Paying for Trust at the Edge: Secure, Lightweight, Deadline-Aware Named Data Networking for Edge-Cloud Compute Orchestration
Article Information
Abstract
Edge nodes are among the most resource-constrained components of computing infrastructure, yet security verification competes directly with application execution for limited compute resources. In Named Data Networking (NDN), each retrieved object carries a producer signature whose verification consumes edge CPU cycles, while existing cryptographic and orchestration studies rarely quantify its impact on service reliability. This paper develops SLED, a secure edge--cloud framework over NDN that incorporates a Security Verification Engine (SVE) into the edge compute budget, explicitly coupling verification occupancy with named-function execution. SLED combines DACSIR, which prices verification into deadline-aware cache-assisted routing; LSAV, which amortises one Ed25519 signature over a Merkle tree covering $B$ Data packets and re-validates cached objects using symmetric tokens within a trust domain; and DREP, which dynamically provisions and reclaims cloud burst workers according to edge utilisation. Cryptographic costs measured on a host CPU were scaled to individual tiers using modelling factors and incorporated into a discrete-event simulator. At 6,000 Interests per second, SLED achieves a deadline satisfaction ratio of 0.978, compared with 0.952 for the same datapath using per-packet RSA-2048 and 0.600 for vanilla NDN, while reducing mean per-request verification latency from 7,150.5 to 258.4~$\mu$s and recovering 94.5% of the insecure upper-bound utility. Replacing RSA-2048 with Ed25519 alone yields little improvement, indicating that reliability is more sensitive to verification frequency than to the cryptographic primitive in the evaluated configurations. These results demonstrate that verification should be treated as a first-class resource cost and jointly optimised with workload placement and deadline requirements, while noting that system-level results are simulation-based and per-tier scaling factors are estimated.
Graphical Abstract
Keywords
Data Availability Statement
Funding
Conflicts of Interest
AI Use Statement
Ethical Approval and Consent to Participate
References
- Shi, W., Cao, J., Zhang, Q., Li, Y., & Xu, L. (2016). Edge computing: Vision and challenges. IEEE Internet of Things Journal, 3(5), 637-646.
[CrossRef] [Google Scholar] - Xiao, Y., Jia, Y., Liu, C., Cheng, X., Yu, J., & Lv, W. (2019). Edge computing security: State of the art and challenges. Proceedings of the IEEE, 107(8), 1608-1631.
[CrossRef] [Google Scholar] - Roman, R., Lopez, J., & Mambo, M. (2018). Mobile edge computing, Fog et al.: A survey and analysis of security threats and challenges. Future Generation Computer Systems, 78, 680-698.
[CrossRef] [Google Scholar] - Jacobson, V., Smetters, D. K., Thornton, J. D., Plass, M. F., Briggs, N. H., & Braynard, R. L. (2009, December). Networking named content. In Proceedings of the 5th international conference on Emerging networking experiments and technologies (pp. 1-12).
[CrossRef] [Google Scholar] - Zhang, L., Afanasyev, A., Burke, J., Jacobson, V., Claffy, K., Crowley, P., ... & Zhang, B. (2014). Named data networking. ACM SIGCOMM Computer Communication Review, 44(3), 66-73.
[CrossRef] [Google Scholar] - Yi, C., Afanasyev, A., Moiseenko, I., Wang, L., Zhang, B., & Zhang, L. (2013). A case for stateful forwarding plane. Computer Communications, 36(7), 779-791.
[CrossRef] [Google Scholar] - Sifalakis, M., Kohler, B., Scherb, C., & Tschudin, C. (2014). An information centric network for computing the distribution of computations. In Proceedings of the 1st ACM Conference on Information-Centric Networking (ICN) (pp. 137-146).
[CrossRef] [Google Scholar] - Krol, M., & Psaras, I. (2017, September). NFaaS: Named function as a service. In Proceedings of the 4th ACM Conference on Information-Centric Networking (pp. 134-144).
[CrossRef] [Google Scholar] - Krol, M., Habak, K., Oran, D., Kutscher, D., & Psaras, I. (2018, September). Rice: Remote method invocation in icn. In Proceedings of the 5th ACM Conference on Information-Centric Networking (pp. 1-11).
