Systems and methods for advanced secure edge computing

A decentralized authentication system for edge computing platforms uses a crypto server and asymmetric cryptographic keys to manage secure communications between applications, addressing inefficiencies and cybersecurity issues by local credential verification and reducing reliance on central servers.

WO2025147953A1PCT designated stage expired Publication Date: 2025-07-17MASTERCARD SHANGHAI BUSINESS CONSULTING LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/071791
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-11
Publication Date
2025-07-17

AI Technical Summary

Technical Problem

Edge computing platforms face challenges in securely managing communications between applications due to complex networks, security constraints, unstable networks, low bandwidth, and latency lags, especially when centralized authentication servers are distant, leading to inefficiencies and cybersecurity risks.

Method used

A decentralized authentication system using a crypto server on the edge computing platform that stores credential information, performs local credential verification, and enables secure communication between applications through asymmetric cryptographic keys and key rings, allowing for secure and efficient authorization without relying on central servers.

Benefits of technology

This system enhances security, reduces bandwidth requirements, improves processing speed, and minimizes network overhead by enabling secure, decentralized processing and reducing the dependency on remote authentication centers, thus strengthening edge-based ecosystems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024071791_17072025_PF_FP_ABST
    Figure CN2024071791_17072025_PF_FP_ABST
Patent Text Reader

Abstract

A system for secure edge computing is provided. The system is programmed to: a) execute a plurality of applications including a first application and a second application; b) execute a crypto server in communication with the plurality of applications; c) receive, from the first application, an access request to access the second application; d) determine whether the second application includes credential information for the first application; and e) if the determination is that the second application does not include credential information for the first application, the at least one processor is programmed to: (i) transmit, from the second application to the crypto server, a credential request for credential information for the first application; (ii) upon validating the credential request, transmit, from the crypto server to the second application, the credential information for the first application; and (iii) permit communication between the first application and the second application.
Need to check novelty before this filing date? Find Prior Art

Description

SYSTEMS AND METHODS FOR ADVANCED SECURE EDGE COMPUTINGBACKGROUND

[0001] The field of the invention relates generally to secure edge computing, and more particularly, to computer-based systems and methods for providing secure connections for remote edge computer systems.

[0002] Edge computing platforms are geographically deployed in remote sites, which are far away from the central management center. In many situations, these edge computing platforms are deployed at remote sites as the single entrance door for the user to access a secure network. One major challenge in this scenario is efficiently and securely managing the communications between applications involved in the edge computing platform while meeting security and communication requirements. The edge computing platform may contain and execute several categories of applications with a variety of different privileges running to support users. Traditionally, applications could communicate with a central authorization / authentication service to grant or verify credentials for further processing. However, the central authorization / authentication service is generally deployed at a management center, which may be very distant from the edge computing platform. Consequently, interactions between applications on the edge computing platform may not be effective due to complex networks, security constraints, unstable networks, low bandwidth, and / or latency lags. Accordingly, there is a need for an improved system to support edge computing platforms more securely.

[0003] BRIEF DESCRIPTION

[0004] In one aspect, a system for secure edge computing is provided. The system includes a memory device and at least one processor coupled to the memory device. The at least one processor is programmed to execute a plurality of applications including a first application and a second application. The at least one processor is also programmed to execute a crypto server in communication with the plurality of  applications. The crypto server stores a plurality of credential information for the plurality of applications. The at least one processor is further programmed to receive, from the first application, an access request to access the second application. In addition, the at least one processor is programmed to determine whether the second application includes credential information for the first application. If the determination is that the second application does not include credential information for the first application, the at least one processor is programmed to: a) transmit, from the second application to the crypto server, a credential request for credential information for the first application; b) upon validating the credential request, transmit, from the crypto server to the second application, the credential information for the first application; and c) permit communication between the first application and the second application.

[0005] In another aspect, a computer-implemented method for secure edge computing is provided. The method is implemented on a computing device comprising a memory device coupled to at least one processor. The method includes executing a plurality of applications including a first application and a second application. The method also includes executing a crypto server in communication with the plurality of applications. The crypto server stores a plurality of credential information for the plurality of applications. The method further includes receiving, from the first application, an access request to access the second application. In addition, the method includes determining whether the second application includes credential information for the first application. If the determination is that the second application does not include credential information for the first application, the method further includes a) transmitting, from the second application to the crypto server, a credential request for credential information for the first application; b) upon validating the credential request, transmitting, from the crypto server to the second application, the credential information for the first application; and c) permitting communication between the first application and the second application.

[0006] In a further aspect, at least one non-transitory computer-readable storage media having computer-executable instructions embodied thereon for secure edge computing is provided. When executed by at least one processor, the computer-executable instructions cause at least one processor to execute a plurality of  applications including a first application and a second application. The computer-executable instructions also cause at least one processor to execute a crypto server in communication with the plurality of applications. The crypto server stores a plurality of credential information for the plurality of applications. The computer-executable instructions further cause at least one processor to receive, from the first application, an access request to access the second application. In addition, the computer-executable instructions cause at least one processor to determine whether the second application includes credential information for the first application. If the determination is that the second application does not include credential information for the first application, the computer-executable instructions cause the at least one processor to: a) transmit, from the second application to the crypto server, a credential request for credential information for the first application; b) upon validating the credential request, transmit, from the crypto server to the second application, the credential information for the first application; and c) permit communication between the first application and the second application.BRIEF DESCRIPTION OF THE DRAWINGS

[0007] Figures 1-9 show example embodiments of the methods and systems described herein.

[0008] Figure 1 is a schematic diagram illustrating an example configuration of an edge computing system in accordance with one embodiment of the present disclosure.

[0009] Figure 2 is a schematic diagram illustrating an example configuration of another edge computing system in accordance with one embodiment of the present disclosure.

[0010] Figure 3 is a schematic diagram illustrating an example configuration of a further edge computing system in accordance with one embodiment of the present disclosure.

[0011] Figure 4 is a timing diagram of a process for registering a user or application using the edge computing systems shown in Figures 1, 2, and 3.

[0012] Figure 5 is a timing diagram of a process for accessing an application using the edge computing systems shown in Figures 1, 2, and 3.

[0013] Figure 6 is an expanded block diagram of an example embodiment of a computer system used for the secure edge computing systems shown in Figures 1, 2, and 3.

[0014] Figure 7 illustrates an example configuration of a user computing device.

[0015] Figure 8 illustrates an example configuration of a server system, such as the edge computing systems shown in Figures 1, 2, and 3, in accordance with one example embodiment of the present disclosure.

[0016] Figure 9 is a flow diagram of an example process for accessing an application using the edge computing systems shown in Figures 1, 2, and 3.

[0017] Although specific features of various embodiments may be shown in some drawings and not in others, this is for convenience only. Any feature of any drawing may be referenced and / or claimed in combination with any feature of any other drawing.DETAILED DESCRIPTION

[0018] For the purposes of this discussion, authentication is the process of verifying that the computer application that is trying to access another computer device or resource is a legitimate (permissioned) application and not a bad actor. In other words, is the accessing computer resource or asset a legitimate party or asset (has the authority or permission) trying to access another resource. Centralized authentication is a version of authentication, where applications communicate with a centralized authentication server, receives a credential from the centralized  authentication server, and then the applications communicate with each other using this credential.

