Mobile Edge-Cloud Security Infrastructure for Latency and Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing demand for data processing in augmented reality (AR) and virtual reality (VR) applications, particularly with 5G and Mobile Edge Computing (MEC) technologies, leads to network congestion and latency issues, as numerous devices generate significant traffic, causing costs and performance problems for wireless carriers.

Innovation Solution

Implementing a mobile edge-cloud security infrastructure with hardware-based security components like Trusted Execution Environment (TEE), Hardware Security Module (HSM), and Software Guard Extensions (SGX) to securely separate and manage workloads across multiple security domains, ensuring efficient and secure data processing and storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Power

If traffic is backhauled to the EPC for processing, then data processing capability is improved, but network latency increases and network costs increase

Engineering Contradiction:
Improvedata processing capabilityVSAvoidnetwork latency
Core Design Contradiction:
PowerVSLoss of time

Solution Approach 1:

The patent segments the centralized EPC processing function into distributed edge computing nodes deployed at multiple edge locations closer to end devices. This segmentation allows data processing to occur locally at the edge rather than being backhauled to a centralized EPC, thereby reducing network latency while maintaining processing capability through distributed architecture

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a spatial dimension by deploying computing resources across multiple geographic edge locations rather than concentrating them at a single centralized EPC. This dimensional transformation enables data processing to occur at edge locations nearest to data sources, reducing the physical distance data must travel and thus reducing latency

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If more network resources are allocated to handle increased traffic, then data processing capability is improved, but network costs increase

Engineering Contradiction:
Improvedata processing capabilityVSAvoidnetwork costs
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent applies local quality by deploying computing resources with appropriate capabilities at specific edge locations based on local demand characteristics. Rather than uniformly allocating resources across the entire network, each edge node provides processing power tailored to its local traffic patterns and requirements, optimizing resource utilization and reducing overall network costs

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent enables edge computing nodes to autonomously process and handle their own local data processing requirements without requiring additional centralized network resources. Each edge node independently manages its workload, reducing the need for extra network capacity and lowering overall network operational costs

Inventive Principle:
Principle #25Self-service

3Productivity

If multiple workloads are hosted on the same hardware platform, then resource utilization is improved, but security risks increase due to potential cross-contamination

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces hardware-based security modules and virtualization layers as intermediaries between multiple workloads sharing the same physical hardware platform. These intermediary components provide isolation boundaries that prevent cross-contamination between workloads while allowing them to coexist on the same hardware, thus maintaining both high resource utilization and strong security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a nested architecture where multiple isolated virtual environments or containers are nested within a single physical hardware platform. Each nested layer provides security boundaries, allowing workloads to be densely packed on shared hardware while maintaining isolation through hierarchical structuring similar to nested dolls

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS10884814B2Mobile edge-cloud security infrastructure
Publication Date: 2021.01.05 INTEL CORP
  • US10884814B2 patent drawing
  • US10884814B2 patent drawing
  • US10884814B2 patent drawing

AI summary

System and techniques for multifactor intelligent agent control are described herein. A workload request may be received from a user device via a network. The workload may be instantiated in an isolated environment on an edge computing platform. Here, the isolated environment may be a container or a virtual machine. The instantiation of the workload may include using a hardware security component (SEC) of the mobile edge computing platform to prevent access to data or code of the workload from other environments hosted by the mobile edge computing platform. The workload may then be executed in the isolated environment and a result of the workload returned to the user device.