Edge Device Grouping With Virtual PSKs for Secure Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional edge applications often have unique requirements that differ from cloud or monolithic architectures, necessitating improved methods for device detection, connection, and network management in edge computing systems.
Innovation Solution
The system employs a processor to detect and authenticate devices using a common pre-shared key (PSK), form groups based on predefined criteria, create secure subnetworks, assign virtual pre-shared keys (vPSKs) dynamically, and manage network slices to optimize device capabilities and service requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If devices are authenticated using a common pre-shared key and grouped together, then network security is enhanced through isolation, but device complexity increases due to the need for group formation and key management
Solution Approach 1:
The patent segments devices into distinct groups based on predefined criteria (device type, service plan, subscription level) and assigns different virtual pre-shared keys to each group. This segmentation enables isolated authentication and communication channels for different device groups, enhancing network security while managing complexity through structured organization.
Solution Approach 2:
The patent dynamically changes authentication parameters by assigning virtual pre-shared keys (vPSKs) based on device capabilities and service requirements. The system can reassign vPSKs dynamically or statically depending on real-time service requirements and usage patterns, allowing flexible security management without increasing operational complexity.
2Reliability
If subnetworks are created for each subscriber, then network isolation and security are improved, but scalability is reduced due to the number of separate networks to manage
Solution Approach 1:
The patent creates a universal authentication and management system that handles multiple subscribers and device types through a single edge computing system. The system uses common pre-shared keys and virtual pre-shared keys that can be applied across different subscriber groups, enabling the same infrastructure to serve multiple purposes without requiring separate dedicated networks for each subscriber.
Solution Approach 2:
The patent uses virtual pre-shared keys that can be copied and assigned to different devices and groups without creating separate physical networks. The vPSK mechanism allows the system to replicate security configurations across multiple subscribers and device types, maintaining network isolation while improving scalability through virtual rather than physical duplication.
3Productivity
If virtual pre-shared keys are assigned dynamically based on service requirements, then resource allocation efficiency is improved, but authentication time increases due to capability analysis and key assignment processes
Solution Approach 1:
The patent performs preliminary actions by pre-defining criteria for device grouping and pre-configuring virtual pre-shared keys in the edge computing system memory. Devices are pre-categorized by type, service plan, and subscription level, allowing the system to quickly assign appropriate vPSKs without performing complex analysis during authentication. This preliminary preparation enables dynamic resource allocation while minimizing authentication time.
Solution Approach 2:
The patent implements feedback mechanisms where the edge computing system analyzes device capabilities and service requirements, then provides feedback in the form of appropriate virtual pre-shared key assignments. The system continuously monitors device performance and service usage, allowing for dynamic reassignment of vPSKs to optimize resource allocation while maintaining efficient authentication processes through learned patterns and preferences.
Data Source
AI summary
A method for establishing connections and forming groups in an edge computing system includes detecting and identifying devices attempting to connect to the network using a processor. The method involves authenticating detected devices with a common pre-shared key (PSK) stored in memory, forming groups of connected devices based on predefined criteria, and sharing the PSK within each group via a secured channel. It also includes creating a subnetwork or private LAN for each subscriber using network configuration data, assigning virtual pre-shared keys (vPSKs) to devices based on service requirements, determining device capabilities by analyzing received device-specific information, and identifying supported applications based on device capabilities and application compatibility data stored in memory.