[0019] The present embodiments may relate to, inter alia, systems and methods for secure edge computing, and more particularly, to computer-based systems and methods for providing secure connections for remote edge computer systems. In one exemplary embodiment, the process is performed by an edge computing platform ( “ECP” ) computer device, also known as an ECP server or ECP controller. The ECP controller may be remote from a central authentication server and / or a central authorization server. The ECP controller may be used to provide secure authentication and / or authorization services remote from the central server set-up.

[0020] The system and method described herein provide secure communications on one or more decentralized virtualizable edge platforms. This system and method use one or more symmetric cryptographic algorithms, asymmetric cryptographic algorithms, and the operating system kernel’s capabilities. This allows the system to provide decentralized authorization / authentication, secret storage and distribution on the edge computing platform, and confidentiality and integrity of interaction data.

[0021] In the exemplary embodiment, the ECP controller executes a hypervisor and two virtual machines (VM) , VM A and VM B. In these embodiments, the hypervisor executes a crypto server, which is in communication with a KVM (Kernel-based Virtual Machine) module and a dominant key ring.

[0022] In these embodiments, the VM A executes application A and a local key ring A, where application A is in communication with the local key A. The VM B executes application B and a local key ring B, where application B is in communication with the local key B. The hypervisor is also executing application C, which is in communication with a local key ring C. One having skill in the art would understand that each VM and the hypervisor may be executing multiple applications. Furthermore, different numbers of VMs and / or combinations of VMs and applications  may be used in different configurations. In at least one embodiment, the applications may be used for processing transactions and / or other data messages.

[0023] In the exemplary embodiment, each application A, B, and C has an assigned USER ID. Furthermore, each VM A and B has an assigned VM UUID (universally unique identifier) . In some embodiments, the VM UUID is assigned by the hypervisor. In additional environments, each application’s USER ID is assigned to the application and remains the same every time the application is started. In other embodiments, the application’s USER ID may be a combination of an application ID and the VM UUID. In still further embodiments, the USER ID may be assigned by one of the hypervisor and / or the VM when the application is started. In some embodiments, the application USER ID and VM UUID are provided and / or accessible by the crypto server.

[0024] In the exemplary embodiment, the dominant key ring is a private resource owned by the crypto server and can only be accessed by the crypto server. In some embodiments, the local key rings are owned by the applications or the VMs. In at least one embodiment, each application on a VM has its own local key ring. In other embodiments, all of the applications on the same VM share a local key ring. In some embodiments, each local key ring is cleared when the ECP controller reboots. In some further embodiments, the dominant key ring is cleared when the ECP controller reboots.

[0025] The crypto server initializes a pair of asymmetric cryptographic keys when the crypto server boots up. The crypto server may use any proven trusted asymmetric cryptographic algorithms, i.e., RSA, and SM2. The crypto server will save the key pair into the Dominant Key Ring. In the exemplary embodiment, both of the private / public key pair will expire after a predefined period of time. In addition, this key pair can ONLY be directly accessed by the crypto server.

[0026] In the exemplary embodiment, each application requires authorization to be accessed either by a user, such as via a user computer device, or by another application.

[0027] In the exemplary embodiment, the system is used for communication between the applications and the hypervisor as outlined herein. This communication consists of four stages: Initialization, Registration, Handshake, and Transportation.

[0028] In the Initialization stage, the crypto server initializes a pair of asymmetric cryptographic keys when the crypto server boots up. The system may use any proven and trusted asymmetric cryptographic algorithms (e.g., RSA, and SM2) . The crypto server will save the key pair into the dominant key ring. In the exemplary embodiment, both of the private / public key pair will expire after a predefined period of time. In addition, this key pair can only be directly accessed by the crypto server. The crypto server has pre-configured trusted invocation bindings in terms of the application’s user information, USER ID and VM UUID (universally unique identifier) in this context. In some embodiments, the crypto server is pre-configured with a whitelist of safe identities, such as those of the virtual machines and / or applications. In these embodiments, the whitelist is used during the registration stage.

[0029] In the Registration stage, each application proactively sends a request with VM UUID, USER ID and public key to the crypto server to register itself. The crypto server will first check if the USER ID and VM UUID group is valid. After the validation is passed, the crypto server returns a credential to the application. The detailed logic of this process is described in the following process. First, the application generates and stores the application’s public key and private key in the application’s local key ring. In some embodiments, the local key ring may be tied to the virtual machine that the application is executing on. Next, the application registers itself to the crypto server. Then, the crypto server validates the USER ID and VM UUID of the request. If the request is invalid, then the request is rejected. If the request is valid, the crypto server returns the public key and the bindings for this application. Then the application stores the public key and the bindings in the local key ring. At the end of the Registration process, each application will store the crypto server’s public key in the corresponding local key ring.

[0030] In the Handshake stage, a client application and the target application exchange public keys by handshaking. This approach supports two kinds of handshaking, one is the exchange of public keys only, and the other is to get an interim working key. The client application initiates this process by sending a handshake request to a target application. The request contains the client application’s public key, USER ID and VM UUID. The target application validates the client application’s user information. If the request is valid, the target application will generate and store a working key in their local key ring. Then the target application encrypts the working key with the client application’s public key and returns that encrypted information to the client application.

[0031] In the example embodiment, the Transportation stage outlines a transfer with a permanent working key. In this stage, the client application sends the target application data encrypted with the working key generated in the Handshake stage. When the target application receives data, the target application checks if it has an in-memory working key or a local key ring. If an in-memory working key or local key ring is not found, the target application will perform a re-handshake operation.

[0032] For this sequence, the working key is permanent until it is expired. This is for systems where the security level is not very high. If the confidentiality level of the system communication is higher, the digital envelope method could be leveraged for data transportation.

[0033] With the digital envelope method, each request and response will be encrypted with a unique interim working key. Different requests or responses will be encrypted with different working keys. In this method, the communication will be more secure than having a permanent working key. If the Transportation is based on a digital envelope, then the system only needs to handshake to exchange public keys for the client and target applications.

[0034] The above process could also include an extend stage to support communications between applications within same realm (such as VM in this context) . In the same virtual machine, different applications can share the local key  rings and the dominant key ring as well. The crypto server could be in a stealth state. In this set-up the client application and the target application could bypass the crypto server to do key exchange with same local key ring.

[0035] At least one of the technical problems addressed by this system includes: (i) increased security for distributed systems; (ii) reduced bandwidth required for processing remote users; (iii) secure decentralized processing for remote users; (iv) improved processing speed; (v) removing dependency on a remote authentication center; (vi) reduced network overhead; (vii) reduced potential attack surface for each edge device; and (viii) improved security for edge-based ecosystems.