[CrossRef] [Google Scholar] - Krol, M., Mastorakis, S., Oran, D., & Kutscher, D. (2019, September). Compute first networking: Distributed computing meets ICN. In Proceedings of the 6th ACM Conference on Information-Centric Networking (pp. 67-77).
[CrossRef] [Google Scholar] - Scherb, C., Grewe, D., Wagner, M., & Tschudin, C. (2018, January). Resolution strategies for networking the IoT at the edge via named functions. In 2018 15th IEEE Annual Consumer Communications & Networking Conference (CCNC) (pp. 1-6). IEEE.
[CrossRef] [Google Scholar] - Amadeo, M., Ruggeri, G., Campolo, C., Molinaro, A., Loscri, V., & Calafate, C. T. (2019). Fog computing in IoT smart environments via named data networking: A study on service orchestration mechanisms. Future internet, 11(11), 222.
[CrossRef] [Google Scholar] - Kondo, D., Ansquer, T., Tanigawa, Y., & Tode, H. (2024). Resource breadcrumbs: Discovering edge computing resources over Named Data Networking. IEEE Transactions on Network and Service Management, 21(3), 3305-3316.
[CrossRef] [Google Scholar] - Zhang, Z., Yu, Y., Zhang, H., Newberry, E., Mastorakis, S., Li, Y., ... & Zhang, L. (2018). An overview of security support in named data networking. IEEE Communications Magazine, 56(11), 62-68.
[CrossRef] [Google Scholar] - Yu, Y., Afanasyev, A., Clark, D., Claffy, K. C., Jacobson, V., & Zhang, L. (2015, September). Schematizing trust in named data networking. In proceedings of the 2nd ACM Conference on Information-Centric Networking (pp. 177-186).
[CrossRef] [Google Scholar] - Ahlgren, B., Dannewitz, C., Imbrenda, C., Kutscher, D., & Ohlman, B. (2012). A survey of information-centric networking. IEEE Communications Magazine, 50(7), 26-36.
[CrossRef] [Google Scholar] - Xylomenos, G., Ververidis, C. N., Siris, V. A., Fotiou, N., Tsilopoulos, C., Vasilakos, X., ... & Polyzos, G. C. (2013). A survey of information-centric networking research. IEEE communications surveys & tutorials, 16(2), 1024-1049.
[CrossRef] [Google Scholar] - Zhang, M., Luo, H., & Zhang, H. (2015). A survey of caching mechanisms in information-centric networking. IEEE Communications Surveys & Tutorials, 17(3), 1473-1499.
[CrossRef] [Google Scholar] - Javaheri, A., Bohlooli, A., & Jamshidi, K. (2024). Enhancing computation reuse efficiency in ICN-based edge computing by modifying content store table structure. Computing, 106(9), 2949-2969.
[CrossRef] [Google Scholar] - Mao, Y., You, C., Zhang, J., Huang, K., & Letaief, K. B. (2017). A survey on mobile edge computing: The communication perspective. IEEE communications surveys & tutorials, 19(4), 2322-2358.
[CrossRef] [Google Scholar] - Mach, P., & Becvar, Z. (2017). Mobile edge computing: A survey on architecture and computation offloading. IEEE communications surveys & tutorials, 19(3), 1628-1656.
[CrossRef] [Google Scholar] - Ndikumana, A., Tran, N. H., Ho, T. M., Han, Z., Saad, W., Niyato, D., & Hong, C. S. (2019). Joint communication, computation, caching, and control in big data multi-access edge computing. IEEE Transactions on mobile Computing, 19(6), 1359-1374.
[CrossRef] [Google Scholar] - Wang, C., Liang, C., Yu, F. R., Chen, Q., & Tang, L. (2017). Computation offloading and resource allocation in wireless cellular networks with mobile edge computing. IEEE Transactions on Wireless Communications, 16(8), 4924-4938.
[CrossRef] [Google Scholar] - Ren, J., Yu, G., He, Y., & Li, G. Y. (2019). Collaborative cloud and edge computing for latency minimization. IEEE Transactions on Vehicular Technology, 68(5), 5031-5044.
