K.R., S. Iyengar, and L. Patnaik,
[60] E. Alfonso, Velosa, Perkins, L. Hung, J. F. Hines, and S. R.M, “Social internet of things (siot): Foundations, thrust areas, systematic
“Predicts 2015: The internet of things,” 2015. [Online]. Available: review and future directions,” Comput. Commun., vol. 139, pp. 32 –
[Link] 57, 2019.
[61] V. Afshar, “Cisco: Enterprises are leading the [86] M. G. Sarowar, M. S. Kamal, and N. Dey, “Internet of things and
internet of things innovation,” 2017. [Online]. its impacts in computing intelligence: A comprehensive review–iot
Available: [Link] application for big data,” in Proc. Big Data Analytics for Smart and
leading-the-internet-of-things-us-59a41fcee4b0a62d0987b0c6 Connected Cities, 2019, pp. 103–136.
[62] L. Calderoni, A. Magnani, and D. Maio, “Iot manager: An open-source [87] Y. Mehmood, F. Ahmad, I. Yaqoob, A. Adnane, M. Imran, and
iot framework for smart cities,” J. Syst. Archit., In press, 2019. S. Guizani, “Internet-of-things-based smart cities: Recent advances and
[63] O. Bello and S. Zeadally, “Toward efficient smartification of the internet challenges,” IEEE Commun. Mag., vol. 55, no. 9, pp. 16–24, 2017.
of things (iot) services,” Future Gener. Comput. Syst., vol. 92, pp. 663 [88] M. Gusev and S. Dustdar, “Going back to the roots—the evolution of
– 673, 2019. edge computing, an iot perspective,” IEEE Internet Computing, vol. 22,
[64] M. binti Mohamad Noor and W. H. Hassan, “Current research on no. 2, pp. 5–15, 2018.
internet of things (iot) security: A survey,” Comput. Netw., vol. 148, [89] A. Taivalsaari and T. Mikkonen, “Cloud technologies for the internet
pp. 283 – 294, 2019. of things: Defining a research agenda beyond the expected topics,” in
[65] M. De Donno, N. Dragoni, A. Giaretta, and A. Spognardi, “Ddos- Proc. 41st IEEE Euromicro Conf. Softw. Engineer. Advanc. Appl., 2015,
capable iot malwares: Comparative analysis and mirai investigation,” Madeira, Portugal, pp. 484–488.
Security Commun. Netw., pp. 1–30, 2018. [90] X. Zheng, A. Chen, G. Luo, L. Tian, and Z. Cai, “Privacy-preserved
[66] C. Bodei, S. Chessa, and L. Galletta, “Measuring security in iot distinct content collection in human-assisted ubiquitous computing
communications,” Theoretical Comput. Sci., vol. 764, pp. 100 – 124, systems,” Inf. Sci., vol. 493, pp. 91 – 104, 2019.
2019. [91] S. Goudarzi, M. H. Anisi, A. H. Abdullah, J. Lloret, S. A. Soleymani,
[67] J. Pan and J. McElhannon, “Future edge cloud and edge computing for and W. H. Hassan, “A hybrid intelligent model for network selection
internet of things applications,” IEEE Internet Things J., vol. 5, no. 1, in the industrial internet of things,” Appl. Soft Comput., vol. 74, pp.
pp. 439–449, 2018. 529 – 546, 2019.
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 39

[92] R. F. Babiceanu and R. Seker, “Cyber resilience protection for in- [115] R. Mijumbi, J. Serrat, J.-L. Gorricho, N. Bouten, F. De Turck, and
dustrial internet of things: A software-defined networking approach,” R. Boutaba, “Network function virtualization: State-of-the-art and
Comput. Industry, vol. 104, pp. 47 – 58, 2019. research challenges,” IEEE Commun. Surveys Tuts., vol. 18, no. 1, pp.
[93] M. Frustaci, P. Pace, G. Aloi, and G. Fortino, “Evaluating critical 236–262, 2015.
security issues of the iot world: Present and future challenges,” IEEE [116] B. Varghese, W. Nan, L. I. Jianyu, and D. S. Nikolopoulos, “Edge-as-
Internet Things J., vol. 5, no. 4, pp. 2483–2495, 2018. a-service: Towards distributed cloud architectures,” in Proc. Int. Conf.
[94] J. G. An, F. Le Gall, J. Kim, J. Yun, J. Hwang, M. Bauer, M. Zhao, on Parallel Comput. (ParCo), 2017, Bologna, Italy, pp. 1–10.
and J. S. Song, “Towards global iot-enabled smart cities interworking [117] S. Sahhaf, W. Tavernier, M. Rost, S. Schmid, D. Colle, M. Pickavet, and
using adaptive semantic adapter,” IEEE Internet Things J., In press, P. Demeester, “Network service chaining with optimized network func-
2019. tion embedding supporting service decompositions,” Comput. Netw.,
[95] D. Dujovne, T. Watteyne, X. Vilajosana, and P. Thubert, “6tisch: vol. 93, pp. 492–505, 2015.
deterministic ip-enabled industrial internet (of things),” IEEE Commun. [118] “Huawei observation to nfv,” Accessed on
Mag., vol. 52, no. 12, pp. 36–41, 2014. September 28, 2019. [Online]. Available:
[96] L. Doyle, “Facebook, google use sdn to boost data [Link] 399662
center connectivity,” Accessed on September 28, 2019. [On- [119] “European telecommunications standards institute industry
line]. Available: [Link] specifications group, mobile-edge computing—network functions
Google-use-SDN-to-boost-data-center-connectivity virtualisation.” [Online]. Available: [Link]
[97] M. Yang, H. Rastegarfar, and I. B. Djordjevic, “Physical-layer adap- clusters/technologies/nfv, Accessed October 06, 2019
tive resource allocation in software-defined data center networks,” [120] F. B. Jemaa, G. Pujolle, and M. Pariente, “Cloudlet- and nfv-based
IEEE/OSA J. Optical Commun. Netw., vol. 10, no. 12, pp. 1015–1026, carrier wi-fi architecture for a wider range of services,” Annals
2018. Telecommun., vol. 71, no. 11-12, pp. 1–8, 2016.
[98] “Software defined networking: The new norm for networks,” [121] W. Z. Khan, E. Ahmed, S. Hakak, I. Yaqoob, and A. Ahmed, “Edge
Accessed on September 28, 2019. [Online]. Available: computing: A survey,” Future Gener. Comput. Syst., vol. 97, pp. 219
[Link] – 235, 2019.
[Link] [122] M. Alenezi, K. Almustafa, and K. A. Meerja, “Cloud based sdn and
[99] F. de Oliveira Silva, J. H. de Souza Pereira, P. F. Rosa, and S. T. Kofuji, nfv architectures for iot infrastructure,” Egyptian Inf. Journal, vol. 20,
“Enabling future internet architecture research and experimentation by no. 1, pp. 1 – 10, 2019.