[0036] A technical effect of the systems and processes described herein is achieved by performing at least one of the following steps: a) execute a plurality of applications including a first application and a second application; b )execute a crypto server in communication with the plurality of applications, wherein the crypto server stores a plurality of credential information for the plurality of applications; c) receive, from the first application, an access request to access the second application; d) determine whether the second application includes credential information for the first application; e) if the determination is that the second application does not include credential information for the first application, the at least one processor is programmed to: i) transmit, from the second application to the crypto server, a credential request for credential information for the first application; ii) upon validating the credential request, transmit, from the crypto server to the second application, the credential information for the first application; and iii) permit communication between the first application and the second application; f) if the determination is that the second application includes credential information for the first application, permit communication between the first application and the second application; g) wherein the access request includes at least one identifier for the first application; h) wherein the credential request includes the at least one identifier for the first application; i) wherein the crypto server validates the credential request based upon the at least one identifier of the first application; j) deny the credential request if the crypto server does not validate the credential request; k) deny the access request if the validation of the at least one identifier for the first application fails; l) encrypt the  credential information for the first application with a public key for the second application prior to transmitting to the second application; m) transmit a public key for the second application to the first application after receiving the credential information for the first application; n) wherein the crypto server is in communication with a dominant key ring, wherein the crypto server stores the plurality of credential information for the plurality of applications in the dominant key ring; o) receive registration information from the first application, wherein the registration information for the first application includes the credential information for the first application; p) validate the registration information for the first application; q) store the registration information for the first application in the dominant key ring; r) retrieve credential information for the crypto server from the dominant key ring; s) transmit the credential information for the crypto server to the first application; t) store the credential information for the crypto server in a local key ring in communication with the first application; u) execute the first application in a first virtual machine; v) execute the crypto server in a hypervisor in communication with the first virtual machine; w) execute the second application in the first virtual machine; x) execute the second application in a second virtual machine; y) execute a third application of the plurality of applications in the hypervisor; and z) wherein the crypto server and the plurality of applications are executed on the same physical edge computing device.

[0037] As will be appreciated, based on the description herein the technical improvement in the secure edge computing as described herein is a computer-based solution to a technical deficiency or problem that is itself rooted in computer technology (e.g., the problem itself derives from the use of computer technology) . More specifically, edge computing systems may require tremendous amounts of bandwidth when communicating with central authentication servers and open themselves up to cybersecurity issues. Edge computer-based authentication system are useful to more efficiently and securely process authentication in an efficient manner and significantly reduce the computer processing resources required. Accordingly, to address this problem, the systems and methods described herein address this technical problem by using and authenticating an edge computing system.

[0038] The following detailed description of the embodiments of the disclosure refers to the accompanying drawings. The same reference numbers in different drawings may identify the same or similar elements. Also, the following detailed description does not limit the claims.

[0039] Described herein are computer systems such as authentication computer systems. As described herein, all such computer systems include a processor and a memory. However, any processor in a computer device referred to herein may also refer to one or more processors wherein the processor may be in one computing device or a plurality of computing devices acting in parallel. Additionally, any memory in a computer device referred to herein may also refer to one or more memories wherein the memories may be in one computing device or a plurality of computing devices acting in parallel.

[0040] As used herein, a processor may include any programmable system including systems using micro-controllers, reduced instruction set circuits (RISC) , application specific integrated circuits (ASICs) , logic circuits, and any other circuit or processor capable of executing the functions described herein. The above examples are example only and are thus not intended to limit in any way the definition and / or meaning of the term “processor. ”

[0041] As used herein, the term “database” may refer to either a body of data, a relational database management system (RDBMS) , or to both. As used herein, a database may include any collection of data including hierarchical databases, relational databases, flat file databases, object-relational databases, object-oriented databases, and any other structured collection of records or data that is stored in a computer system. The above examples are example only, and thus are not intended to limit in any way the definition and / or meaning of the term database. Examples of RDBMS’s include, but are not limited to including,  Database, MySQL,  DB2,  SQL Server,  and PostgreSQL. However, any database may be used that enables the systems and methods described herein. (Oracle is a registered trademark of Oracle Corporation, Redwood Shores, California; IBM is a registered trademark of International Business Machines Corporation, Armonk, New York;  Microsoft is a registered trademark of Microsoft Corporation, Redmond, Washington; and Sybase is a registered trademark of Sybase, Dublin, California. )

[0042] In one embodiment, a computer program is provided, and the program is embodied on a computer readable medium. In an example embodiment, the system is executed on a single computer system, without requiring a connection to a sever computer. In a further embodiment, the system is being run in a environment (Windows is a registered trademark of Microsoft Corporation, Redmond, Washington) . In yet another embodiment, the system is run on a mainframe environment and a server environment (UNIX is a registered trademark of X / Open Company Limited located in Reading, Berkshire, United Kingdom) . In a further embodiment, the system is run on an environment (iOS is a registered trademark of Cisco Systems, Inc. located in San Jose, CA) . In yet a further embodiment, the system is run on a Mac environment (Mac OS is a registered trademark of Apple Inc. located in Cupertino, CA) . In still yet a further embodiment, the system is run on OS (Android is a registered trademark of Google, Inc. of Mountain View, CA) . In another embodiment, the system is run on OS (Linux is a registered trademark of Linus Torvalds of Boston, MA) . The application is flexible and designed to run in various different environments without compromising any major functionality. In some embodiments, the system includes multiple components distributed among a plurality of computing devices. One or more components may be in the form of computer-executable instructions embodied in a computer-readable medium.

[0043] As used herein, an element or step recited in the singular and proceeded with the word “a” or “an” should be understood as not excluding plural elements or steps, unless such exclusion is explicitly recited. Furthermore, references to “example embodiment” or “one embodiment” of the present disclosure are not intended to be interpreted as excluding the existence of additional embodiments that also incorporate the recited features.

[0044] As used herein, the terms “software” and “firmware” are interchangeable and include any computer program stored in memory for execution by  a processor, including RAM memory, ROM memory, EPROM memory, EEPROM memory, and non-volatile RAM (NVRAM) memory. The above memory types are example only and are thus not limiting as to the types of memory usable for storage of a computer program.

[0045] Furthermore, as used herein, the term “real-time” refers to at least one of the time of occurrence of the associated events, the time of measurement and collection of predetermined data, the time for a computing device (e.g., a processor) to process the data, and the time of a system response to the events and the environment. In the embodiments described herein, these activities and events may be considered to occur substantially instantaneously.

[0046] As used herein, the terms “payment device, ” “transaction card, ” “financial transaction card, ” and “payment card” refer to any suitable transaction card, such as a credit card, a debit card, a prepaid card, a charge card, a membership card, a promotional card, a frequent flyer card, an identification card, a prepaid card, a gift card, and / or any other device that may hold payment account information, such as mobile phones, Smartphones, personal digital assistants (PDAs) , wearable computing devices, key fobs, and / or any other computing devices capable of providing account information. Moreover, these terms may refer to payments made directly from or using bank accounts, stored valued accounts, mobile wallets, etc., and accordingly are not limited to physical devices but rather refer generally to payment credentials. Each type of payment device can be used as a method of payment for performing a transaction. In addition, consumer card account behavior can include but is not limited to purchases, management activities (e.g., balance checking) , bill payments, achievement of targets (meeting account balance goals, paying bills on time) , and / or product registrations (e.g., mobile application downloads) .

[0047] The systems and processes are not limited to the specific embodiments described herein. In addition, components of each system and each process can be practiced independent and separate from other components and processes described herein. Each component and process also can be used in combination with other assembly packages and processes.

