Edge Device Secure Region Data Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Edge computing systems face security risks and high communication and calculation loads due to the large number of IoT devices, which can lead to data leakage or falsification, especially in critical applications like connected cars.
Innovation Solution
Implementing a data processing method where IoT devices store and process data in a secure region using Trusted Execution Environment (TEE) technology, reducing the data amount transmitted to the service provider server and ensuring irreversible data transmission, thereby enhancing security and reducing loads.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is processed and stored in a secure region with restricted access, then data security and prevention of falsification are improved, but device complexity and processing requirements increase
Solution Approach 1:
The patent divides the data processing system into distinct secure and non-secure regions within the edge device. The secure region (e.g., Trusted Execution Environment) is segmented to handle sensitive data processing isolated from the rest of the system, allowing security improvements without requiring the entire device to become more complex.
Solution Approach 2:
The patent introduces a secure region as an intermediary layer between data collection and external transmission. This intermediary handles security-critical operations (data processing, encryption) while maintaining simplicity in the overall system architecture by acting as a dedicated security buffer rather than permeating the entire device.
2Quantity of substance
If all collected data is transmitted to the service provider server, then data availability for processing is improved, but communication load and transmission time increase
Solution Approach 1:
The patent performs preliminary data processing and reduction actions at the edge device before transmission to the service provider server. By pre-processing data locally (filtering, aggregating, or transforming data), the system reduces the quantity of data that needs to be transmitted, thereby decreasing communication time while maintaining data availability for subsequent processing.
Solution Approach 2:
The patent extracts only the necessary data or processed results from the full dataset before transmission. Instead of transmitting all collected data, the system extracts and transmits only the essential information or processed outputs, reducing communication load while preserving data availability for service provider processing.
3Productivity
If data processing is performed at the edge device, then calculation load on service provider server is reduced, but security risks from physical attacks and data leakage increase
Solution Approach 1:
The patent segments data processing into two parts: simple processing at the edge device (improving productivity) and secure processing in the isolated secure region (mitigating security risks). This segmentation allows the edge device to perform beneficial local processing while containing security risks within a restricted, monitored environment that prevents data leakage and physical attack impacts.
4Reliability
If irreversible data processing is performed in secure region, then data protection against leakage is improved, but processing complexity and computational resources increase
Solution Approach 1:
The patent creates a copy or transformed version of the data within the secure region that maintains the necessary information for processing while being irreversible to external systems. This copying approach allows data protection through transformation rather than destruction, maintaining processing capability while achieving security goals without excessive complexity.
Data Source
AI summary
A data processing method is performed by an edge device acquiring collected data from a collection target and a first computer capable of communicating with the edge device. The method includes: a first calculation process of, by the edge device, storing the collected data in a secure region to which referring of internally stored information from outside is not allowable and calculating first data which has a data amount less than the collected data and is irreversible in the secure region based on the stored collected data; a first communication process of, by the edge device, transmitting the first data calculated through the first calculation process to the first computer; and a second calculation process of, by the first computer, calculating second data based on the first data transmitted from the edge device through the first communication process.