using software defined networking,” in Proc. IEEE European Workshop [123] M. S. Bonfim, K. L. Dias, and S. F. L. Fernandes, “Integrated nfv/sdn
Softw. Defined Netw., 2012, Darmstadt, Germany, pp. 73–78. architectures: A systematic literature review,” ACM Comput. Surveys,
[100] D. Kreutz, F. M. V. Ramos, P. E. Verı́ssimo, C. E. Rothenberg, vol. 51, no. 6, pp. 114:1–114:39, 2019.
S. Azodolmolky, and S. Uhlig, “Software-defined networking: A com- [124] A. Tzanakaki, M. P. Anastasopoulos, and D. Simeonidou, “Converged
prehensive survey,” Proc. IEEE, vol. 103, no. 1, pp. 14–76, 2015. optical, wireless, and data center network infrastructures for 5g ser-
[101] M. Casado, M. J. Freedman, J. Pettit, J. Luo, N. Gude, N. McKeown, vices,” IEEE/OSA J. Optical Commun. Netw., vol. 11, no. 2, pp. A111–
and S. Shenker, “Rethinking enterprise network control,” IEEE/ACM A122, 2019.
Trans. Netw., vol. 17, no. 4, pp. 1270–1283, 2009. [125] N. Y. Kim, J. H. Ryu, B. W. Kwon, Y. Pan, and J. H. Park,
[102] L. Wang, Q. Li, R. Sinnott, Y. Jiang, and J. Wu, “An intelligent rule “Cf-cloudorch: container fog node-based cloud orchestration for iot
management scheme for software defined networking,” Comput. Netw., networks,” J. Supercomput., vol. 74, no. 12, pp. 7024–7045, 2018.
vol. 144, pp. 77 – 88, 2018. [126] A. Blenk, A. Basta, M. Reisslein, and W. Kellerer, “Survey on
[103] I. I. Awan, N. Shah, M. Imran, M. Shoaib, and N. Saeed, “An improved network virtualization hypervisors for software defined networking,”
mechanism for flow rule installation in-band sdn,” J. Syst. Archit., IEEE Commun. Surveys Tuts., vol. 18, no. 1, pp. 655–685, 2016.
vol. 96, pp. 1 – 19, 2019. [127] H. A. Alameddine, S. Sharafeddine, S. Sebbah, S. Ayoubi, and C. Assi,
[104] M. Casado, N. Foster, and A. Guha, “Abstractions for software-defined “Dynamic task offloading and scheduling for low-latency iot services
networks,” Commu. ACM, vol. 57, no. 10, pp. 86–95, 2014. in multi-access edge computing,” IEEE J. Selected Areas Commun.,
[105] K. M. Modieginyane, B. B. Letswamotse, R. Malekian, and A. M. vol. 37, no. 3, pp. 668–682, 2019.
Abu-Mahfouz, “Software defined wireless sensor networks application [128] J. Wang, J. Pan, and F. Esposito, “Elastic urban video surveillance
opportunities for efficient network management: A survey,” Comput. system using edge computing,” in Proc. ACM Workshop Smart Internet
Electrical Eng., vol. 66, pp. 274 – 287, 2018. Things, 2017, New York, NY, USA, p. 7.
[106] G. S. Aujla, R. Chaudhary, K. Kaur, S. Garg, N. Kumar, and R. Ranjan, [129] Y. Lin, H. Tseng, Y. Lin, and L. Chen, “Nb-iottalk: A service platform
“Safe: Sdn-assisted framework for edge–cloud interplay in secure for fast development of nb-iot applications,” IEEE Internet Things J.,
healthcare ecosystem,” IEEE Trans. Industrial Informatics, vol. 15, vol. 6, no. 1, pp. 928–939, 2019.
no. 1, pp. 469–480, 2019. [130] E. A. Mazied, M. Y. ElNainay, M. J. Abdel-Rahman, S. F. Midkiff,
[107] F. A. Zaman, A. Jarray, and A. Karmouch, “defined network-based M. R. Rizk, H. A. Rakha, and A. B. MacKenzie, “The wireless
edge cloud resource allocation framework,” IEEE Access, vol. 7, pp. control plane: An overview and directions for future research,” J. Netw.
10 672–10 690, 2019. Comput. Appl., vol. 126, pp. 104 – 122, 2019.
[108] N. McKeown, T. Anderson, H. Balakrishnan, G. Parulkar, L. Peterson, [131] J. Huang, Q. Duan, S. Guo, Y. Yan, and S. Yu, “Converged network-
J. Rexford, S. Shenker, and J. Turner, “Openflow: enabling innovation cloud service composition with end-to-end performance guarantee,”
in campus networks,” ACM SIGCOMM Comput. Commun. Review, IEEE Trans. Cloud Comput., vol. 6, no. 2, pp. 545–557, 2018.
vol. 38, no. 2, pp. 69–74, 2008. [132] B. N. Silva, M. Khan, and K. Han, “Internet of things: A comprehensive
[109] “Sdn architecture,” Accessed on September 28, review of enabling technologies, architecture, and challenges,” IETE
2019. [Online]. Available: [Link] Technical review, vol. 35, no. 2, pp. 205–220, 2018.
content/uploads/2013/02/[Link] [133] B. Yang, W. K. Chai, Z. Xu, K. V. Katsaros, and G. Pavlou, “Cost-
[110] W. Zhou, L. Li, M. Luo, and W. Chou, “Rest api design patterns for efficient nfv-enabled mobile edge-cloud for low latency mobile applica-
sdn northbound api,” in Proc. 28th IEEE Int. Conf. Advanced Inform. tions,” IEEE Trans. Netw. Service Manag., vol. 15, no. 1, pp. 475–488,
Netw. Appl. Workshops, 2014, Victoria, British Columbia, pp. 358–365. 2018.
[111] “Openflow switch specification version 1.5.0.” [134] A. A. Abdelltif, E. Ahmed, A. T. Fong, A. Gani, and M. Imran, “Sdn-
[Online]. Available: [Link] based load balancing service for cloud servers,” IEEE Commun. Mag.,
content/uploads/2014/10/[Link] vol. 56, no. 8, pp. 106–111, 2018.
[112] S. A. Hossain, M. A. Rahman, and M. A. Hossain, “Edge computing [135] M. K. Jaiswal, “Introduction to openflow,” in Proc. Innovations in
framework for enabling situation awareness in iot based smart city,” J. Software-Defined Netw. Netw. Functions Virtualization, 2018, pp. 52–
Parallel Distrib. Comput., vol. 122, pp. 226 – 237, 2018. 71.
[113] I. Farris, A. Orsino, L. Militano, A. Iera, and G. Araniti, “Federated [136] S. Secci, P. Raad, and P. Gallard, “Linking virtual machine mobility to
iot services leveraging 5g technologies at the edge,” Ad Hoc Netw., user mobility,” IEEE Trans. Netw. Service Manag., vol. 13, no. 4, pp.
vol. 68, pp. 58 – 69, 2018. 927–940, Dec 2016.
[114] M. Satyanarayanan, R. Schuster, M. Ebling, G. Fettweis, H. Flinck, [137] A. Raza and S. Lee, “Gate switch selection for in-band controlling
K. Joshi, and K. Sabnani, “An open ecosystem for mobile-cloud in software defined networking,” IEEE Access, vol. 7, pp. 5671–5681,
convergence,” IEEE Commun. Mag., vol. 53, no. 3, pp. 63–70, 2015. 2019.
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 40

