Domain-to-Domain Interface Scrambling for Edge Computing Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In edge computing and IoT environments, protecting proprietary hardware and software intellectual property is challenging due to the difficulty in separating and securing proprietary content from different tenants in shared platforms, especially where trust boundaries differ and communication is non-uniform, leading to risks of intrusion and unauthorized disclosure.
Innovation Solution
Implementing domain-to-domain scrambling of communication interfaces using salt values and authentication tokens to control exposure and access, enabling secure interaction between chiplets and models from different vendors while maintaining proprietary content protection throughout the lifecycle, and using dynamic linkers for address resolution across domains to obscure proprietary information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If tenants share edge computing resources to execute services and applications, then productivity and resource utilization are improved, but security and confidentiality of proprietary intellectual property deteriorate
Solution Approach 1:
The patent segments the shared edge computing platform into isolated execution environments (containers or virtual machines) for each tenant. Each tenant's proprietary code and data are confined to their own execution environment, preventing access to other tenants' resources while allowing shared infrastructure utilization. This segmentation resolves the contradiction by enabling both high resource utilization through sharing and strong security through isolation.
Solution Approach 2:
The patent introduces an intermediary layer (platform executable or runtime environment) that mediates between tenants' proprietary code and the shared hardware resources. This intermediary controls and monitors all interactions, ensuring that tenants can utilize shared resources productively while the intermediary maintains security boundaries and prevents unauthorized access to proprietary intellectual property.
2Reliability
If tenants maintain separability of proprietary technology, then security and confidentiality are improved, but device complexity and integration difficulty worsen
Solution Approach 1:
The patent implements a universal execution environment that can host multiple tenants' proprietary code with different security requirements. The same platform infrastructure and isolation mechanisms serve all tenants simultaneously, providing confidentiality protection without requiring separate physical systems for each tenant. This universality reduces integration complexity while maintaining strong separability and confidentiality.
3Ease of operation
If communication interfaces are exposed for integration, then ease of operation and collaboration are improved, but risk of unauthorized access and intrusion worsens
Solution Approach 1:
The patent applies different security qualities to different communication interfaces based on their exposure level and sensitivity. Critical interfaces that access proprietary data maintain strong isolation and authentication, while less sensitive interfaces used for standard collaboration can have more permissive access controls. This localized application of security measures enables easy operation for non-critical functions while protecting against intrusion risks for sensitive operations.
Data Source
Figure 1
Figure 2
Figure 3A~3B
AI summary
Methods, apparatus, systems, and articles of manufacture to protect proprietary functionality and/or other content in hardware and software are disclosed. An example computer apparatus includes; a first circuit including a first interface, the first circuit associated with a first domain; a second circuit including a second interface, the second circuit associated with a second domain; and a chip manager to generate a first authenticated interface for the first interface using a first token and to generate a second authenticated interface for the second interface using a second token to enable communication between the first authenticated interface and the second authenticated interface.