[0048] The following detailed description illustrates embodiments of the disclosure by way of example and not by way of limitation. It is contemplated that the disclosure has general application to authenticating users for transactions conducted over an electronic payment network.

[0049] Figure 1 is a schematic diagram illustrating an example configuration of an edge computing system 100 in accordance with one embodiment of the present disclosure. Edge computing system 100 includes a physical edge computing platform (ECP) 105. The ECP 105 in system 100 is executing a hypervisor 110 and two virtual machines (VM) , VM A 115 and VM B 120. The hypervisor 110 includes a crypto server 125, which is in communication with a KVM (Kernel-based Virtual Machine) module 130 and a dominant key ring 135.

[0050] VM A 115 includes application A 140 and a local key ring A 155, where application A 140 is in communication with the local key A 155. VM B 120 includes application B 145 and a local key ring B 160, where application B 145 is in communication with the local key B 160. The hypervisor 110 is also executing application C 150, which is in communication with a local key ring C 165. While only one application 140, 145, and 150 is shown in each VM 115 and 120 and the hypervisor 110, one having skill in the art would understand that each VM 115 and 120 and the hypervisor 110 may be executing multiple applications. Furthermore, different numbers of VMs and / or combinations of VMs and applications may be used in different configurations. In at least one embodiment, the applications A, B, and C 140, 145, and 150 may be used for processing transactions and / or other data messages.

[0051] In the exemplary embodiment, each application A, B, and C 140, 145, and 150 has an assigned USER ID. Furthermore, each VM A and B has an assigned VM UUID (universally unique identifier) . In some embodiments, the VM UUID is assigned by the hypervisor 110. In additional environments, each application’s USER ID is assigned to the application and remains the same every time the application is started. In other embodiments, the application’s USER ID may be a combination of an application ID and the VM UUID. In still further embodiments, the USER ID may be assigned by one of the hypervisor 110 and / or the VM 115 when the  application is started. In some embodiments, the application USER ID and VM UUID are provided and / or accessible by the crypto server 125.

[0052] In the exemplary embodiment, the dominant key ring 135 is a private resource owned by the crypto server 125 and can only be accessed by the crypto server 125. In some embodiments, the local key rings 155, 160, and 165 are owned by the applications 140, 145, and 150 or the VMs 115 and 120. In at least one embodiment, each application on a VM has its own local key ring. In other embodiments, all of the applications on the same VM share a local key ring. In some embodiments, each local key ring 155, 160, and 165 is cleared when the ECP 105 reboots. In some further embodiments, the dominant key ring 135 is cleared when the ECP 105 reboots.

[0053] The present disclosure describes two roles: application 140 and crypto server 125. These two roles could be running in different realms, which means running on different virtual machines or hypervisor 110 within one physical ECP 105. In the example embodiment, the crypto server 125 is a cryptographic service provider running on an ECP’s hypervisor 110. The crypto server 125 exposes interfaces consumed by one or more applications running on the same ECP 105. The application 140 is a process running on the same ECP 105 with the crypto server 125, either in a virtual machine 115 or in the hypervisor 110.

[0054] In this approach, the crypto server 125 is able to leverage two Linux kernel modules, the KVM (Kernel-based Virtual Machine) module 130 and the kernel key retention service, also known as a key ring 135. All keys including symmetric keys and asymmetric keys are securely stored in the key ring 135. Specifically, two kinds of logical key rings are introduced in this method: a dominant key ring 135 and a local key ring. The dominant key ring 135 is a private resource owned by or managed by the crypto server 125. The local key ring 155 is a resource owned by each of the user applications 140.

[0055] In at least one embodiment, the overall architecture used for this system comprises a virtual machine (VM) 115, a hypervisor 110, an application  140 (including the crypto server 125) , and / or the Linux Kernel Modules. The crypto server 125 runs in the hypervisor 110 with dominant keys, and cryptographic functions.

[0056] The crypto server 125 initializes a pair of asymmetric cryptographic keys when the crypto server 125 boots up. The crypto server 125 may use any proven trusted asymmetric cryptographic algorithms, i.e., RSA, and SM2. The crypto server 125 will save the key pair into the Dominant Key Ring 135. In the exemplary embodiment, both of the private / public key pair will expire after a predefined period of time. In addition, this key pair can ONLY be directly accessed by the crypto server 125.

[0057] In the exemplary embodiment, each application A, B, and C 140, 145, and 150 requires authorization to be accessed either by a user, such as via a user computer device, or by another application.

[0058] In the exemplary embodiment, the system 100 is used for communication between the applications 140 and 145 and the hypervisor 110 as outlined herein. This communication consists of four stages: Initialization, Registry, Handshake, and Transportation.

[0059] In the Initialization stage, the crypto server 125 initializes a pair of asymmetric cryptographic keys when the crypto server 125 boots up. The system 100 may use any proven trusted asymmetric cryptographic algorithms, i.e., RSA, and SM2. The crypto server 125 saves the key pair to the Dominant Key Ring 135. In the exemplary embodiment, both of the private / public key pair will expire after a predefined period of time. In addition, this key pair can ONLY be directly accessed by the crypto server 125. The crypto server 125 has pre-configured trusted invocation bindings in terms of the application’s user information, USER ID and VM UUID (universally unique identifier) in this context. In some embodiments, the crypto server 125 is pre-configured with a whitelist of safe identities, such as those of the virtual machines 115 and / or applications 140. In these embodiments, the whitelist is used during the registration stage.

[0060] In the Registry stage, each application A, B, and C 140, 145, and 150 proactively sends a request with VM UUID, USER ID and public key to the crypto server 125 to register itself. The crypto server 125 will firstly check if the USER ID and VM UUID group is valid. After the validation is passed, the crypto server 125 returns a credential to the corresponding application A, B, and C 140, 145, and 150. The detailed logic of this process is described in the following process. First, the application A 140 generates and stores the application’s public key and private key in the application’s local key ring A 155. Next, the application A 140 registers itself to the crypto server 125. For registration, the application A 140 provides its VM UUID, USER ID and public key. Then, the crypto server 125 validates USER ID and VM UUID of the request. If the request is invalid, then the request is rejected. If the request is valid, the crypto server 125 returns public key and the bindings for application A 140. Then application A 140 stores the public key and bindings in local key ring A 155. This process repeats for each application and at the end of the Registration process, each application will store the crypto server’s public key in their corresponding local key ring A, B, and C 155, 160, and 165.

[0061] In the Handshake stage, a client application (application A 140) and a target application (application B 145) exchange public keys by handshaking. This approach supports two kinds of handshaking, one is exchange public keys only, the other is to get an interim working key. The client application 145 initiates this process by sending a handshake request to the target application 150. The request contains the client application’s public key, USER ID and VM UUID. The target application 145 validates the client application’s user information. If the request is valid, the target application 145 will generate and store a working key in their Local Key Ring 160. Then the target application 145 encrypts the working key with the client application’s public key and returns that encrypted information to the client application 140.