[138] R. Muñoz, R. Vilalta, N. Yoshikane, R. Casellas, R. Martı́nez, T. Tsuri- requirements, and challenges,” IEEE Netw., vol. 34, no. 1, pp. 174–181,
tani, and I. Morita, “Integration of iot, transport sdn, and edge/cloud 2020.
computing for dynamic distribution of iot analytics and efficient use of [161] E. Ahmed, A. Naveed, A. Gani, S. H. A. Hamid, M. Imran, and
network resources,” J. Lightwave Technol., vol. 36, no. 7, pp. 1420– M. Guizani, “Process state synchronization-based application execution
1428, April 2018. management for mobile edge/cloud computing,” Future Gener. Comput.
[139] H. Huang, J. Zhu, and L. Zhang, “An sdn based management frame- Syst., vol. 91, pp. 579 – 589, 2019.
work for iot devices,” in Proc. 25th IET Irish Signals Syst. Conf., 2014. [162] S. Yu, “Big privacy: Challenges and opportunities of privacy study in
[140] J. Ni, X. Lin, and X. S. Shen, “Efficient and secure service-oriented the age of big data,” IEEE Acess, vol. 4, pp. 2751–2763, 2016.
authentication supporting network slicing for 5g-enabled iot,” IEEE J. [163] C. C. Byers, “Architectural imperatives for fog computing: Use cases,
Selected Areas Commun., vol. 36, no. 3, pp. 644–657, 2018. requirements, and architectural techniques for fog-enabled iot net-
[141] A.-R. Sadeghi, C. Wachsmann, and M. Waidner, “Security and works,” IEEE Commun. Mag., vol. 55, no. 8, pp. 14–20, 2017.
privacy challenges in industrial internet of things,” in Proc. 52nd [164] A. Karim, A. Siddiqa, Z. Safdar, M. Razzaq, S. A. Gillani, H. Tahir,
ACM/EDAC/IEEE Design Automation Conf. (DAC), 2015, pp. 1–6. S. Kiran, E. Ahmed, and M. Imran, “Big data management in par-
[142] P. Gope, R. Amin, S. H. Islam, N. Kumar, and V. K. Bhalla, ticipatory sensing: Issues, trends and future directions,” Future Gener.
“Lightweight and privacy-preserving rfid authentication scheme for Comput. Syst., In press, 2017.
distributed iot infrastructure with secure localization services for smart [165] Z. Wen, X. Liu, Y. Xu, and J. Zou, “A restful framework for internet of
city environment,” Future Gener. Comput. Syst., vol. 83, pp. 629–637, things based on software defined network in modern manufacturing,”
2018. The Int. J. Advanced Manufacturing Technol., vol. 84, no. 1-4, pp.
[143] H. A. Khattak, M. A. Shah, S. Khan, I. Ali, and M. Imran, “Perception 361–369, 2016.
layer security in internet of things,” Future Gener. Comput. Syst., vol. [166] X. Li, D. Li, J. Wan, C. Liu, and M. Imran, “Adaptive transmission
100, pp. 144 – 164, 2019. optimization in sdn-based industrial internet of things with edge
[144] Q. Li, X. He, M. Xu, Y. Jiang, and L. Wang, “Unified middlebox computing,” IEEE Internet Things J., vol. 5, no. 3, pp. 1351–1360,
model design and deployment with dynamic resources,” IEEE Trans. 2018.
Netw. Service Manag., vol. 15, no. 3, pp. 1035–1048, 2018. [167] M. G. R. Alam, M. M. Hassan, M. Z. Uddin, A. Almogren, and
[145] P. Neves, C. Rui, M. Costa, G. Gaspar, J. Alcaraz-Calero, Q. Wang, G. Fortino, “Autonomic computation offloading in mobile edge for iot
J. Nightingale, G. Bernini, G. Carrozzo, and Ángel Valdivieso, “Future applications,” Future Gener. Comput. Syst., vol. 90, pp. 149–157, 2019.
mode of operations for 5g – the selfnet approach enabled by sdn/nfv,” [168] M. Boussard, D. T. Bui, R. Douville, N. Le Sauze, L. Noirie, P. Peloso,
Comput. Standards Interfaces, vol. 54, no. P4, pp. 229–246, 2017. R. Varloot, and M. Vigoureux, “The majord’home: a sdn approach to
[146] A. J. Ferrer, F. HernáNdez, J. Tordsson, E. Elmroth, A. Ali-Eldin, let isps manage and extend their customers’ home networks,” in Proc.
C. Zsigri, R. Sirvent, J. Guitart, R. M. Badia, K. Djemame et al., 10th IEEE Intl. Conf. Netw. Service Manag. (CNSM) Workshop, 2014,
“Optimis: A holistic approach to cloud service provisioning,” Future Rio de Janeiro, Brazil, pp. 430–433.
Gener. Comput. Syst., vol. 28, no. 1, pp. 66–77, 2012. [169] M. Boussard, D. T. Bui, L. Ciavaglia, R. Douville, M. Le Pallec,
[147] M. Bastam, M. Sabaei, and R. Yousefpour, “A scalable traffic engineer- N. Le Sauze, L. Noirie, S. Papillon, P. Peloso, and F. Santoro,
ing technique in an sdn-based data center network,” Trans. Emerging “Software-defined lans for interconnected smart environment,” in Proc.
Telecommun. Technol., vol. 29, no. 2, p. e3268, 2018. 27th IEEE Intl. Teletraffic Conf., 2015, Ghent, Belgium, pp. 219–227.
[148] M. Chiang and T. Zhang, “Fog and iot: An overview of research [170] A. Yassine, S. Singh, M. S. Hossain, and G. Muhammad, “Iot big
opportunities,” IEEE Internet Things J., vol. 3, no. 6, pp. 854–864, data analytics for smart homes with fog and cloud computing,” Future
2016. Gener. Comput. Syst., vol. 91, pp. 563–573, 2019.
[149] K. Zhang, S. Leng, Y. He, S. Maharjan, and Y. Zhang, “Mobile [171] O. Briante, F. Cicirelli, A. Guerrieri, A. Iera, A. Mercuri, G. Ruggeri,
edge computing and networking for green and low-latency internet of G. Spezzano, and A. Vinci, “A social and pervasive iot platform for
things,” IEEE Commun. Mag., vol. 56, no. 5, pp. 39–45, 2018. developing smart environments,” in Proc. The Internet Things Smart
[150] R. Amin, M. Reisslein, and N. Shah, “Hybrid sdn networks: A survey Urban Ecosystems, 2019, pp. 1–23.
of existing approaches,” IEEE Commun. Surveys Tuts., vol. 20, no. 4, [172] M. Lee, Y. Kim, and Y. Lee, “A home cloud-based home network auto-
pp. 3259–3306, 2018. configuration using sdn,” in Proc. 12th IEEE Intl. Conf. Netw. Sens.
[151] M. Mahalingam, D. Dutt, K. Duda, P. Agarwal, L. Kreeger, T. Sridhar, Control, 2015, Taipei, Taiwan, pp. 444–449.
M. Bursell, and C. Wright, “Virtual extensible local area network [173] A. Hakiri, P. Berthou, A. Gokhale, and S. Abdellatif,
(vxlan): A framework for overlaying virtualized layer 2 networks over “Publish/subscribe-enabled software defined networking for efficient
layer 3 networks,” Internet Eng. Task Force, Fremont, CA, USA, RFC and scalable iot communications,” arXiv preprint arXiv:1711.05036,
7348, Accessed on September 2019. 2017.
[152] A. Javed, K. Heljanko, A. Buda, and K. Främling, “Cefiot: A fault- [174] Y. Zhang, H. Zhou, and J.-l. Chen, “Cross-layer access control in pub-
tolerant iot architecture for edge and cloud,” in Proc. 4th IEEE World lish/subscribe middleware over software-defined networks,” Comput.
Forum Internet Things (WF-IoT), 2018, Singapore, Singapore, pp. 813– Commun., vol. 134, pp. 1–13, 2019.
818. [175] J. Chen, E. Cañete, D. Garrido, M. Dı́az, and K. Piotrowski, “Pico: A
[153] C. Chen, M. Won, R. Stoleru, and G. G. Xie, “Energy-efficient fault- platform independent communications middleware for heterogeneous
tolerant data storage and processing in mobile cloud,” IEEE Trans. devices in smart grids,” Computer Standards Interfaces, In press, 2019.
Cloud Comput., vol. 3, no. 1, pp. 28–41, 2015. [176] M. A. da Cruz, J. J. Rodrigues, P. Lorenz, P. Solic, J. Al-Muhtadi,
[154] D. Satria, D. Park, and M. Jo, “Recovery for overloaded mobile edge and V. H. C. Albuquerque, “A proposal for bridging application layer
computing,” Future Gener. Comput. Syst., vol. 70, pp. 138 – 147, 2017. protocols to http on iot solutions,” Future Gener. Comput. Syst., vol. 97,
[155] A. A. Abdellatif, A. Emam, C.-F. Chiasserini, A. Mohamed, A. Jaoua, pp. 145–152, 2019.
and R. Ward, “Edge-based compression and classification for smart [177] T. Lin, J.-M. Kang, H. Bannazadeh, and A. Leon-Garcia, “Enabling sdn
healthcare systems: Concept, implementation and evaluation,” Expert applications on software-defined infrastructure,” in Proc. IEEE Netw.
Syst. with Appl., vol. 117, pp. 1 – 14, 2019. Operat. Manag. Symp. (NOMS), 2014, Krakow, Poland, pp. 1–7.
[156] X. Xu, Q. Liu, Y. Luo, K. Peng, X. Zhang, S. Meng, and L. Qi, “A [178] A. Galis, J. Rubio-Loyola, S. Clayman, L. Mamatas, S. Kukliński,
computation offloading method over big data for iot-enabled cloud- J. Serrat, and T. Zahariadis, “Software enabled future internet–
edge computing,” Future Gener. Comput. Syst., vol. 95, pp. 522 – 533, challenges in orchestrating the future internet,” in Proc. Springer Intl.
2019. Conf. Mobile Netw. Manag., 2013, Tokyo, Japan, pp. 228–244.
[157] L. Valerio, M. Conti, and A. Passarella, “Energy efficient distributed [179] P. Bull, R. Austin, and M. Sharma, “Pre-emptive flow installation for
analytics at the edge of the network for iot environments,” Pervasive internet of things devices within software defined networks,” in Proc.
Mobile Comput., vol. 51, pp. 27 – 42, 2018. IEEE 3rd Intl. Conf. Future Internet Things Cloud, 2015, pp. 124–130.
[158] “Put the most trusted, independent location data and technology [180] V. R. Tadinada, “Software defined networking: Redefining the future of
platform to work for your business,” Accessed on September 28, internet in iot and cloud era,” in Proc. IEEE Intl. Conf. Future Internet
2019. [Online]. Available: [Link] Things Cloud, 2014, Barcelona, Spain, pp. 296–301.
[159] “The right information at just the right time,” Accessed on September [181] E. Patouni, A. Merentitis, P. Panagiotopoulos, A. Glentis, and
28, 2019. [Online]. Available: [Link] N. Alonistioti, “Network virtualisation trends: Virtually anything is
[160] I. Yaqoob, L. U. Khan, S. M. A. Kazmi, M. Imran, N. Guizani, and possible by connecting the unconnected,” in IEEE Conf. SDN Future
C. S. Hong, “Autonomous driving cars in smart cities: Recent advances, Netw. Services (SDN4FNS), 2013, Trento, Italy, pp. 1–7.
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 41

