Edge Computing Node Identity Obfuscation for Topology Hiding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the context of edge computing, wireless communication service providers face challenges in maintaining the confidentiality of their edge computing network topology while enabling seamless access to edge computing services for user equipment (UE) across different carrier networks.
Innovation Solution
The proposed solution involves using obfuscated identities for edge computing nodes, which can be hashed or encrypted values. These obfuscated identities are periodically changed to prevent inference of the node's location, allowing UE to evaluate and select the best network for application layer connections based on performance metrics without exposing the underlying network topology.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If edge computing node identities are made visible for network access, then UE can establish connections and evaluate network performance, but network topology confidentiality is compromised
Solution Approach 1:
The patent introduces an intermediary mechanism where edge computing node identities are obfuscated using hashing or encryption. The home network acts as a mediator that receives service requests, translates obfuscated identities into actual node identifiers, and establishes connections without exposing the real network topology to UEs or foreign networks. This resolves the contradiction by enabling access while protecting confidentiality through the intermediary translation layer.
Solution Approach 2:
The patent transforms the identity parameter of edge computing nodes from visible, human-readable identifiers into obfuscated forms (hashed or encrypted values). This parameter change allows the system to maintain functional equivalence for connection purposes while fundamentally altering the information state to protect network topology. The obfuscated identity serves as a functional substitute that preserves access capability while eliminating topological exposure.
2Adaptability or versatility
If edge computing node locations are exposed for service access, then inter-carrier access is enabled, but security and privacy are reduced
Solution Approach 1:
The patent creates a virtual copy of the edge computing node identity system where obfuscated identifiers (hashed or encrypted versions) serve as functional duplicates of real node identities. These copied identities enable inter-carrier access and service discovery without replicating the sensitive location information. The copy allows versatility in access while the original confidential information remains protected.
3Device complexity
If real edge computing node identities are used, then direct connection establishment is simplified, but network topology can be inferred and exposed
Solution Approach 1:
The patent employs an intermediary translation mechanism where the home network receives connection requests containing obfuscated identities, translates them into real node identifiers, and establishes connections. This intermediary process adds minimal complexity to the user-facing interface while providing robust protection against topology inference. The complexity is shifted from the UE side to the network side, where it can be managed centrally and securely.
Data Source
AI summary
A method of establishing an application layer connection between a user equipment (UE) and an application executing on an edge computing node via a communication network. The method comprises receiving an application service availability message by the UE that identifies a plurality of networks that provide access to an identified application executing on an edge computing node within the network; for each network identified in the application service availability message, receiving by the UE an application service figure-of-merit determined by that network associated with a prospective application layer connection between the UE and an edge computing node executing the identified application that is located in that network; based on evaluating the figure-of-merit associated with each network establishing an application layer connection by the UE via the selected network to the application executing on the edge computing node in the selected network.


