Edge Computing Gateway Secure Container Framework

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional edge devices are resource-constrained and prone to resource poverty, limiting the type of applications they can run and experiencing peak demand issues, while existing container platforms require manual configuration and pose security vulnerabilities, especially in large-scale deployments.

Innovation Solution

The implementation of a secure container framework using licenses, labels, and secure containers within an edge computing gateway (ECG) that automates resource allocation and security management, allowing dynamic scaling and secure operation of applications at the edge without the need for manual sysadmin intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration is used for container platforms, then security control is maintained, but device complexity and operational burden increase significantly

Engineering Contradiction:
Improvesecurity controlVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables self-service through automated license validation, resource allocation, and security policy enforcement. The container manager automatically validates licenses against the license server, allocates resources based on predefined policies, and enforces security measures without requiring manual sysadmin intervention, thereby reducing operational burden while maintaining security control

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security policies, resource allocation rules, and license validation mechanisms are established in advance before container deployment. The system pre-configures access-control lists, defines resource quotas, and sets up security contexts, allowing containers to be deployed automatically without manual configuration while maintaining consistent security posture

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If resource-constrained edge devices are used, then deployment flexibility is improved, but productivity and application runtime are limited

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidapplication runtime productivity
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system dynamically allocates and manages resources based on real-time container needs and available hardware capacity. The license server dynamically issues and revokes access rights, the container manager dynamically assigns resources, and the system can dynamically adjust security policies, allowing resource-constrained devices to efficiently handle variable workloads while maintaining flexibility

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Instead of providing full resource access to all containers, the system applies partial resource allocation based on license terms and security policies. Resources are selectively granted only to authorized containers that meet predefined criteria, optimizing the use of constrained hardware while ensuring fair and secure resource distribution

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If security measures are implemented in container frameworks, then reliability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvecontainer securityVSAvoidcontainer deployment ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system introduces intermediary components including a license server that mediates between container managers and the central authorization system, and a container manager that acts as an intermediary between users and the hardware/resources. These intermediaries handle complex security validation and resource management automatically, presenting simplified interfaces to users while maintaining robust security measures

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Security contexts, access-control lists, and resource allocation policies are pre-established before container deployment. The system pre-validates licenses, pre-assigns security contexts, and pre-configures resource quotas, allowing containers to be deployed with minimal user input while automatically receiving appropriate security configurations without requiring users to manually configure security settings

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250016161A1Method and System for Secure Container Application Framework
Publication Date: 2025.01.09 VEEA INC
  • US20250016161A1 patent drawing
  • US20250016161A1 patent drawing
  • US20250016161A1 patent drawing

AI summary

An edge computing gateway (ECG) includes a processor configured to establish a distributed container network that includes a plurality of interconnected ECGs, each of which includes an orchestrator and containers. The processor may determine available resources on one or more additional ECGs in the distributed container network, select one of the additional ECGs in the distributed container network to run a container based on the available resources determined by the orchestrator of the ECG, and allocate resources from the selected ECG to execute the container. In response to changes in resource demands, the processor may dynamically reallocate resources between the ECG and the selected ECG to adjust container performance across the distributed container network.