Edge Device Grouping With Virtual PSKs for Secure Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional edge applications often have unique requirements that differ from cloud or monolithic architectures, necessitating improved methods for device detection, connection, and network management in edge computing systems.

Innovation Solution

The system employs a processor to detect and authenticate devices using a common pre-shared key (PSK), form groups based on predefined criteria, create secure subnetworks, assign virtual pre-shared keys (vPSKs) dynamically, and manage network slices to optimize device capabilities and service requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If devices are authenticated using a common pre-shared key and grouped together, then network security is enhanced through isolation, but device complexity increases due to the need for group formation and key management

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments devices into distinct groups based on predefined criteria (device type, service plan, subscription level) and assigns different virtual pre-shared keys to each group. This segmentation enables isolated authentication and communication channels for different device groups, enhancing network security while managing complexity through structured organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent dynamically changes authentication parameters by assigning virtual pre-shared keys (vPSKs) based on device capabilities and service requirements. The system can reassign vPSKs dynamically or statically depending on real-time service requirements and usage patterns, allowing flexible security management without increasing operational complexity.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If subnetworks are created for each subscriber, then network isolation and security are improved, but scalability is reduced due to the number of separate networks to manage

Engineering Contradiction:
Improvenetwork isolationVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal authentication and management system that handles multiple subscribers and device types through a single edge computing system. The system uses common pre-shared keys and virtual pre-shared keys that can be applied across different subscriber groups, enabling the same infrastructure to serve multiple purposes without requiring separate dedicated networks for each subscriber.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses virtual pre-shared keys that can be copied and assigned to different devices and groups without creating separate physical networks. The vPSK mechanism allows the system to replicate security configurations across multiple subscribers and device types, maintaining network isolation while improving scalability through virtual rather than physical duplication.

Inventive Principle:
Principle #26Copying

3Productivity

If virtual pre-shared keys are assigned dynamically based on service requirements, then resource allocation efficiency is improved, but authentication time increases due to capability analysis and key assignment processes

Engineering Contradiction:
Improveresource allocation efficiencyVSAvoidauthentication time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-defining criteria for device grouping and pre-configuring virtual pre-shared keys in the edge computing system memory. Devices are pre-categorized by type, service plan, and subscription level, allowing the system to quickly assign appropriate vPSKs without performing complex analysis during authentication. This preliminary preparation enables dynamic resource allocation while minimizing authentication time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the edge computing system analyzes device capabilities and service requirements, then provides feedback in the form of appropriate virtual pre-shared key assignments. The system continuously monitors device performance and service usage, allowing for dynamic reassignment of vPSKs to optimize resource allocation while maintaining efficient authentication processes through learned patterns and preferences.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12549458B2Methods and systems for micro edge applications and grouping
Publication Date: 2026.02.10 VEEA INC
  • US12549458B2 patent drawing
  • US12549458B2 patent drawing
  • US12549458B2 patent drawing

AI summary

A method for establishing connections and forming groups in an edge computing system includes detecting and identifying devices attempting to connect to the network using a processor. The method involves authenticating detected devices with a common pre-shared key (PSK) stored in memory, forming groups of connected devices based on predefined criteria, and sharing the PSK within each group via a secured channel. It also includes creating a subnetwork or private LAN for each subscriber using network configuration data, assigning virtual pre-shared keys (vPSKs) to devices based on service requirements, determining device capabilities by analyzing received device-specific information, and identifying supported applications based on device capabilities and application compatibility data stored in memory.