Computing Sandbox Driven Secure Edge Computing System for Industrial IoT

Fan Zhang, Pengfei Yu, Shaoyong Guo, Weicong Huang, Feng Qi · IEEE Transactions on Network and Service Management · 2025

With the initiation of the Internet of Everything, edge computing has emerged as a pivotal paradigm, shifting from cloud computing to better address the growing data demands and latency issues in Industrial Internet of Things (IIoT). However, securing edge computing systems remains a critical challenge as malicious attackers can compromise the IIoT systems, gain control over edge servers, and tamper with computation programs and results. Existing solutions, such as cryptographic encryption, intrusion detection, and blockchain-based methods, have been widely used to enhance security. Yet, these approaches often suffer from high computational overhead, limited adaptability to dynamic IIoT environments, and a lack of foundational trusted assurance mechanisms. Although Trusted Execution Environment (TEE)-based solutions provide a hardware-enhanced secure execution environment, they face scalability and usability challenges and cannot fully support the parallel execution requirements of multiple and diverse IIoT applications. To overcome these limitations, a novel secure edge computing system is proposed for IIoT that strengthens security from the physical layer. By establishing a computing sandbox model, we extend the trust boundaries of the TEE using a virtual Trusted Platform Module (TPM), enabling secure and efficient execution for diverse IIoT applications. The proposed approach integrates a trust guarantee mechanism with decentralized adaptive attestation, ensuring real-time integrity verification while reducing performance overhead. Through security analysis and experimental validation, it is shown that our system improves Non-Volatile Random-Access Memory (NVRAM) launch time by approximately 1,700 times compared to hardware TPM-based virtual TPM implementations, while enhancing protection against attacks such as rollback.

Read the paper · More papers on PaperTik