Increasing rate of progress in hardware and artificial intelligence (AI) solutions is enabling a range of software systems to be deployed closer to their users, increasing application of edge software system paradigms. Edge systems support scenarios in which computation is placed closer to where data is generated and needed, and provide benefits such as reduced latency, bandwidth optimization, and higher resiliency and availability. Users who operate in highly-uncertain and resource-constrained environments, such as first responders, law enforcement, and soldiers, can greatly benefit from edge systems to support timelier decision making. Unfortunately, understanding how different architecture approaches for edge systems impact priority quality concerns is largely neglected by industry and research, yet crucial for national and local safety, optimal resource utilization, and timely decision making. Much of industry is focused on the hardware and networking aspects of edge systems, with very little attention to the software that enables edge capabilities. This paper presents our work to fill this gap, defining a reference architecture for edge systems in highly-uncertain environments, and showing examples of how it has been implemented in practice.
Internet of Things (IoT) security remains a challenge due to device vulnerabilities and untrusted supply chains, often limiting the benefits that organizations can obtain from integrating novel IoT devices to support business goals and enhance user experience. To that effect we developed KalKi: an IoT security platform that uses software-defined networking (SDN) concepts and constructs to create per-device defenses that enable integration of untrusted, off-the-shelf IoT devices. However, KalKi had limitations related to performance, scalability, and usability. This paper presents KalKi++, an evolution of KalKi that improves the performance, scalability and usability of the platform by orders of magnitude, with the added benefit of now being able to run on resource-limited hardware and support a larger number of use cases. We present the new architecture, enhanced threat model, and evaluation results for the new platform.
Commercial IoT devices are increasingly being integrated into software systems. However, given the also increasing number of IoT vulnerability reports, there is a pressing need to enable organizations to achieve such integration with high assurance, especially for systems with high security and safety requirements. We present KalKi, a software-defined IoT security platform that moves security enforcement to the network to enable safe integration of IoT devices, even if the devices are not fully trusted or configurable. KalKi leverages software-defined networking (SDN) concepts and constructs, combined with a rich policy model that specifies both cyber and kinetic attacks, to create a safe, highly-dynamic and extensible IoT integration platform. Our experiments demonstrate high performance, scalability and resilience, even in the presence of a powerful attacker.
Personnel operating in tactical environments heavily rely on information sharing to perform their missions. Solutions deployed in these environments need to focus on reliability and performance, in addition to usability to work as unattended as possible due to the often chaotic nature of operations. In this paper we propose a solution for delay-tolerant data sharing, in particular file sharing, using well supported, common networking protocols. The solution is based on the concept of broadcatching, which combines a delay-tolerant protocol such as BitTorrent with a publish/subscribe mechanism such as RSS to enable “many to one” information sharing. Experimental data shows that it is a promising approach for enabling reliable, mostly unattended data sharing on tactical networks in tactical environments.
This paper reports the results and findings of a historical analysis of open source intelligence (OSINT) information (namely Twitter data) surrounding the events of the September 11, 2012 attack on the US Diplomatic mission in Benghazi, Libya. In addition to this historical analysis, two prototype capabilities were combined for a table top exercise to explore the effectiveness of using OSINT combined with a context aware handheld situational awareness framework and application to better inform potential responders as the events unfolded. Our experience shows that the ability to model sentiment, trends, and monitor keywords in streaming social media, coupled with the ability to share that information to edge operators can increase their ability to effectively respond to contingency operations as they unfold.
Soldiers, first responders and other personnel operating at the tactical edge increasingly make use of mobile devices to help with tasks such as face recognition, language translation, decision-making and mission planning. Tactical-edge environments are characterized by limited resources, dynamic context, high stress and poor connectivity. This paper focuses on three architecture patterns that address these conditions. The Data Source Integration pattern uses server-side standardized definitions of live or cached geo-located data feeds that can be customized and filtered on a single, map-based user interface on a mobile device. The Group Context Awareness pattern uses context obtained from groups of handheld devices operating as part of a team to make sure that the right information is displayed to the right soldier at the right time. The Cloudlet-Based Cyber-Foraging pattern uses cloudlets as code-offload elements to optimize resources and increase computation power of mobile devices. Cloudlets are discoverable, localized, stateless servers running one or more virtual machines on which users can offload resource-intensive computations from their mobile devices. Prototype applications have been implemented for each of these patterns. Experiment results and participation in exercises have shown the effectiveness of the patterns in addressing the challenges of resource-constrained environments.
Handheld mobile technology is reaching first responders and soldiers in the field to help with mission execution. A characteristic of mission execution environments is that people are typically deployed in teams or groups to execute the mission. Most commercially-available context-aware mobile applications are based on context expressed mainly as location and time of an individual device plus the device user’s preferences or history. This work extends context to consider the group that the individual is a part of and presents a reference architecture for group-context-aware mobile applications that integrates contextual information from individuals and nearby team members operating to execute a mission. The architecture is highly extensible to support changes in context data models, context data storage mechanisms, context reasoning engines and rules, sensors, communication mechanisms and context views. A prototype implementation was built to demonstrate the validity and extensibility of the reference architecture.
: This report describes some of the challenges of software versioning in an SOA environment and provides guidance on how to meet these challenges by following industry guidelines and recommended practices. Managing change in software systems becomes more difficult as the software increases in size, complexity, and dependencies. Part of this task is software versioning, in which version identifiers are assigned to software artifacts for the purpose of managing their evolution. However, software versioning is not a self-contained task. Versioning decisions affect a wide range of processes that fall under the broad heading of change management. With the advent of service- oriented architecture (SOA) as a software-development paradigm, software versioning has become even more entwined with the software life cycle, mainly due to the highly distributed nature, multiproduct outcome, and multilayer implementation of service-oriented systems. The report describes typical items that a versioning policy for a service-oriented system should contain, including which artifacts to version, how to apply version control, and the impact of versioning on each phase of the life cycle within an SOA infrastructure.
: Context-aware mobile applications can sense and respond to changes in environment or context. An example is a location-based application that uses GPS coordinates to define the information displayed to mobile users based on their current location. Our work focuses on the integration of an individual's context with that of nearby individuals operating as part of a group or unit, such as in the military or first-responder situations. This integrated context can then be used to enhance the precision of information provided to users and give a more complete picture of the status of a mission. Given the early stages of the research process when there are many unknowns, we defined extensibility as the main architectural driver. This work has provided the ability to leverage the architecture to support collaboration. By identifying extensibility scenarios early in the design process, we were able to construct an architecture that supports multi-organizational collaboration to construct and evaluate different pieces of the architecture: context data models, context sources such as sensors, context reasoning engines and rules, and context visualization activities. This has allowed us to reach out to researchers from multiple universities and industry, resulting in synergistic research and development furthering the goals of all participants.
: Achieving interoperability in an e-government context is difficult. Although the benefits of enabling e-government systems to interoperate are significant, repeated failures to build working systems provide evidence that the tasks necessary to gain those benefits are poorly understood. Many governments have addressed interoperability as primarily a technical issue. However, to address the entirety of the interoperability challenge, development teams must also consider nontechnical factors that influence their efforts to meet interoperability goals. This report describes a proposed model through which to understand interoperability in the e-government context. With this model, system developers should characterize interoperability in six dimensions: Developers need to analyze e-government interoperability requirements at the technical, semantic, and organizational levels, but they should also consider the legal, political, and sociocultural issues with which the e-government system must also interoperate. This report explains some of the challenges associated with achieving interoperability in e-government systems and presents some guidance on how to address interoperability requirements, with the goal of making both policy makers and system developers aware of the depth and breadth of these challenges.