Cloud-native encryption as a service for IoT
Abstract
Abstract Encryption as a Service (EaaS) is a practical solution for resource-constrained Internet of Things (IoT) devices that cannot efficiently execute costly cryptographic tasks locally. This paper presents a cloud-native EaaS platform implemented on Kubernetes and designed to support scalable encryption, decryption, and key-management services for IoT environments. The paper describes the functional architecture of the platform, defines its main service workflow, and introduces two deployment modes, namely cloud-based and fog-based deployment. The proposed platform is evaluated in terms of processing time, deployment time, and end-to-end response time. The results show that the fog-based deployment reduces the response time by at least $$16\%$$ for small payloads and by up to $$6.8\times$$ for larger payloads compared with the cloud-based mode. The deployment analysis also shows that increasing the number of replicas from 1 to 5 leads to a deployment-time increase of more than $$30\%$$ , while increasing the workload to 11 replicas results in an increase of about $$47\%$$ . In addition, the results indicate that the Key Manager is the most resource-intensive component and has the highest impact on pod readiness time. Overall, the findings show that the proposed Kubernetes-based EaaS platform can provide flexible and scalable cryptographic support for IoT systems, while fog-based placement offers clear latency advantages in the evaluated prototype setting.
Article Details
Authors (8)
Amir Javadpour
Tarik Taleb
Chafika Benzaid
Khaled Zeraoulia
Abderezzak Djebrani
Mohamed Yacine Belhadi
Luis Cordeiro
Luís Rosa