[CrossRef] [Google Scholar] - Liu, J. & Zhang, Q. (2018). Offloading schemes in mobile edge computing for ultra-reliable low latency communications. IEEE Access, 6, 12825-12837.
[CrossRef] [Google Scholar] - Tourani, R., Misra, S., Mick, T., & Panwar, G. (2018). Security, privacy, and access control in information-centric networking: A survey. IEEE Communications Surveys & Tutorials, 20(1), 566-600.
[CrossRef] [Google Scholar] - Nour, B., Khelifi, H., Hussain, R., Mastorakis, S., & Moungla, H. (2021). Access control mechanisms in named data networks: A comprehensive survey. Acm computing Surveys (cSuR), 54(3), 1-35.
[CrossRef] [Google Scholar] - Gasti, P., Tsudik, G., Uzun, E., & Zhang, L. (2013, July). DoS and DDoS in named data networking. In 2013 22nd International Conference on Computer Communication and Networks (ICCCN) (pp. 1-7). IEEE.
[CrossRef] [Google Scholar] - Compagno, A., Conti, M., Gasti, P., & Tsudik, G. (2013, October). Poseidon: Mitigating interest flooding DDoS attacks in named data networking. In 38th annual IEEE conference on local computer networks (pp. 630-638). IEEE.
[CrossRef] [Google Scholar] - Kumar, N., Singh, A. K., Aleem, A., & Srivastava, S. (2019). Security attacks in named data networking: A review and research directions. Journal of Computer Science and Technology, 34(6), 1319-1350.
[CrossRef] [Google Scholar] - Bernstein, D. J., Duif, N., Lange, T., Schwabe, P., & Yang, B.-Y. (2012). High-speed high-security signatures. Journal of Cryptographic Engineering, 2(2), 77-89.
[CrossRef] [Google Scholar] - Gündoğan, C., Amsüss, C., Schmidt, T. C., & Wählisch, M. (2020, June). IoT content object security with OSCORE and NDN: A first experimental comparison. In 2020 IFIP Networking Conference (Networking) (pp. 19-27). IEEE.
[Google Scholar] - Wong, C. K., & Lam, S. S. (1998, October). Digital signatures for flows and multicasts. In Proceedings Sixth International Conference on Network Protocols (Cat. No. 98TB100256) (pp. 198-209). IEEE.
[CrossRef] [Google Scholar] - Xu, L., Yuan, X., Zhou, Z., Wang, C., & Xu, C. (2021). Towards efficient cryptographic data validation service in edge computing. IEEE Transactions on Services Computing, 16(1), 656-669.
[CrossRef] [Google Scholar] - Psaras, I., Chai, W. K., & Pavlou, G. (2012, August). Probabilistic in-network caching for information-centric networks. In Proceedings of the second edition of the ICN workshop on Information-centric networking (pp. 55-60).
[CrossRef] [Google Scholar] - Breslau, L., Cao, P., Fan, L., Phillips, G., & Shenker, S. (1999, March). Web caching and Zipf-like distributions: Evidence and implications. In IEEE INFOCOM'99. Conference on Computer Communications. Proceedings. Eighteenth Annual Joint Conference of the IEEE Computer and Communications Societies. The Future is Now (Cat. No. 99CH36320) (Vol. 1, pp. 126-134). IEEE.
[CrossRef] [Google Scholar] - Baccelli, E., Mehlis, C., Hahm, O., Schmidt, T. C., & Wahlisch, M. (2014, September). Information centric networking in the IoT: Experiments with NDN in the wild. In Proceedings of the 1st ACM conference on information-centric networking (pp. 77-86).
[CrossRef] [Google Scholar] - Amadeo, M., Campolo, C., Quevedo, J., Corujo, D., Molinaro, A., Iera, A., ... & Vasilakos, A. V. (2016). Information-centric networking for the internet of things: challenges and opportunities. IEEE Network, 30(2), 92-100.
[CrossRef] [Google Scholar] - Merkle, R. C. (1987, August). A digital signature based on a conventional encryption function. In Conference on the theory and application of cryptographic techniques (pp. 369-378). Berlin, Heidelberg: Springer Berlin Heidelberg.