[182] A.-C. G. Anadiotis, L. Galluccio, S. Milardo, G. Morabito, and [204] N. Wang, B. Varghese, M. Matthaiou, and D. S. Nikolopoulos, “Enorm:
S. Palazzo, “Towards a software-defined network operating system for A framework for edge node resource management,” IEEE Trans.
the iot,” in Proc. 2nd IEEE Intl. World Forum Internet Things (WF- Services Comput., In press, 2017.
IoT), 2015, Milano, Italy, pp. 579–584. [205] M. Körner, T. M. Runge, A. Panda, S. Ratnasamy, and S. Shenker,
[183] D. Bendouda, A. Rachedi, and H. Haffaf, “Programmable architecture “Open carrier interface: An open source edge computing framework,”
based on software defined network for internet of things: connected in Proc. Workshop Netw. Emerg. Appli. Technol., 2018, Budapest,
dominated sets approach,” Future Gener. Comput. Syst., vol. 80, pp. Hungary, pp. 27–32.
188–197, 2018. [206] “The linux foundation projects,” Accessed on September 28, 2019.
[184] Y. B. Zikria, H. Yu, M. K. Afzal, M. H. Rehmani, and O. Hahm, “Inter- [Online]. Available: [Link]
net of things (iot): Operating system, applications and protocols design, [207] F. Bonomi, R. Milito, J. Zhu, and S. Addepalli, “Fog computing and its
and validation techniques,” Future Gener. Comput. Syst., vol. 88, pp. role in the internet of things,” in Proc. 1st edit. ACM MCC Workshop
699 – 706, 2018. Mobile cloud comput., 2012, New York, NY, USA, pp. 13–16.
[185] A.-C. G. Anadiotis, S. Milardo, G. Morabito, and S. Palazzo, “Toward [208] B. Varghese, N. Wang, J. Li, and D. S. Nikolopoulos, “Edge-as-
unified control of networks of switches and sensors through a network a-service: Towards distributed cloud architectures,” arXiv preprint
operating system,” IEEE Internet Things J., vol. 5, no. 2, pp. 895–904, arXiv:1710.10090, 2017.
2018. [209] B. Chen, M. Imran, N. Nasser, and M. Shoaib, “Self-aware autonomous
[186] P. Martinez-Julia and A. F. Skarmeta, “Empowering the internet of city: From sensing to planning,” IEEE Commun. Mag., vol. 57, no. 4,
things with software defined networking,” FP7 European research pp. 33–39, 2019.
project on the future Internet of Things, 2014. [210] H. Teng, Y. Liu, A. Liu, N. N. Xiong, Z. Cai, T. Wang, and X. Liu, “A
[187] M. Ojo, D. Adami, and S. Giordano, “A sdn-iot architecture with nfv novel code data dissemination scheme for internet of things through
implementation,” in Proc. IEEE Globecom Workshops (GC Wkshps), mobile vehicle of smart cities,” Future Gener. Comput. Syst., vol. 94,
2016, Washington DC, United States, pp. 1–6. pp. 351–367, 2019.
[188] P. Hu, “A system architecture for software-defined industrial internet [211] “Charging infrastructure for electric vehicles in germany progress re-
of things,” in Proc. IEEE Intl. Conf. Ubiquit. Wireless Broadband port and recommendations 2015,” Nationale Platform Elektromobilitat,
(ICUWB), 2015, Montreal, QC, Canada, pp. 1–5. Report, 2015.
[189] R. Morabito, I. Farris, A. Iera, and T. Taleb, “Evaluating performance [212] H. El-Sayed, S. Sankar, M. Prasad, D. Puthal, A. Gupta, M. Mohanty,
of containerized iot services for clustered devices at the network edge,” and C.-T. Lin, “Edge of things: The big picture on the integration of
IEEE Internet Things J., vol. 4, no. 4, pp. 1019–1030, 2017. edge, iot and the cloud in a distributed computing environment,” IEEE
[190] Y. Jararweh, M. Al-Ayyoub, E. Benkhelifa, M. Vouk, A. Rindos et al., Access, vol. 6, pp. 1706–1717, 2018.
“Sdiot: a software defined based internet of things framework,” J. [213] T. Hayajneh, K. Griggs, M. Imran, and B. J. Mohd, “Secure and
Ambient Intelligence Humanized Comput., vol. 6, no. 4, pp. 453–461, efficient data delivery for fog-assisted wireless body area networks,”
2015. Peer-to-Peer Netw. Appl., vol. 12, no. 5, pp. 1289–1307, 2019.
[191] Q. Xiaofeng, L. Wenmao, G. Teng, H. Xinxin, W. Xutao, and [214] M. I. Razzak, M. Imran, and G. Xu, “Big data analytics for preventive
C. Pengcheng, “Wot/sdn: web of things architecture using sdn,” China medicine,” Neural Comput. Appl., In press, 2019.
Commun., vol. 12, no. 11, pp. 1–11, 2015.
[215] G. Fortino, C. Savaglio, C. E. Palau, J. S. de Puga, M. Ganzha,
[192] M. Steiner, G. Tsudik, and M. Waidner, “Diffie-hellman key distribu-
M. Paprzycki, M. Montesinos, A. Liotta, and M. Llop, “Towards
tion extended to group communication,” in 3rd ACM Conf. Comput.
multi-layer interoperability of heterogeneous iot platforms: The inter-
Commun. Security, 1996, Delhi, India, pp. 31–37.
iot approach,” in Proc. Integ., interconn., and interopera. IoT Syst.,
[193] X. Zhang, C. Lyu, Z. Shi, D. Li, N. N. Xiong, and C. Chi, “Reliable
2018, pp. 199–232.
multiservice delivery in fog-enabled vanets: Integrated misbehavior
[216] C. Gomez, A. Arcia-Moret, and J. Crowcroft, “Tcp in the internet of
detection and tolerance,” IEEE Access, vol. 7, pp. 95 762–95 778, 2019.
things: from ostracism to prominence,” IEEE Internet Comput., vol. 22,
[194] J.-w. Xu, K. Ota, M.-x. Dong, A.-f. Liu, and Q. Li, “Siotfog: Byzantine-
no. 1, pp. 29–41, 2018.
resilient iot fog networking,” Frontiers Inf. Technol. Electronic Eng.,
vol. 19, no. 12, pp. 1546–1557, 2018. [217] H. Lin and N. W. Bergmann, “Iot privacy and security challenges for
[195] A. Alrawais, A. Alhothaily, C. Hu, and X. Cheng, “Fog computing smart home environments,” Information, vol. 7, no. 3, p. 44, 2016.
for the internet of things: Security and privacy issues,” IEEE Internet [218] “Internet of things related standards.” [Online]. Available:
Comput., vol. 21, no. 2, pp. 34–42, 2017. [Link]
[196] A. J. Jara, S. Varakliotis, A. F. Skarmeta, and P. Kirstein, “Extending [219] “Connecting devices where we live and work,” 2019. [Online].
the internet of things to the future internet through ipv6 support,” Available: [Link]
Mobile Inf. Syst., vol. 10, no. 1, pp. 3–17, 2014. [220] “Open connectivity foundation: Unlocking the massive opportunity in
[197] N. Kushalnagar, G. Montenegro, and C. Schumacher, “Ipv6 over low- the internet of things,” Accessed on September 28, 2019. [Online].
power wireless personal area networks (6lowpans): overview, assump- Available: [Link]
tions, problem statement, and goals,” The IETF Trust, Tech. Rep., 2007. [221] R. Stackowiak, A. Licht, V. Mantha, and L. Nagode, Big Data and the
[198] B. T. De Oliveira, L. B. Gabriel, and C. B. Margi, “Tinysdn: Enabling Internet of Things: enterprise information architecture for a new age.
multiple controllers for software-defined wireless sensor networks,” Apress, 2015.
IEEE Latin America Trans., vol. 13, no. 11, pp. 3690–3696, 2015. [222] M. Iglesias-Urkia, D. Casado-Mansilla, S. Mayer, and A. Urbieta,
[199] Q. Duan, Y. Yan, and A. V. Vasilakos, “A survey on service-oriented “Validation of a coap to iec 61850 mapping and benchmarking vs
network virtualization toward convergence of networking and cloud http-rest and ws-soap,” in Proc. 23rd IEEE Intl. Conf. Emerg. Technol.
computing,” IEEE Trans. Netw. Serv. Manag., vol. 9, no. 4, pp. 373– Factory Automation (ETFA), vol. 1, 2018, Funchal, Portugal, pp. 1015–
392, 2012. 1022.
[200] W. Rafique, M. Khan, N. Sarwar, and W. Dou, “A security framework [223] C.-S. Park and W.-S. Park, “A group-oriented dtls handshake for secure
to protect edge supported defined internet of things infrastructure,” in iot applications,” IEEE Trans. Automation Science Eng., no. 99, pp. 1–
15th EAI Int. Conf. Collaborative Comput.: Netw., Appl. Worksharing, 10, 2018.
2019, London, UK, pp. 71–88. [224] M. Collotta, G. Pau, T. Talty, and O. K. Tonguz, “Bluetooth 5: A
[201] W. Rafique, X. He, Z. Liu, Y. Sun, and W. Dou, “Cfadefense: A security concrete step forward toward the iot,” IEEE Commun. Mag., vol. 56,
solution to detect and mitigate crossfire attacks in software-defined iot- no. 7, pp. 125–131, 2018.
edge infrastructure,” in Proc. 21st IEEE Intl. Conf. High Performance [225] “P1903.2 - standard for service composition protocols
Comput. and Commun.; IEEE 17th Int. Conf. Smart City; IEEE 5th of next generation service overlay network (ngson),”
Int. Conf. Data Sci. Syst. (HPCC/SmartCity/DSS), 2019, Zhangjiajie, Accessed on September 28, 2019. [Online]. Available:
China, pp. 500–509. [Link]
[202] P. Garraghan, X. Ouyang, R. Yang, D. McKee, and J. Xu, “Straggler [226] “Standard for self-organizing management protocols of
root-cause and impact analysis for massive-scale virtualized cloud next generation service overlay network (ngson),” Ac-
datacenters,” IEEE Trans. Services Comput., vol. 12, no. 1, pp. 91– cessed on September 28, 2019. [Online]. Available:
104, 2019. [Link]
[203] Y. Liu, H.-N. Dai, H. Wang, M. Imran, X. Wang, and M. Shoaib, [227] “P1903.1-standard for content delivery protocols of next generation ser-
“Uav-enabled data acquisition scheme with directional wireless energy vice overlay network (ngson),” Accessed on September 28, 2019. [On-
transfer for internet of things,” Comput. Commun., In press, 2020. line]. Available: [Link]
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 42

