arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.27858cs.CR

面向6G医疗物联网的边缘自适应安全技术

Adaptive Security at the Edge for 6G-Enabled Healthcare IoT

Ijaz Ahmad, Ijaz Ahmad, Erkki Harjula

AI总结:

该研究针对6G医疗物联网的边缘安全问题,提出NANOEDGEGUARD内核层闭环控制器,实验显示其可降低99百分位警报RTT并减少过量突发流量,提升医疗物联网弹性。

AI中文摘要:

医疗物联网服务日益依赖边缘网关传输常规遥测数据和罕见但时间敏感的警报,即使短暂的流量突发也会增大最坏情况下的延迟并干扰紧急消息。我们提出NANOEDGEGUARD,一种内核层闭环控制器,可在边缘观测每个源的流量强度,并利用内核流量控制钩子执行可审计的多层速率策略。与静态防火墙规则或用户空间控制循环不同,该设计通过滞环优先实现快速执行和明确恢复,并记录策略转换以确保可审计性。在托管MQTT代理的树莓派网关和生成生命体征、警报及定时突发的两个ESP32端点上进行的实验表明,与用户空间防火墙基线相比,自适应内核层速率控制可将第99百分位的警报往返时间(RTT)降低13.3%,同时维持无强制时的RTT,且与无强制情况相比可减少46%的过量接纳突发流量。这些早期结果表明,在网关处进行自适应、可审计的强制可提升医疗物联网的弹性,未来可扩展至边缘智能中的按需策略部署。

英文摘要:

Healthcare IoT services increasingly rely on edge gateways to relay routine telemetry and deliver rare but timecritical alarms. Even short traffic bursts can inflate worstcase delay and interfere with urgent messages. We present NANOEDGEGUARD, a kernel-plane closed-loop controller that observes per-source traffic intensity at the edge and enforces an auditable, multi-tier rate policy using in-kernel traffic-control hooks. Unlike static firewall rules or user-space control loops, our design prioritizes fast actuation and explicit recovery through hysteresis, and it records policy transitions for auditability. Using a Raspberry Pi gateway hosting an MQTT broker and two ESP32 endpoints generating vitals, alarms, and a timed burst, we show that adaptive kernel-plane rate control reduces the 99th-percentile alarm RTT by 13.3% compared to a user-space firewall baseline while maintaining no-enforcement-level RTT, and it reduces excess admitted burst traffic by 46% compared to no enforcement. These early results indicate that adaptive, auditable enforcement at the gateway can improve resilience for healthcare IoT, and it can be extended toward on-demand policy deployment in future edge intelligence.

补充信息

↑