[0062] The Transportation stage outlines a transfer with a permanent working key. In this stage, the client application 140 sends the target application 145 data encrypted with the working key generated in handshake stage. When the target application 145 receives data, the target application 145 checks if it has an in-memory  working key or a key in the Local Key Ring 160. If not found, the target application 145 will perform a re-handshake operation.

[0063] For this sequence, the working key is permanent until it is expired. This is for systems where the security level is not very high. If the confidentiality level of system communication is higher, the digital envelope method could be leveraged for data transportation.

[0064] With the digital envelope method, each request and response will be encrypted with a unique interim working key. Different requests or responses will be encrypted with different working keys. In this method, the communication will be more secure than having a permanent working key. If the transportation is based on digital envelope, then only need to handshake to exchange public keys for the client and target applications.

[0065] The above process could also include an extend stage to support communications between applications within same realm (such as VM in this context) . In same virtual machine, different applications can share the Local Key Rings and the Dominant Key Ring as well. The crypto server 125 could be in stealth state. In this set-up the client application 140 and the target application 145 could bypass crypto server 125 to do key exchange with same Local Key Ring 155.

[0066] While the above describes the secure edge computing system being used for processing transactions and / or other data messages, one having skill in the art would understand that other implementations may be used as well. For a non-limited example, the secure edge computing system may be used to analyze transactions and / or message to determine one or more other trends and / or patterns. The systems could also be used for analyzing other data stored within a data database; data that is not necessarily related to financial transactions. The system should not be limited to such applications.

[0067] Figure 2 is a schematic diagram illustrating an example configuration of another edge computing system 200 in accordance with one embodiment of the present disclosure. In system 200, VM A 115 includes multiple  applications (A and B) 140 and 145. While only two applications are shown, VM A 115 may contain any number of applications. In system 200, each application (A and B) 140 and 145 includes its own Local Key Ring (A and B) 155 and 160. In some other embodiments, there may be a single Local Key Ring 155 for VM A 115.

[0068] The two applications (A and B) 140 and 145 are in communication with each other and with the crypto server 125. For application A 140 to directly communicate with application B 145, both applications 140 and 145 need to register with the crypto server 125. Then both applications 104 and 145 need to go through the Handshake Sequence to exchange credentials as described herein.

[0069] Figure 3 is a schematic diagram illustrating an example configuration of a further edge computing system 300 in accordance with one embodiment of the present disclosure. In system 300 the crypto server 125 and the two applications 1404 and 145 are all on the same device, the ECP 105, without virtual machines. While only two applications are shown, ECP 105 may contain any number of applications. In system 300, each application (A and B) 140 and 145 includes its own Local Key Ring (A and B) 155 and 160. In some other embodiments, there may be a single Local Key Ring 155 for the ECP 105.

[0070] The two applications (A and B) 140 and 145 are in communication with each other and with the crypto server 125. For application A 140 to directly communicate with application B 145, both applications 140 and 145 need to register with the crypto server 125. Then both applications 104 and 145 need to go through the Handshake Sequence to exchange credentials as described herein.

[0071] Systems 100, 200, and 300 are described herein as example configurations for the systems and methods described herein. One having skill in the art would understand that other configurations would work with the systems and methods described herein.

[0072] Figure 4 is a timing diagram of a process 400 for registering a user or application using the edge computing systems 100, 200, and 300 (shown in  Figures 1, 2, and 3) . For the registration process 400, application A 140 registers with the crypto server 125.

[0073] Prior to the registration process 400, the crypto server 125 initializes a pair of asymmetric cryptographic keys when the crypto server 125 boots up. The crypto server 125 may use any proven trusted asymmetric cryptographic algorithms, i.e., RSA, and SM2. The crypto server 125 saves the key pair to the Dominant Key Ring 135. In the exemplary embodiment, both of the crypto server’s private / public key pair will expire after a predefined period of time. In addition, this key pair can ONLY be directly accessed by the crypto server 125. In some embodiments, the crypto server 125 is pre-configured with a whitelist of safe identities, such as those of the virtual machines 115 and / or applications 140 (both shown in Figure 1) . In these embodiments, the whitelist is used during the registration stage.

[0074] For the registration process 400, first application A 140 generates S410 a private / public key pair. application A 140 may use any proven trusted asymmetric cryptographic algorithms, i.e., RSA, and SM2. applications A 140 then saves S415 the key pair in its local key ring A 155. In the exemplary embodiment, both of application A’s private / public key pair will expire after a predefined period of time.

[0075] Then, application A 140 transmits S420 a registration message to the crypto server 125. The registration message includes, one or more of, the VM UUID of the VM A 115 that application A 140 is executing on; the USER ID of application A 140, and the public key that application A 140 generated. The crypto server 125 then validates S425 application A 140 using the VM UUID and the USER ID that were provided. In at least one embodiment, the crypto server 125 uses a Validation API 405 to validate S425 application A 140.

[0076] If application A 140 is validated, the crypto server 125 stores S430 a binding of the VM UUID and the USER ID with the public key in the dominant key ring 135. The crypto server 125 then retrieves S435 the crypto server’s public key and bindings from the dominant key ring 135. The crypto server 125 then transmits S440 the crypto server’s public key and bindings to application A 140. Application A  140 then stores S445 the crypto server’s public key and bindings in its local key ring A 155.

[0077] The registration process 400 is performed for all of the applications 140, 145, and 150 in the system 100, 200, and 300. This means that the dominant key ring 135 includes the USER ID, the VM UUID, and the public key for all of the applications on the ECP 105. Furthermore, each application’s local key ring includes the crypto server’s public key and bindings.

[0078] In at least one embodiment, the data in the return registration message is encrypted using application A’s public key. In a further embodiment, at least one of the VM UUID and / or the USER ID are encrypted using a common public key or another key, when transmitted to the crypto server 125 and / or the Validation API 405.

[0079] In some embodiments, one or more of the VM UUID and / or the USER ID are encrypted using a common public key or other key when stored in the dominant key ring.

[0080] In some embodiments, the local key ring 155 includes a verification process to verify that the accessing application is the correct one for the provided USER ID. In still further embodiments, the dominant key ring 135 may also include a verification step to configure that it is the crypto server 125 that is accessing the dominant key ring.

[0081] In further enhancements, the system 100, 200, and 300 may include a signature and a common public key to ensure that the VM UUID, the USER ID, and / or the public keys are not changed maliciously on the fly.

[0082] Figure 5 is a timing diagram of a process 500 for accessing an application using the edge computing systems 100, 200, and 300 (shown in Figures 1, 2, and 3) . Process 500 is for accessing an application using a handshake to allow for secure communication between two applications. The handshaking process 500 is used for when there are not valid keys between the two applications. This may occur when  it is the first time that the applications have tried to communicate. This may also occur after one or more of the keys of the applications have expired.

[0083] In the exemplary embodiment, application A 140 attempts to access application B 145 by transmitting S505 a handshake request to application B 145. In the exemplary embodiment, the handshake request includes application A’s VM UUID and USER ID. application B 145 retrieves S510 application A’s information from application B’s local key ring B 160. The local key ring B 160 returns S515 a blank or null indicating that the local key ring B 160 does not include application A’s information. The local key ring B 160 may also return S515 a blank or null to indicate that application A’s information in the local key ring B 160 has expired. application B 145 and the local key ring B 160 may use the provided VM UUID and USER ID to retrieve S510 application A’s information. In at least one embodiment, application A’s information in the local key ring B 160 includes application A’s public key.