[228] “P1915.1 - standard for software defined networking and network func- [251] R. Gracia-Tinedo, C. Cotes, E. Zamora-Gómez, G. Ortiz, A. Moreno-
tion virtualization security,” Accessed on September 28, 2019. [Online]. Martı́nez, M. Sánchez-Artigas, P. Garcı́a-López, R. Sánchez,
Available: [Link] A. Gómez, and A. Illana, “Giving wings to your data: A first experi-
[229] “P1916.1 - standard for software defined networking ence of personal cloud interoperability,” Future Gener. Comput. Syst.,
and network function virtualization performance,” Ac- vol. 78, pp. 1055–1070, 2018.
cessed on September 28, 2019. [Online]. Available: [252] A. Limaye and T. Adegbija, “A workload characterization of the spec
[Link] cpu2017 benchmark suite,” in Proc. IEEE Intl. Symp. Perform. Analysis
[230] “P1917.1 - standard for software defined networking and network func- Syst. Softw. (ISPASS), 2018, Belfast, Northern Ireland (UK)., pp. 149–
tion virtualization reliability,” Accessed on September 28, 2019. [On- 158.
line]. Available: [Link] [253] “European telecommunications standards institute industry
[231] “P1913.1 - standard for software defined quantum communication,” specifications group. mobile-edge computing—mec metrics
Accessed on September 28, 2019. [Online]. Available: best practice and guidelines,” Accessed on September 28,
[Link] 2019. [Online]. Available: [Link]
[232] “Ieee p1921.1 - software-defined networking bootstrapping IEG/001099/004/01.01.0160/[Link]
procedures,” Accessed on September 28, 2019. [Online]. Available: [254] “European telecommunications standards institute industry specifi-
[Link] cations group, mec proofs of concept,” Accessed on September
[233] “Ieee p1930.1 - sdn based middleware for control and management 28, 2019. [Online]. Available: [Link]
of networks,” Accessed on September 28, 2019. [Online]. Available: clusters/technologies/mobile-edge-computing/mec-poc
[Link] [255] “European telecommunications standards institute, poc 2 edge video
[234] “Ieee p802.1cf - recommended practice for network reference orchestration and video clip replay,” Accessed on September 28,
model and functional description of ieee 802 access 2019. [Online]. Available: [Link]
network,” Accessed on September 28, 2019. [Online]. Available: 2-Edge-Video-Orchestration-and-Video-Clip-Replay-via-MEC
[Link] [256] “European telecommunications standards institute, poc 7
[235] K. Gray and T. D. Nadeau, Network Function Virtualization, A. Iv- multi-service mec platform for advanced service de-
ernizzi, Ed. Morgan Kaufmann, Cambridge, MA, USA, 2016. livery,” Accessed on September 28, 2019. [On-
[236] J. Halpern, C. Pignataro et al., “Service function chaining (sfc) archi- line]. Available: [Link]
tecture,” in RFC 7665. Internet Eng. Task Force, Fremont, CA, USA, Service-MEC-Platform-for-Advanced-Service-Delivery
2015. [257] S. Deng, X. Gao, Z. Lu, Z. Li, and X. Gao, “Dos vulnerabilities and
[237] G. Lopez-Millan, R. Marin-Lopez, and F. Pereniguez-Garcia, “Towards mitigation strategies in software-defined networks,” J. Netw. Comput.
a standard sdn-based ipsec management framework,” Computer Stan- Appl., vol. 125, pp. 209–219, 2019.
dards Interfaces, vol. 66, p. 103357, 2019. [258] C. Li, Z. Qin, E. Novak, and Q. Li, “Securing sdn infrastructure of
[238] P. Bosshart, D. Daly, G. Gibb, M. Izzard, N. McKeown, J. Rexford, iot–fog networks from mitm attacks,” IEEE Internet Things J., vol. 4,
C. Schlesinger, D. Talayco, A. Vahdat, G. Varghese et al., “P4: Pro- no. 5, pp. 1156–1164, 2017.
gramming protocol-independent packet processors,” ACM SIGCOMM [259] R. McRee, “Microsoft threat modeling tool 2014: identify & mitigate,”
Comput. Commun. Review, vol. 44, no. 3, pp. 87–95, 2014. ISSA J., vol. 39, p. 42, 2014.
[239] H. Hromic, D. Le Phuoc, M. Serrano, A. Antonić, I. P. Žarko, C. Hayes, [260] Z. Khan, Z. Pervez, and A. G. Abbasi, “Towards a secure service
and S. Decker, “Real time analysis of sensor data for the internet of provisioning framework in a smart city environment,” Future Gener.
things by means of clustering and event processing,” in Proc. IEEE Comput. Syst., vol. 77, pp. 112 – 135, 2017.
Intl. Conf. Communica. (ICC), 2015, London UK, pp. 685–691.
[261] L. Liu, Z. Ma, and W. Meng, “Detection of multiple-mix-attack
[240] S. A. De Chaves, R. B. Uriarte, and C. B. Westphall, “Toward an
malicious nodes using perceptron-based trust in iot networks,” Future
architecture for monitoring private clouds,” IEEE Commun. Mag.,
Gener. Comput. Syst., vol. 101, pp. 865 – 879, 2019.
vol. 49, no. 12, pp. 130–137, 2011.
[262] R. A. Sowah, K. B. Ofori-Amanfo, G. A. Mills, and K. M. Koumadi,
[241] C. Meurisch, A. Seeliger, B. Schmidt, I. Schweizer, F. Kaup, and
“Detection and prevention of man-in-the-middle spoofing attacks in
M. Mühlhäuser, “Upgrading wireless home routers for enabling large-
manets using predictive techniques in artificial neural networks (ann),”
scale deployment of cloudlets,” in Proc. Springer Intl. Conf. Mobile
J. Comput, Netw. Commun., pp. 1–14, 2019.
Comput., Appl., Services (MOBICASE), 2015, Berlin, Germany,, pp.
12–29. [263] R. Lu, K. Heung, A. H. Lashkari, and A. A. Ghorbani, “A lightweight
[242] M. Shiraz and A. Gani, “A lightweight active service migration privacy-preserving data aggregation scheme for fog computing-
framework for computational offloading in mobile cloud computing,” enhanced iot,” IEEE Access, vol. 5, pp. 3302–3312, 2017.
J. Supercomput., vol. 68, no. 2, pp. 978–995, 2014. [264] A. Muthanna, A. A Ateya, A. Khakimov, I. Gudkova, A. Abuar-
[243] W. Li, Y. Zhao, S. Lu, and D. Chen, “Mechanisms and challenges on qoub, K. Samouylov, and A. Koucheryavy, “Secure and reliable iot
mobility-augmented service provisioning for mobile cloud computing,” networks using fog computing with software-defined networking and
IEEE Commun. Mag., vol. 53, no. 3, pp. 89–97, 2015. blockchain,” J. Sensor Actuator Netw., vol. 8, no. 1, p. 15, 2019.
[244] J. Povedano-Molina, J. M. Lopez-Vega, J. M. Lopez-Soler, A. Corradi, [265] M. Badra and R. Borghol, “Long-term integrity and non-repudiation
and L. Foschini, “Dargos: A highly adaptable and scalable monitoring protocol for multiple entities,” Sustainable Cities Society, vol. 40, pp.
architecture for multi-tenant clouds,” Future Gener. Comput. Syst., 189 – 193, 2018.
vol. 29, no. 8, pp. 2041–2056, 2013. [266] F. Wang, L. Xu, H. Wang, and Z. Chen, “Identity-based non-repudiable
[245] T. Taleb, K. Samdanis, B. Mada, H. Flinck, S. Dutta, and D. Sabella, dynamic provable data possession in cloud storage,” Comput. Electr.
“On multi-access edge computing: A survey of the emerging 5g Eng., vol. 69, pp. 521 – 533, 2018.
network edge cloud architecture and orchestration,” IEEE Commun. [267] J. Kang, R. Yu, X. Huang, M. Wu, S. Maharjan, S. Xie, and Y. Zhang,
Surveys Tuts., vol. 19, no. 3, pp. 1657–1681, 2017. “Blockchain for secure and efficient data sharing in vehicular edge
[246] “Openfog reference architecture for fog computing,” Architecture computing and networks,” IEEE Internet Things J., vol. 6, no. 3, pp.
Working Group, 2017. 4660–4670, 2019.
[247] “Octeon fusion-m integrated baseband processors,” Accessed on April [268] J. Cao, M. Xu, Q. Li, K. Sun, Y. Yang, and J. Zheng, “Disrupting sdn
03, 2020. [Online]. Available: [Link] via the data plane: A low-rate flow table overflow attack,” in Proc. Int.
pushes-iot-analytics-extreme-edge-mist-computing-2/ Conf. Security Privacy Commun. Syst., 2017, Niagara Falls, Canada,
[248] A. Yousefpour, C. Fung, T. Nguyen, K. Kadiyala, F. Jalali, A. Ni- pp. 356–376.
akanlahiji, J. Kong, and J. P. Jue, “All one needs to know about fog [269] D. Yin, L. Zhang, and K. Yang, “A ddos attack detection and mitigation
computing and related edge computing paradigms: A complete survey,” with software-defined internet of things framework,” IEEE Access,
J. Syst. Archit., 2019. vol. 6, pp. 24 694–24 705, 2018.
[249] M. Aazam, E.-N. Huh, and M. St-Hilaire, “Towards media inter-cloud [270] M. Ambrosin, M. Conti, F. De Gaspari, and R. Poovendran,
standardization–evaluating impact of cloud storage heterogeneity,” J. “Lineswitch: Tackling control plane saturation attacks in software-
Grid Comput., vol. 16, no. 3, pp. 425–443, 2018. defined networking,” IEEE/ACM Trans. Netw., vol. 25, no. 2, pp. 1206–
[250] T. Halabi and M. Bellaiche, “A broker-based framework for standard- 1219, 2017.
ization and management of cloud security-slas,” Comput. Security, [271] C. Kolias, G. Kambourakis, A. Stavrou, and J. Voas, “Ddos in the iot:
vol. 75, pp. 59–71, 2018. Mirai and other botnets,” Comput., vol. 50, no. 7, pp. 80–84, 2017.
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 43