[CrossRef] [Google Scholar] - Laurie, B., Messeri, E., & Stradling, R. (2021). Certificate transparency version 2.0. RFC 9162, Internet Engineering Task Force.
[CrossRef] [Google Scholar] - National Institute of Standards and Technology (2024). Stateless hash-based digital signature standard. FIPS 205, NIST.
[CrossRef] [Google Scholar] - Mastorakis, S., Mtibaa, A., Lee, J., & Misra, S. (2020). Icedge: When edge computing meets information-centric networking. IEEE Internet of Things Journal, 7(5), 4203-4217.
[CrossRef] [Google Scholar] - Alghamdi, A., & Keshta, I. (2026). Blockchain consensus mechanisms and enhancement techniques for federated learning-based intrusion detection systems in IoT smart homes. Journal of Reliable and Secure Computing, 2(1), 1-26.
[CrossRef] [Google Scholar] - Ranaweera, P., Jurcut, A. D., & Liyanage, M. (2021). Survey on multi-access edge computing security and privacy. IEEE Communications Surveys & Tutorials, 23(2), 1078-1124.
[CrossRef] [Google Scholar] - Chen, X., Jiao, L., Li, W., & Fu, X. (2016). Efficient multi-user computation offloading for mobile-edge cloud computing. IEEE/ACM Transactions on Networking, 24(5), 2795-2808.
[CrossRef] [Google Scholar] - Kleinrock, L. (1975). Queueing Systems, Volume 1: Theory. Wiley-Interscience, New York, NY, USA. https://dl.acm.org/doi/abs/10.5555/1096491
[Google Scholar] - Moriarty, K., Kaliski, B., Jonsson, J., & Rusch, A. (2016). PKCS \#1: RSA cryptography specifications version 2.2. RFC 8017, Internet Engineering Task Force.
[CrossRef] [Google Scholar] - Josefsson, S. & Liusvaara, I. (2017). Edwards-curve digital signature algorithm (EdDSA). RFC 8032, Internet Engineering Task Force.
[CrossRef] [Google Scholar] - Krawczyk, H., Bellare, M., & Canetti, R. (1997). HMAC: Keyed-hashing for message authentication. RFC 2104, Internet Engineering Task Force.
[CrossRef] [Google Scholar] - Rescorla, E. (2018). The Transport Layer Security (TLS) protocol version 1.3. RFC 8446, Internet Engineering Task Force.
[CrossRef] [Google Scholar] - National Institute of Standards and Technology (2024). Module-lattice-based digital signature standard. FIPS 204, NIST.
[CrossRef] [Google Scholar] - Bernstein, D. J. & Lange, T. (2017). Post-quantum cryptography. Nature, 549(7671), 188-194.
[CrossRef] [Google Scholar] - Khelifi, H., Luo, S., Nour, B., Moungla, H., Faheem, Y., Hussain, R., & Ksentini, A. (2020). Named data networking in vehicular ad hoc networks: State-of-the-art and challenges. IEEE Communications Surveys & Tutorials, 22(1), 320-351.