[0084] application B 145 requests S520 application A’s information from the crypto server 125. In at least one embodiment, the request includes the VM UUID and the USER ID provided by application A 140. The crypto server 125 request S525 application A’s information from the dominant key ring 135. If application A 140 has registered as per process 400 (shown in Figure 4) , the dominant key ring 135 returns S530 application A’s information to the crypto server 125. In the exemplary embodiment, application A’s information includes application A’s public key. In other embodiments, other information may be included as well.

[0085] The crypto server 125 encrypts S535 application A’s information with application B’s public key. Then the crypto server 125 returns S540 the encrypted information to application B 145. application B 145 processes S545 the encrypted information including decrypting. Then application B 145 stores S550 application A’s public key in its local key ring 160. application B 145 also transmits S555 its public key and other information to application A 140. The other information may include application B’s key encrypted with application A’s public key. The other information may also include a signature for validation purposes, such as application A's VM UUID encrypted using application B’s encryption key. In some embodiments,  application A 140 stores application B’s information in its local key ring A 155 (shown in Figure 1) .

[0086] Figure 6 is an expanded block diagram of an example embodiment of a computer system 600used for the secure edge computing systems 100, 200, and 300 (shown in Figures 1, 2, and 3) . In the exemplary embodiment, system 600 may be used for processing data and authentication using the secure edge computing systems as described herein. In the exemplary embodiment, the system 600 may be programmed to a) execute a plurality of applications including a first application 140 and a second application 145 (both shown in Figure 1) ; b) execute a crypto server 125 (shown in Figure 1) in communication with the plurality of applications, where the crypto server 125 stores a plurality of credential information for the plurality of applications; c) receive, from the first application 140, an access request to access the second application 145; d) determine whether the second application 145 includes credential information for the first application 140; and e) if the determination is that the second application 145 does not include credential information for the first application 140, i) transmit, from the second application 145 to the crypto server 125, a credential request for credential information for the first application 140; ii) upon validating the credential request, transmit, from the crypto server 125 to the second application 145, the credential information for the first application 140; and c) permit communication between the first application 140 and the second application 145.

[0087] In the exemplary embodiment, user computer devices 605 are computers that include a web browser or a software application, which enables user computer devices 605 to access remote computer devices, such as ECP 105, using the Internet or other network. More specifically, user computer devices 605 may be communicatively coupled to the Internet through many interfaces including, but not limited to, at least one of a network, such as the Internet, a local area network (LAN) , a wide area network (WAN) , or an integrated services digital network (ISDN) , a dial-up-connection, a digital subscriber line (DSL) , a cellular phone connection, and a cable modem. User computer devices 605 may be any device capable of accessing the Internet including, but not limited to, a desktop computer, a laptop computer, a personal  digital assistant (PDA) , a cellular phone, a smartphone, a tablet, a phablet, wearable electronics, smart watch, or other web-based connectable equipment or mobile devices.

[0088] In the exemplary embodiment, network server 610 is a computer system used for remotely providing and / or retrieving processing information. Network server 610 includes a web browser or a software application, which enables network server 610 to access remote computer devices, such as ECP 105, using the Internet or other network. More specifically, network server 610 may be hosted on one or more computers that are communicatively coupled to the Internet through many interfaces including, but not limited to, at least one of a network, such as the Internet, a local area network (LAN) , a wide area network (WAN) , or an integrated services digital network (ISDN) , a dial-up-connection, a digital subscriber line (DSL) , a cellular phone connection, and a cable modem. Network server 610 may be any device capable of accessing the Internet including, but not limited to, a desktop computer, a laptop computer, a personal digital assistant (PDA) , a cellular phone, a smartphone, a tablet, a phablet, wearable electronics, smart watch, or other web-based connectable equipment or mobile devices.

[0089] In the exemplary embodiments, edge computing platform (ECP) 105 authorizes communication between applications 140 and 145 (both shown in Figure 1) . In some embodiments, the ECP 105 is in communication with one or more user computer devices 605. In some embodiments, ECP 105 executes a plurality of applications and is remote from any network server 610. In the exemplary embodiment, ECP 105 may be configured in multiple different configurations, such as systems 100, 200, and 300, as a non-limiting example, as described further herein.

[0090] In the exemplary embodiments, ECP (s) 105 are computers that include a web browser or a software application, which allow for communication with a plurality of user computer devices 605, using the Internet or other network. More specifically, ECP 105 may be communicatively coupled to the Internet through many interfaces including, but not limited to, at least one of a network, such as the Internet, a local area network (LAN) , a wide area network (WAN) , or an integrated services digital network (ISDN) , a dial-up-connection, a digital subscriber line (DSL) , a cellular phone  connection, and a cable modem. ECP 105 may be any device capable of accessing the Internet including, but not limited to, a desktop computer, a laptop computer, a personal digital assistant (PDA) , a cellular phone, a smartphone, a tablet, a phablet, wearable electronics, smart watch, or other web-based connectable equipment or mobile devices.

[0091] A database server 615 is connected to database 620. In one embodiment, centralized database 620 is stored on the ECP 105 and can be accessed by potential users at one of user computing devices 605 by logging onto ECP 105, such as through one or more applications. In an alternative embodiment, database 620 is stored remotely from ECP 105 and may be non-centralized. Database 620 may be a database configured to store information in including, for example, transaction data.

[0092] Database 620 may include a single database having separated sections or partitions, or may include multiple databases, each being separate from each other. Database 620 may store transaction data generated over a computer network, such as the network server 610 including data relating to merchants, consumers, account holders, prospective customers, issuers, acquirers, and / or purchases made.

[0093] Figure 7 illustrates an example configuration of a user computing device 702. User computing device 702 may include, but is not limited to, user computer device 605 (shown in Figure 6) . User computing device 702 includes a processor 705 for executing instructions. In some embodiments, executable instructions are stored in a memory area 710. Processor 705 may include one or more processing units (e.g., in a multi-core configuration) . Memory area 710 is any device allowing information such as executable instructions and / or other data to be stored and retrieved. Memory area 710 may include one or more computer-readable media.

[0094] User computing device 702 also includes at least one media output component 715 for presenting information to a user 700. Media output component 715 is any component capable of conveying information to user 700. In some embodiments, media output component 715 includes an output adapter such as a video adapter and / or an audio adapter. An output adapter is operatively coupled to processor 705 and operatively couplable to an output device such as a display device  (e.g., a cathode ray tube (CRT) , liquid crystal display (LCD) , light emitting diode (LED) display, or “electronic ink” display) or an audio output device (e.g., a speaker or headphones) .

[0095] In some embodiments, user computing device 702 includes an input device 720 for receiving input from user 701. Input device 720 may include, for example, a keyboard, a pointing device, a mouse, a stylus, a touch sensitive panel (e.g., a touch pad or a touch screen) , a camera, a gyroscope, an accelerometer, a position detector, and / or an audio input device. A single component such as a touch screen may function as both an output device of media output component 715 and input device 720.