[272] J. Zheng, Q. Li, G. Gu, J. Cao, D. K. Yau, and J. Wu, “Realtime ddos IEEE/ACM Int. Symp. Edge Comput. (SEC), 2016, Washington, DC,
defense using cots sdn switches via adaptive correlation analysis,” IEEE USA, pp. 51–63.
Trans. Inf. Forensics Security, vol. 13, no. 7, pp. 1838–1853, 2018. [295] J. Kang, R. Yu, X. Huang, and Y. Zhang, “Privacy-preserved
[273] K. Bhardwaj, J. C. Miranda, and A. Gavrilovska, “Towards iot-ddos pseudonym scheme for fog computing supported internet of vehicles,”
prevention using edge computing,” in Proc. {USENIX} Workshop on IEEE Trans. Intelligent Transport. Syst., vol. 19, no. 8, pp. 2627–2637,
Hot Topics in Edge Computing (HotEdge 18), 2018, Boston, MA. 2018.
[274] G. Han, H. Wang, J. Jiang, W. Zhang, and S. Chan, “Caslp: A confused [296] Q. Kong, R. Lu, M. Ma, and H. Bao, “A privacy-preserving sensory
arc-based source location privacy protection scheme in wsns for iot,” data sharing scheme in internet of vehicles,” Future Gener. Comput.
IEEE Commun. Mag., vol. 56, no. 9, pp. 42–47, 2018. Syst., vol. 92, pp. 644–655, 2019.
[275] L. Chen, S. Thombre, K. Järvinen, E. S. Lohan, A. Alén-Savikko, [297] G. Wang, J. He, X. Shi, J. Pan, and S. Shen, “Analyzing and evaluat-
H. Leppäkoski, M. Z. H. Bhuiyan, S. Bu-Pasha, G. N. Ferrara, ing efficient privacy-preserving localization for pervasive computing,”
S. Honkala, J. Lindqvist, L. Ruotsalainen, P. Korpisaari, and H. Kuus- IEEE Internet Things J., vol. 5, no. 4, pp. 2993–3007, 2018.
niemi, “Robustness, security and privacy in location-based services for [298] A. M. Alberti, G. D. Scarpioni, V. J. Magalhães, A. Cerqueira S.,
future iot: A survey,” IEEE Access, vol. 5, pp. 8956–8977, 2017. J. J. P. C. Rodrigues, and R. da Rosa Righi, “Advancing novagenesis
[276] J. Wang, R. Wen, J. Li, F. Yan, B. Zhao, and F. Yu, “Detecting and architecture towards future internet of things,” IEEE Internet Things
mitigating target link-flooding attacks using sdn,” IEEE Trans. Depend. J., vol. 6, no. 1, pp. 215–229, 2019.
Secure Comput., In press, 2018. [299] “Proofpoint uncovers internet of things (iot),”
[277] L. Xue, X. Ma, X. Luo, E. W. Chan, T. T. Miu, and G. Gu, Accessed on October 31, 2019. [Online].
“Linkscope: toward detecting target link flooding attacks,” IEEE Trans. Available: [Link]
Inf. Forensics Security, vol. 13, no. 10, pp. 2423–2438, 2018. internet-of-things-iot-cybera.
[278] L. Wang, Q. Li, Y. Jiang, X. Jia, and J. Wu, “Woodpecker: Detecting [300] “13th world wide infrastructure security re-
and mitigating link-flooding attacks via sdn,” Comput. Netw., vol. 147, port,” Accessed on November 1, 2019. [On-
pp. 1 – 13, 2018. line]. Available: [Link]
[279] X. Ma, J. Li, Y. Tang, B. An, and X. Guan, “Protecting internet infras- 087/images/13th Worldwide Infrastructure Security [Link]
tructure against link flooding attacks: A techno-economic perspective,” [301] S. Khandelwal, “Friday’s massive ddos attack came from just
Inf. Sci., vol. 479, pp. 486 – 502, 2019. 100,000 hacked iot devices,” Accessed on October 31, 2019.
[280] C. Liaskos and S. Ioannidis, “Network topology effects on the de- [Online]. Available: [Link]
tectability of crossfire attacks,” IEEE Trans. Inf. Forensics Security, [Link]
vol. 13, no. 7, pp. 1682–1695, 2018. [302] C. Frank, C. Nance, S. Jarocki, and W. E. Pauli, “Protecting iot from
[281] C. Baker, “Recent iot-based attacks: What is the impact on managed mirai botnets; iot device hardening,” J. Inf. Syst. Applied Research,
dns operators?” Accssed on November 02, 2019. [Online]. Available: vol. 11, no. 2, p. 33, 2018.
[Link] [303] “Smartcam products: Snh-p6410bn,” Accessed on October 15, 2019.
[Online]. Available: [Link]
[282] M. Lyu, D. Sherratt, I. Sivanathan, H. H. Gharakheili, A. Radford,
[304] “Samsung smartŒthings hub,” Accessed on October 22,
and V. Sivaraman, “Quantifying the reflective ddos attack capability of
2019. [Online]. Available: [Link]
household iot devices,” in Proc. 10th ACM Conf. Security Privacy in
smarthings/hubs-and-kits/samsung-smarthhings-hub/.
Wireless Mobile Netw., 2017, Montreal, QC, Canada, pp. 46–51.
[305] I. Stojmenovic, S. Wen, X. Huang, and H. Luan, “An overview of
[283] T. L. Seals, “Iot botnet bursts on the scene with
fog computing and its security issues,” Concurrency Comput.: Practice
massive ddos aŠattack.” Accessed on September 28, 2019.
Exp., vol. 28, no. 10, pp. 2991–3005, 2016.
[Online]. Available: [Link]
[306] “New ddos attack lfa: From may 11th netease attacked,”
iot-botnet-bursts-on-the-scene/
Accessed on October 30, 2019. [Online]. Available:
[284] R. U. Rasool, U. Ashraf, K. Ahmed, H. Wang, W. Rafique, and
[Link]/articles/network/[Link].
Z. Anwar, “Cyberpulse: A machine learning based link flooding attack
[307] A. Studer and A. Perrig, “The coremelt attack,” in Proc. European
mitigation system for defined networks,” IEEE Access, In press, 2019.
Symp. Research Comput. Security. Springer, 2009, Saint Malo, France,
[285] B. Yan, Y. Xu, and H. J. Chao, “Bigmac: Reactive network-wide policy pp. 37–52.
caching for sdn policy enforcement,” IEEE J. Sel. Areas Commun., [308] M. S. Kang, S. B. Lee, and V. D. Gligor, “The crossfire attack,” in
vol. 36, no. 12, pp. 2675–2687, 2018. Proc. IEEE Symp. Security Privacy, 2013, San Francisco, California.,
[286] C. Li, Y. Wu, X. Yuan, Z. Sun, W. Wang, X. Li, and L. Gong, pp. 127–141.
“Detection and defense of ddos attack–based on deep learning in [309] L. John, “Biggest ddos attack in history hammers
openflow-based sdn,” Int. J. Commun. Syst., vol. 31, no. 5, p. e3497, spamhaus,” Accessed on October 07, 2019. [Online]. Available:
2018. [Link]
[287] J. Wan, J. Li, M. Imran, and D. Li, “A blockchain-based solution [310] K. Beckmann and M. Thoss, “A wireless sensor network protocol
for enhancing security and privacy in smart factory,” IEEE Trans. for the omg data distribution service,” in Proc. 10th Int. Workshop
Industrial Informatics, vol. 15, no. 6, pp. 3652–3660, 2019. Intelligent Sol. Embedded Syst., 2012, pp. 45–50.
[288] M. A. Amanullah, R. A. A. Habeeb, F. H. Nasaruddin, A. Gani, [311] C. Anglano, R. Gaeta, and M. Grangetto, “Securing coding-based cloud
E. Ahmed, A. S. M. Nainar, N. M. Akim, and M. Imran, “Deep learning storage against pollution attacks,” IEEE Trans. Parallel Distrib. Syst.,
and big data technologies for iot security,” Comput. Commun., 2020. vol. 28, no. 5, pp. 1457–1469, 2017.
[289] D. Li, Q. Yang, W. Yu, D. An, X. Yang, and W. Zhao, “A strategy-proof [312] X. Chen, L. Jiao, W. Li, and X. Fu, “Efficient multi-user computation
privacy-preserving double auction mechanism for electrical vehicles offloading for mobile-edge cloud computing,” IEEE/ACM Trans. Netw.,
demand response in microgrids,” in Proc. 36th IEEE Intl. Performance vol. 24, no. 5, pp. 2795–2808, 2016.
Comput. Commun. Conf. (IPCCC), 2017, San Diego, CA, USA, pp. [313] B. Ramachandran, S. K. Srivastava, C. S. Edrington, and D. A. Cartes,
1–8. “An intelligent auction scheme for smart grid market using a hybrid
[290] F. Chen, T. Xiang, X. Fu, and W. Yu, “User differentiated verifiable immune algorithm,” IEEE Trans. Industrial Electronics, vol. 58, no. 10,
file search on the cloud,” IEEE Trans. Services Comput., vol. 11, no. 6, pp. 4603–4612, 2011.
pp. 948–961, 2018. [314] “Join the community accelerating analytics at the edge,” accessed on
[291] R. Gennaro, C. Gentry, and B. Parno, “Non-interactive verifiable September 25, 2019. [Online]. Available: [Link]
computing: Outsourcing computation to untrusted workers,” in Springer [315] K. Sasaki, N. Suzuki, S. Makido, and A. Nakao, “Vehicle control
Conf. Advances Cryptology - CRYPTO, T. Rabin, Ed., 2010, Santa system coordinated between cloud and mobile edge computing,” in
Barbara, CA, USA, pp. 465–482. Proc. 55th IEEE Annual Conf. Society Instrument Control Engineers
[292] B. Parno, J. Howell, C. Gentry, and M. Raykova, “Pinocchio: Nearly Japan (SICE), 2016, pp. 1122–1127.
practical verifiable computation,” in Proc. IEEE Symp. Security Pri- [316] D. Raychaudhuri, K. Nagaraja, and A. Venkataramani, “Mobilityfirst:
vacy, 2013, Berkeley, CA, USA, pp. 238–252. a robust and trustworthy mobility-centric architecture for the future
[293] J. Clemens, R. Pal, and P. Philip, “Extending trust and attestation to internet,” Mobile Computing and Commun. Review, vol. 16, pp. 2–13,
the edge,” in Proc. IEEE/ACM Int. Symp. Edge Comput. (SEC), 2016, 2012.
Washington, DC, USA, pp. 101–102. [317] S. Singh, P. K. Sharma, S. Y. Moon, and J. H. Park, “Advanced
[294] S. Echeverrı́a, D. Klinedinst, K. Williams, and G. A. Lewis, “Estab- lightweight encryption algorithms for iot devices: survey, challenges
lishing trusted identities in disconnected edge environments,” in Proc. and solutions,” J. Ambient Intelligence Humanized Comput., 2017.
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 44

