Mobile Edge-Cloud Security Infrastructure for Latency and Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing demand for data processing in augmented reality (AR) and virtual reality (VR) applications, particularly with 5G and Mobile Edge Computing (MEC) technologies, leads to network congestion and latency issues, as numerous devices generate significant traffic, causing costs and performance problems for wireless carriers.
Innovation Solution
Implementing a mobile edge-cloud security infrastructure with hardware-based security components like Trusted Execution Environment (TEE), Hardware Security Module (HSM), and Software Guard Extensions (SGX) to securely separate and manage workloads across multiple security domains, ensuring efficient and secure data processing and storage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Power
If traffic is backhauled to the EPC for processing, then data processing capability is improved, but network latency increases and network costs increase
Solution Approach 1:
The patent segments the centralized EPC processing function into distributed edge computing nodes deployed at multiple edge locations closer to end devices. This segmentation allows data processing to occur locally at the edge rather than being backhauled to a centralized EPC, thereby reducing network latency while maintaining processing capability through distributed architecture
Solution Approach 2:
The patent introduces a spatial dimension by deploying computing resources across multiple geographic edge locations rather than concentrating them at a single centralized EPC. This dimensional transformation enables data processing to occur at edge locations nearest to data sources, reducing the physical distance data must travel and thus reducing latency
2Productivity
If more network resources are allocated to handle increased traffic, then data processing capability is improved, but network costs increase
Solution Approach 1:
The patent applies local quality by deploying computing resources with appropriate capabilities at specific edge locations based on local demand characteristics. Rather than uniformly allocating resources across the entire network, each edge node provides processing power tailored to its local traffic patterns and requirements, optimizing resource utilization and reducing overall network costs
Solution Approach 2:
The patent enables edge computing nodes to autonomously process and handle their own local data processing requirements without requiring additional centralized network resources. Each edge node independently manages its workload, reducing the need for extra network capacity and lowering overall network operational costs
3Productivity
If multiple workloads are hosted on the same hardware platform, then resource utilization is improved, but security risks increase due to potential cross-contamination
Solution Approach 1:
The patent introduces hardware-based security modules and virtualization layers as intermediaries between multiple workloads sharing the same physical hardware platform. These intermediary components provide isolation boundaries that prevent cross-contamination between workloads while allowing them to coexist on the same hardware, thus maintaining both high resource utilization and strong security
Solution Approach 2:
The patent implements a nested architecture where multiple isolated virtual environments or containers are nested within a single physical hardware platform. Each nested layer provides security boundaries, allowing workloads to be densely packed on shared hardware while maintaining isolation through hierarchical structuring similar to nested dolls
Data Source
AI summary
System and techniques for multifactor intelligent agent control are described herein. A workload request may be received from a user device via a network. The workload may be instantiated in an isolated environment on an edge computing platform. Here, the isolated environment may be a container or a virtual machine. The instantiation of the workload may include using a hardware security component (SEC) of the mobile edge computing platform to prevent access to data or code of the workload from other environments hosted by the mobile edge computing platform. The workload may then be executed in the isolated environment and a result of the workload returned to the user device.