[0096] User computing device 702 may also include a communication interface 725, which is communicatively couplable to a remote device such as ECP 105 (shown in Figure 1) . Communication interface 725 may include, for example, a wired or wireless network adapter or a wireless data transceiver for use with a mobile phone network (e.g., Global System for Mobile communications (GSM) , 3G, 4G or Bluetooth) or other mobile data network (e.g., Worldwide Interoperability for Microwave Access (WIMAX) ) .

[0097] Stored in memory area 710 are, for example, computer readable instructions for providing a user interface to user 701 via media output component 715 and, optionally, receiving and processing input from input device 720. A user interface may include, among other possibilities, a web browser and / or a client application. Web browsers enable users, such as user 701, to display and interact with media and other information typically embedded on a web page or a website from ECP 105. A client application allows user 701 to interact with, for example, message traffic and / or transaction reports. For example, instructions may be stored by a cloud service, and the output of the execution of the instructions sent to the media output component 715.

[0098] Processor 705 executes computer-executable instructions for implementing aspects of the disclosure. In some embodiments, the processor 705 is  transformed into a special purpose microprocessor by executing computer-executable instructions or by otherwise being programmed.

[0099] Figure 8 illustrates an example configuration of a server system 801 such as ECP 105 (shown in Figure 1) , in accordance with one example embodiment of the present disclosure. Server system 801 may also include, but is not limited to, ECP 105 (shown in Figure 1) , network server 610, and database server 615 (both shown in Figure 6) . In the example embodiment, server system 801 determines and analyzes patterns in transactions, as described herein.

[0100] Server system 801 includes a processor 805 for executing instructions. Instructions may be stored in a memory area 810, for example. Processor 805 may include one or more processing units (e.g., in a multi-core configuration) for executing instructions. The instructions may be executed within a variety of different operating systems on the server system 801, such as UNIX, LINUX, Microsoft  etc. It should also be appreciated that upon initiation of a computer-based method, various instructions may be executed during initialization. Some operations may be required in order to perform one or more processes described herein, while other operations may be more general and / or specific to a particular programming language (e.g., C, C#, C++, Java, or other suitable programming languages, etc. ) .

[0101] Processor 805 is operatively coupled to a communication interface 815 such that server system 801 is capable of communicating with a remote device such as a user system or another server system 801. For example, communication interface 815 may receive requests from a user computer device 605 via the Internet, as illustrated in Figure 6.

[0102] Processor 805 may also be operatively coupled to a storage device 834. Storage device 834 is any computer-operated hardware suitable for storing and / or retrieving data. In some embodiments, storage device 834 is integrated in server system 801. For example, server system 801 may include one or more hard disk drives as storage device 834. In other embodiments, storage device 834 is external to server system 801 and may be accessed by a plurality of server systems 801. For example,  storage device 834 may include multiple storage units such as hard disks or solid-state disks in a redundant array of inexpensive disks (RAID) configuration. Storage device 834 may include a storage area network (SAN) and / or a network attached storage (NAS) system.

[0103] In some embodiments, processor 805 is operatively coupled to storage device 834 via a storage interface 820. Storage interface 820 is any component capable of providing processor 805 with access to storage device 834. Storage interface 820 may include, for example, an Advanced Technology Attachment (ATA) adapter, a Serial ATA (SATA) adapter, a Small Computer System Interface (SCSI) adapter, a RAID controller, a SAN adapter, a network adapter, and / or any component providing processor 805 with access to storage device 834.

[0104] Memory area 810 may include, but are not limited to, random access memory (RAM) such as dynamic RAM (DRAM) or static RAM (SRAM) , read-only memory (ROM) , erasable programmable read-only memory (EPROM) , electrically erasable programmable read-only memory (EEPROM) , and non-volatile RAM (NVRAM) . The above memory types are examples only and are thus not limiting as to the types of memory usable for storage of a computer program.

[0105] Figure 9 is a flow diagram of an example process 900 for accessing an application using the edge computing systems 100, 200, and 300 (shown in Figures 1, 2, and 3) . In the exemplary embodiment, process 900 is performed by the edge computing platform (ECP) 105 (shown in Figure 1) .

[0106] In the exemplary embodiment, the ECP 105 executes 905 a plurality of applications including a first application 140 and a second application 145 (both shown in Figure 1) .

[0107] In the exemplary embodiment, the ECP 105 executes 910 a crypto server 125 (shown in Figure 1) in communication with the plurality of applications. The crypto server 125 stores a plurality of credential information for the plurality of applications. The crypto server 125 is in communication with a dominant key ring 135 (shown in Figure 1) . The crypto server 125 stores the plurality of  credential information for the plurality of applications in the dominant key ring 135. In at least one embodiment, the crypto server 125 and the plurality of applications are executed on the same physical edge computing device 105.

[0108] In the exemplary embodiment, the ECP 105 receives 915, from the first application 140, an access request to access the second application 145. The access request includes at least one identifier for the first application 140, such as, but not limited to, the VM UUID and the USER ID. The ECP 105 denies the access request if the validation of the at least one identifier for the first application fails.

[0109] In the exemplary embodiment, the ECP 105 determines 920 whether the second application 145 includes credential information for the first application 140.

[0110] If the determination is that the second application 145 includes credential information for the first application 140, the ECP 105 permits 925 communication between the first application 140 and the second application 145.

[0111] If the determination is that the second application 145 does not include credential information for the first application 140, the ECP 105 transmits 930, from the second application 145 to the crypto server 125, a credential request for credential information for the first application 140. The credential request includes the at least one identifier for the first application 140, such as, but not limited to, the VM UUID and the USER ID. The crypto server 125 validates the credential request based upon the at least one identifier of the first application 140. The ECP 105 denies the credential request if the crypto server 125 does not validate the credential request.

[0112] Upon validating the credential request, the ECP 105 transmits 935, from the crypto server 125 to the second application 145, the credential information for the first application 140. In some embodiments, the ECP 105 encrypts the credential information for the first application with a public key for the second application prior to transmitting to the second application. In some further embodiments, the ECP 105 transmits a public key for the second application 145 to the  first application 140 after receiving the credential information for the first application 140.

[0113] Then the ECP 105 permits 940 communication between the first application 140 and the second application 145.

[0114] In some further embodiments, the ECP 105 receives registration information from the first application 140. The registration information for the first application 140 includes the credential information for the first application 140. The ECP 105 validates the registration information for the first application 140. The ECP 105 stores the registration information for the first application 140 in the dominant key ring 135. The ECP 105 retrieves credential information for the crypto server 125 from the dominant key ring 135. The ECP 105 transmits the credential information for the crypto server 125 to the first application 140. The ECP 105 stores the credential information for the crypto server 125 in a local key ring 155 (shown in Figure 1) in communication with the first application 140.

[0115] In additional embodiments, the ECP 105 executes the first application 140 in a first virtual machine 115 (shown in Figure 1) . The ECP 105 executes the crypto server 125 in a hypervisor 110 (shown in Figure 1) in communication with the first virtual machine 115. In some embodiments, the ECP 105 executes the second application 145 in the first virtual machine 115. In other embodiments, the ECP 105 executes the second application 145 in a second virtual machine 120 (shown in Figure 1) . In even further embodiments, the ECP 105 executes a third application 150 (shown in Figure 1) of the plurality of applications in the hypervisor 110.