[318] Z. Qin, Y. Yang, T. Yu, I. Khalil, X. Xiao, and K. Ren, “Heavy open issues,” Future Gener. Comput. Syst., vol. 100, pp. 325 – 343,
hitter estimation over set-valued data with local differential privacy,” in 2019.
ACM SIGSAC Conf. on Comput. and Commun. Security, 2016, Vienna, [341] S. Hakak, W. Z. Khan, G. A. Gilkar, M. Imran, and N. Guizani,
Austria, pp. 192–203. “Securing smart cities through blockchain technology: Architecture,
[319] T. W. Chim, S. Yiu, V. O. K. Li, L. C. K. Hui, and J. Zhong, requirements, and challenges,” IEEE Netw., vol. 34, no. 1, pp. 8–14,
“Prga: Privacy-preserving recording gateway-assisted authentication of 2020.
power usage information for smart grid,” IEEE Trans. Depend. Secure [342] Z. Zheng, S. Xie, H.-N. Dai, W. Chen, X. Chen, J. Weng, and M. Imran,
Comput., vol. 12, no. 1, pp. 85–97, 2015. “An overview on smart contracts: Challenges, advances and platforms,”
[320] S. Rathore, B. W. Kwon, and J. H. Park, “Blockseciotnet: Blockchain- Future Gener. Comput. Syst., vol. 105, pp. 475–491, 2020.
based decentralized security architecture for iot network,” J. Network [343] K. Sha, R. Errabelly, W. Wei, T. A. Yang, and Z. Wang, “Edgesec:
Comput. Appl., vol. 143, pp. 167 – 177, 2019. Design of an edge layer security service to enhance iot security,” in
[321] J. Pan, J. Wang, A. Hester, I. Alqerm, Y. Liu, and Y. Zhao, “Edgechain: Proc. 1st IEEE Int. Conf. Fog Edge Comput., 2017, Madrid, Spain, pp.
An edge-iot framework and prototype based on blockchain and smart 81–88.
contracts,” IEEE Internet Things J., vol. 6, no. 3, pp. 4719–4732, 2019. [344] R. H. Hsu, J. Lee, T. Q. S. Quek, and J. C. Chen, “Reconfigurable se-
[322] G. Shang, P. Zhe, B. Xiao, A. Hu, and K. Ren, “Flooddefender: curity: Edge-computing-based framework for iot,” IEEE Netw., vol. 32,
Protecting data and control plane resources under sdn-aimed dos no. 5, pp. 92–99, 2018.
attacks,” in Proc. IEEE Conf. Comput. Commun. (INFOCOM), 2017, [345] J. Ni, X. Lin, and X. S. Shen, “Toward edge-assisted internet of things:
Atlanta, GA, USA, pp. 1–9. From security and efficiency perspectives,” IEEE Netw., vol. 33, no. 2,
[323] “Multi-access edge computing (mec),” Accessed on November 01, pp. 50–57, 2019.
2019. [Online]. Available: [Link] [346] Q. Miao, W. Jing, and H. Song, “Differential privacy–based location
access-edge-computing privacy enhancing in edge computing,” Concurrency Comput.: Practice
[324] “Octeon fusion-m integrated baseband processors,” Ac- Exp., vol. 31, no. 8, p. e4735, 2019.
cessed on November 01, 2019. [Online]. Avail- [347] S. Bera, S. Misra, and A. V. Vasilakos, “Software-defined networking
able: [Link] for internet of things: A survey,” IEEE Internet Things J., vol. 4, no. 6,
processors/octeon-fusion-m/[Link] pp. 1994–2008, 2017.
[325] “Octeon fusion-m integrated baseband processors,”
Accessed on November 01, 2019. [Online].
Available: [Link]
management/iox/[Link]
[326] A. Ahmed and E. Ahmed, “A survey on mobile edge computing,” in
Proc. IEEE Intl. Conf. on Intelligent Syst. & Control, 2016, Coimbat-
ore, India, pp. 1–8.
[327] L. Zhang, D. Estrin, J. Burke, V. Jacobson, J. D. Thornton, D. K. Wajid Rafique is currently pursuing his Ph.D.
Smetters, B. Zhang, and G. Tsudik, “Named data networking (ndn) degree in computer science at Nanjing University,
project,” 2010. China. He is also conducting research in collab-
[328] X. Li, J. Wan, H.-N. Dai, M. Imran, M. Xia, and A. Celesti, “A hybrid oration with the University of Victoria, Australia.
computing solution and resource scheduling strategy for edge com- He received the BS (computer science) degree from
puting in smart manufacturing,” IEEE Trans. Industrial Informatics, Virtual University of Pakistan and the MS (software
vol. 15, no. 7, pp. 4225–4234, 2019. engineering) degree from National University of
[329] I. F. Akyildiz, P. Wang, and S. C. Lin, “Softair: A software defined Sciences and Technology, Pakistan. His research
networking architecture for 5g wireless systems,” Comput. Netw., works have been appeared in several prestigious
vol. 85, pp. 1–18, 2015. international journals and the top tier conferences.
[330] L. Tello-Oquendo, S.-C. Lin, I. F. Akyildiz, and V. Pla, “Software- His research interests include big data services,
defined architecture for qos-aware iot deployments in 5g systems,” Ad machine learning, mobile cloud computing, attacks-defense in virtualized
Hoc Netw., vol. 93, p. 101911, 2019. network infrastructure including IoT and SDN and network security.
[331] A. Li, X. Zong, S. Kandula, X. Yang, and M. Zhang, “Cloudprophet:
towards application performance prediction in cloud,” in Proc. ACM
SIGCOMM Comput. Commun. Review, vol. 41, no. 4. ACM, 2011,
pp. 426–427.
[332] L. Xu, Z. Wang, and W. Chen, “The study and evaluation of arm-based
mobile virtualization,” Int. J. Distrib. Sensor Netw., vol. 11, no. 7, p.
310308, 2015.
[333] M. Silva, A. Tavares, T. Gomes, and S. Pinto, “Chameliot: An agnostic Lianyong Qi received his PhD degree in Department
operating system framework for reconfigurable iot devices,” IEEE of Computer Science and Technology from Nanjing
Internet Things J., vol. 6, no. 1, pp. 1291–1292, 2019. University, China, in 2011. In 2010, he visited
[334] W. Rafique, X. Zhao, S. Yu, I. Yaqoob, M. Imran, and W. Dou, the Department of Information and Communication
“An application development framework for internet of things service Technology, Swinburne University of Technology,
orchestration,” IEEE Internet Things J., In press, 2020. Australia. Now, he is a full professor of the School
[335] W. Rafique, M. Khan, and W. Dou, “Maintainable solution devel- of Information Science and Engineering, Qufu Nor-
opment using collaboration between architecture and requirements in mal University, China. His research interests in-
heterogeneous iot paradigm (short paper),” in Proc. 15th EAI Int. Conf. clude big data and recommender systems. He has
Collaborative Comput.: Netw., Appl. Worksharing, 2019, pp. 489–508. published over 70 research papers (first author or
[336] M. Bartoletti, B. Bellomy, and L. Pompianu, “A journey into bitcoin corresponding author) in international journals (e.g.,
metadata,” J. Grid Comput., pp. 1–20, 2019. IEEE JSAC, IEEE TCC, IEEE TBD, IEEE TII, IEEE T-ITS, IEEE TCSS,
[337] P. K. Sharma, M. Chen, and J. H. Park, “A software defined fog node IEEE TNSE, IEEE TETCI, IS, JCSS, IoT-J, WWW-J, SPE, FGCS, JNCA,
based distributed blockchain cloud architecture for iot,” IEEE Access, MONET, COMCOM, CCPE) and international conferences (e.g., ICWS,
vol. 6, pp. 115–124, 2018. ICSOC, CSCWD, HPCC, TrustCom, CollaborateCom), including 2 Best
[338] P. K. Sharma, S. Rathore, Y. Jeong, and J. H. Park, “Softedgenet: Paper Awards, 3 ESI Highly-cited Papers and 1 ESI Hot Paper. He has
Sdn based energy-efficient distributed network architecture for edge served several international conferences including CPSCom’2018-2020, EAI
computing,” IEEE Commun. Mag., vol. 56, no. 12, pp. 104–111, 2018. Cloudcomp’2019-2020, ML4CS’2020, IIoTBDSC’2020 as various chairs. He
[339] R. Yang, F. R. Yu, P. Si, Z. Yang, and Y. Zhang, “Integrated blockchain also serves as the guest editor of COMCOM, MONET, DCN, JOEUC,
and edge computing systems: A survey, some research issues and JCC, JWCN, SCN, IJDSN, BDMA. He has won the best paper awards of
challenges,” IEEE Commun. Surveys Tuts., vol. 21, no. 2, pp. 1508– international conferences SpaCCS’2017 and CSS’2017.
1532, 2019.
[340] S. Moin, A. Karim, Z. Safdar, K. Safdar, E. Ahmed, and M. Imran,
“Securing iots in distributed blockchain: Analysis, requirements and
IEEE COMMUNICATIONS SURVEYS & TUTORIALS 45