[CrossRef] [Google Scholar]
Cite This Article
TY - JOUR AU - Alam, Mehbub PY - 2026 DA - 2026/09/21 TI - Paying for Trust at the Edge: Secure, Lightweight, Deadline-Aware Named Data Networking for Edge-Cloud Compute Orchestration JO - Journal of Reliable and Secure Computing T2 - Journal of Reliable and Secure Computing JF - Journal of Reliable and Secure Computing VL - 2 IS - 3 SP - 212 EP - 232 DO - 10.62762/JRSC.2026.615829 UR - https://www.icck.org/article/abs/JRSC.2026.615829 KW - secure edge computing KW - trustworthy edge infrastructure KW - cryptographic verification overhead KW - resource-efficient security KW - named data networking KW - deadline-aware service reliability KW - secure edge-cloud orchestration KW - signature amortisation AB - Edge nodes are among the most resource-constrained components of computing infrastructure, yet security verification competes directly with application execution for limited compute resources. In Named Data Networking (NDN), each retrieved object carries a producer signature whose verification consumes edge CPU cycles, while existing cryptographic and orchestration studies rarely quantify its impact on service reliability. This paper develops SLED, a secure edge--cloud framework over NDN that incorporates a Security Verification Engine (SVE) into the edge compute budget, explicitly coupling verification occupancy with named-function execution. SLED combines DACSIR, which prices verification into deadline-aware cache-assisted routing; LSAV, which amortises one Ed25519 signature over a Merkle tree covering $B$ Data packets and re-validates cached objects using symmetric tokens within a trust domain; and DREP, which dynamically provisions and reclaims cloud burst workers according to edge utilisation. Cryptographic costs measured on a host CPU were scaled to individual tiers using modelling factors and incorporated into a discrete-event simulator. At 6,000 Interests per second, SLED achieves a deadline satisfaction ratio of 0.978, compared with 0.952 for the same datapath using per-packet RSA-2048 and 0.600 for vanilla NDN, while reducing mean per-request verification latency from 7,150.5 to 258.4~$\mu$s and recovering 94.5% of the insecure upper-bound utility. Replacing RSA-2048 with Ed25519 alone yields little improvement, indicating that reliability is more sensitive to verification frequency than to the cryptographic primitive in the evaluated configurations. These results demonstrate that verification should be treated as a first-class resource cost and jointly optimised with workload placement and deadline requirements, while noting that system-level results are simulation-based and per-tier scaling factors are estimated. SN - 3070-6424 PB - Institute of Central Computation and Knowledge LA - English ER -
@article{Alam2026Paying,
author = {Mehbub Alam},
title = {Paying for Trust at the Edge: Secure, Lightweight, Deadline-Aware Named Data Networking for Edge-Cloud Compute Orchestration},
journal = {Journal of Reliable and Secure Computing},
year = {2026},
volume = {2},
number = {3},
pages = {212-232},
doi = {10.62762/JRSC.2026.615829},
url = {https://www.icck.org/article/abs/JRSC.2026.615829},
abstract = {Edge nodes are among the most resource-constrained components of computing infrastructure, yet security verification competes directly with application execution for limited compute resources. In Named Data Networking (NDN), each retrieved object carries a producer signature whose verification consumes edge CPU cycles, while existing cryptographic and orchestration studies rarely quantify its impact on service reliability. This paper develops SLED, a secure edge--cloud framework over NDN that incorporates a Security Verification Engine (SVE) into the edge compute budget, explicitly coupling verification occupancy with named-function execution. SLED combines DACSIR, which prices verification into deadline-aware cache-assisted routing; LSAV, which amortises one Ed25519 signature over a Merkle tree covering \$B\$ Data packets and re-validates cached objects using symmetric tokens within a trust domain; and DREP, which dynamically provisions and reclaims cloud burst workers according to edge utilisation. Cryptographic costs measured on a host CPU were scaled to individual tiers using modelling factors and incorporated into a discrete-event simulator. At 6,000 Interests per second, SLED achieves a deadline satisfaction ratio of 0.978, compared with 0.952 for the same datapath using per-packet RSA-2048 and 0.600 for vanilla NDN, while reducing mean per-request verification latency from 7,150.5 to 258.4~\$\mu\$s and recovering 94.5\% of the insecure upper-bound utility. Replacing RSA-2048 with Ed25519 alone yields little improvement, indicating that reliability is more sensitive to verification frequency than to the cryptographic primitive in the evaluated configurations. These results demonstrate that verification should be treated as a first-class resource cost and jointly optimised with workload placement and deadline requirements, while noting that system-level results are simulation-based and per-tier scaling factors are estimated.},
keywords = {secure edge computing, trustworthy edge infrastructure, cryptographic verification overhead, resource-efficient security, named data networking, deadline-aware service reliability, secure edge-cloud orchestration, signature amortisation},
issn = {3070-6424},
publisher = {Institute of Central Computation and Knowledge}
}
Article Metrics
Publisher's Note
ICCK stays neutral with regard to jurisdictional claims in published maps and institutional affiliations.
Rights and Permissions
Copyright © 2026 by the Author(s). Published by Institute of Central Computation and Knowledge. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/), which permits use, sharing, adaptation, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if changes were made.
Portico