[0116] While the above describes the secure edge computing system being used for processing transactions and / or other data messages, one having skill in the art would understand that other implementations may be used as well. For a non-limited example, the secure edge computing system may be used to analyze transactions and / or message to determine one or more other trends and / or patterns. Further implementations include, but are not limited to, real-time transaction message  encryption including processing and storing real-time transactions in a temp system file for timeout control with ephemeral encryption keys; real-time transaction message transcription that is a sensitive function to support user onboarding, where the messages may be encrypted during the transcription process; Authentication / Authorization via REST API calls from one or more operational consoles; Authentication / Authorization between applications among Virtual Machines and / or the Hypervisor which supports traffic routing between different virtual machines in one physical server; secure storage of secrets to provide encryption functions for other applications running on the same server, where multiple encryption keys may be stored; and / or authentication among edge services where the authentication solution could be used for authentication between TCP Proxy and TCP when establishing a TCP connection. The systems could also be used for analyzing other data stored within a data database; data that is not necessarily related to financial transactions. The system should not be limited to such applications.

[0117] As used herein, the term “non-transitory computer-readable media” is intended to be representative of any tangible computer-based device implemented in any method or technology for short-term and long-term storage of information, such as, computer-readable instructions, data structures, program modules and sub-modules, or other data in any device. Therefore, the methods described herein may be encoded as executable instructions embodied in a tangible, non-transitory, computer readable medium, including, without limitation, a storage device and / or a memory device. Such instructions, when executed by a processor, cause the processor to perform at least a portion of the methods described herein. Moreover, as used herein, the term “non-transitory computer-readable media” includes all tangible, computer-readable media, including, without limitation, non-transitory computer storage devices, including, without limitation, volatile and nonvolatile media, and removable and non-removable media such as a firmware, physical and virtual storage, CD-ROMs, DVDs, and any other digital source such as a network or the Internet, as well as yet to be developed digital means, with the sole exception being a transitory, propagating signal.

[0118] This written description uses examples to disclose the disclosure, including the best mode, and also to enable any person skilled in the art to  practice the embodiments, including making and using any devices or systems and performing any incorporated methods. The patentable scope of the disclosure is defined by the claims, and may include other examples that occur to those skilled in the art. Such other examples are intended to be within the scope of the claims if they have structural elements that do not differ from the literal language of the claims, or if they include equivalent structural elements with insubstantial differences from the literal language of the claims.

Claims

1.A system for secure edge computing comprising:a memory device; andat least one processor coupled to the memory device, the at least one processor programmed to:execute a plurality of applications including a first application and a second application;execute a crypto server in communication with the plurality of applications, wherein the crypto server stores a plurality of credential information for the plurality of applications;receive, from the first application, an access request to access the second application;determine whether the second application includes credential information for the first application; andif the determination is that the second application does not include credential information for the first application, the at least one processor is programmed to:transmit, from the second application to the crypto server, a credential request for credential information for the first application;upon validating the credential request, transmit, from the crypto server to the second application, the credential information for the first application; andpermit communication between the first application and the second application.2.The system of Claim 1, if the determination is that the second application includes credential information for the first application, wherein the at least one processor is further programmed to permit communication between the first application and the second application.3.The system of Claim 1, wherein the access request includes at least one identifier for the first application.4.The system of Claim 3, wherein the credential request includes the at least one identifier for the first application.5.The system of Claim 4, wherein the crypto server validates the credential request based upon the at least one identifier of the first application.6.The system of Claim 5, wherein the at least one processor is further programmed to deny the credential request if the crypto server does not validate the credential request.7.The system of Claim 3, wherein the at least one processor is further programmed to deny the access request if the validation of the at least one identifier for the first application fails.8.The system of Claim 1, wherein the at least one processor is further programmed to encrypt the credential information for the first application with a public key for the second application prior to transmitting to the second application.9.The system of Claim 1, wherein the at least one processor is further programmed to transmit a public key for the second application to the first application after receiving the credential information for the first application.10.The system of Claim 1, wherein the crypto server is in communication with a dominant key ring, wherein the crypto server stores the plurality of credential information for the plurality of applications in the dominant key ring.11.The system of Claim 10, wherein the at least one processor is further programmed to:receive registration information from the first application, wherein the registration information for the first application includes the credential information for the first application;validate the registration information for the first application; andstore the registration information for the first application in the dominant key ring.12.The system of Claim 11, wherein the at least one processor is further programmed to:retrieve credential information for the crypto server from the dominant key ring; andtransmit the credential information for the crypto server to the first application.13.The system of Claim 12, wherein the at least one processor is further programmed to store the credential information for the crypto server in a local key ring in communication with the first application.14.The system of Claim 1, wherein the at least one processor is further programmed to:execute the first application in a first virtual machine; andexecute the crypto server in a hypervisor in communication with the first virtual machine.15.The system of Claim 14, wherein the at least one processor is further programmed to execute the second application in the first virtual machine.16.The system of Claim 14, wherein the at least one processor is further programmed to execute the second application in a second virtual machine.17.The system of Claim 14, wherein the at least one processor is further programmed to execute a third application of the plurality of applications in the hypervisor.18.The system of Claim 1, wherein the crypto server and the plurality of applications are executed on the same physical edge computing device.19.A computer-implemented method for secure edge computing, the method implemented on a computing device comprising a memory device coupled to at least one processor, and the method comprises:executing a plurality of applications including a first application and a second application;executing a crypto server in communication with the plurality of applications, wherein the crypto server stores a plurality of credential information for the plurality of applications;receiving, from the first application, an access request to access the second application;determining whether the second application includes credential information for the first application; andif the determination is that the second application does not include credential information for the first application, the method further comprises:transmitting, from the second application to the crypto server, a credential request for credential information for the first application;upon validating the credential request, transmitting, from the crypto server to the second application, the credential information for the first application; andpermitting communication between the first application and the second application.20.At least one non-transitory computer-readable storage media having computer-executable instructions embodied thereon for secure edge computing, wherein when executed by at least one processor, the computer-executable instructions cause at least one processor to:execute a plurality of applications including a first application and a second application;execute a crypto server in communication with the plurality of applications, wherein the crypto server stores a plurality of credential information for the plurality of applications;receive, from the first application, an access request to access the second application;determine whether the second application includes credential information for the first application; andif the determination is that the second application does not include credential information for the first application, the computer-executable instructions cause the at least one processor to:transmit, from the second application to the crypto server, a credential request for credential information for the first application;upon validating the credential request, transmit, from the crypto server to the second application, the credential information for the first application; andpermit communication between the first application and the second application.

Citation Information

Patent Citations

  • Application access method and device, electronic equipment and storage medium

    CN111064757A

  • Edge service obtaining method, server and edge device

    CN113285932A

  • Apparatus and method for providing mobile edge computing services in wireless communication system

    CN113796111A

  • Security authentication method, device and system

    CN116346435A

  • Login method and device of application system, storage medium and electronic device

    CN116389068A