Ibrar Yaqoob is a research professor with the


Department of Computer Science and Engineer-
ing, Kyung Hee University, South Korea, where
he completed his postdoctoral fellowship under the
prestigious grant of Brain Korea 21st Century Plus.
Prior to that, he received his Ph.D. (Computer Sci-
ence) from the University of Malaya, Malaysia, in
2017. He worked as a researcher and developer at
the Centre for Mobile Cloud Computing Research
(C4MCCR), University of Malaya. His numerous
research articles are very famous and among the
most downloaded in top journals. He has reviewed over 200 times for the
top ISI- Indexed journals and conferences. He has been listed among top
researchers by Thomson Reuters (Web of Science) based on the number of
citations earned in last three years in six categories of Computer Science.
He is currently serving/served as a guest/associate editor in various Journals.
He has been involved in a number of conferences and workshops in various
capacities. His research interests include big data, edge computing, mobile
cloud computing, the Internet of Things, and computer networks.

Muhammad Imran is working as an Associate


Professor in the College of Applied Computer Sci-
ence, King Saud University (KSU). His research
interests include mobile and wireless networks, In-
ternet of Things, cloud/edge computing, big data
analytics, and information security. He has published
a number of research papers in refereed international
conferences and journals. His research is financially
supported by several grants. He served as an Editor
in Chief for EAI Transactions on Pervasive Health
and Technology. He also serves as an associate editor
of many international journals including IEEE Access, IEEE Communications
Magazine, and Future Generation Computer Systems. He has been involved in
more than seventy-five conferences and workshops in various capacities, such
as a chair, co-chair and technical program committee member. These include
IEEE ICC, Globecom, AINA, LCN, IWCMC, IFIP WWIC and BWCCA. He
has received a number of national and international awards.

Raihan Ur Rasool is a Fulbright Alumnus of


the University of Chicago, USA. He is currently
affiliated with Victoria University, Melbourne. His
research interests include large-scale systems, secu-
rity and computer architecture. His research work,
comprising over 60 articles, is published in various
international conferences and journals.

Wanchun Dou is a full professor at the State Key


Laboratory for Novel Software Technology, Nanjing
University. He received the Ph.D. degree in 2001. To
date, he has chaired four National Natural Science
Foundation of China projects and published more
than 100 articles in international journals and confer-
ences. His research interests include big data, cloud
computing, and service computing..

View publication stats

Common questions

Powered by AI

The distributed nature of SDIoT-Edge presents specific security challenges such as increased risk for spoofing, tampering, and DDoS attacks due to multiple device interactions and lack of standardization. Mitigation strategies include developing autonomous security solutions, employing SDN programmability for network-level security enhancements, and ensuring robust data encryption and authentication protocols .

Virtualization in SDIoT-Edge paradigms enables efficient service delivery by providing scalable and flexible resource management. It allows for dynamic workload handling, integration across platforms, and improved compatibility. This flexibility is crucial in managing latency-sensitive IoT services and addressing resource constraints at edge nodes .

Constrained resources in IoT devices significantly impact the implementation of comprehensive security measures, as limited processing power and energy make it challenging to deploy intensive security solutions. This necessitates lightweight security protocols and strategic resource allocation through SDN, potentially risking security efficacy amidst sophisticated threats .

SDN plays a crucial role in enhancing security within IoT and edge computing by allowing network-level security solutions through its programmability feature. This facilitates the development of customized traffic forwarding and supports additional hardware techniques for network surveillance. Security applications can be deployed at the SDN application plane to address unique threats in IoT-Edge environments .

Implementing SDIoT with edge computing faces scalability issues due to increased network size, which requires virtualization of services as separate applications to handle data effectively. Security is challenged by the distributed nature of edge systems and limited resources, making them vulnerable to attacks such as DDoS, spoofing, and tampering .

SDN can optimize resource allocation in IoT by enabling programmable traffic management, which facilitates dynamic resource distribution and efficient handling of heterogeneous workloads. This is achieved through virtualization and the flexibility to manage data plane devices and flow management, addressing the diverse requirements of IoT .

The distributed control paradigm in SDIoT-Edge improves frameworks by addressing the central bottleneck of control channels, enhancing scalability and resilience. However, it introduces challenges like communication delays, controller-state synchronization, and security issues due to increased complexity and resource constraints .

A three-tier architecture in SDIoT-Edge infrastructures facilitates better coordination and orchestration than the traditional client-server models. This architecture provides a dedicated network layer for communication among edge resources, thus optimizing data flow, improving connectivity, and supporting novel service requirements such as security and resource management .

Developing data classification strategies is significant in managing IoT big data as it helps decide which data to process locally at the edge and which to send to the cloud, optimizing resource use, reducing latency, and managing bandwidth more effectively. This approach is crucial due to the vast amount of data generated by IoT devices .

Edge analytics enhances efficiency by filtering data at the device's edge and reducing unnecessary data transfer to the central cloud. This minimizes network strain and better manages resources like storage, energy, and computational power .

You might also like