Edge Application Migration via Direct Host-to-Host Context Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing edge computing technologies rely on centralized processing by an orchestrator, exposing application and user information, leading to security concerns for service providers.
Innovation Solution
The method and apparatus for transferring edge computing applications involve direct communication between edge computing hosts, allowing user context information to pass through without exposure to the orchestrator, enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If centralized processing by edge computing orchestrator is used, then application transfer control is simplified, but application information and user information security deteriorates
Solution Approach 1:
The patent segments the information transfer path by introducing encrypted channels that isolate sensitive application information and user information from the orchestrator. The orchestrator only receives encrypted identifiers and metadata, while the actual sensitive data is segmented into separate encrypted transmissions between edge computing hosts directly, preventing centralized exposure of sensitive information.
Solution Approach 2:
The patent introduces encryption algorithms and encrypted identifier mechanisms as intermediaries between the orchestrator and sensitive information. The orchestrator acts as a mediator for coordination but cannot access plaintext sensitive data, as the encryption layer serves as an intermediary that protects information while still enabling orchestrator-mediated resource allocation and transfer coordination.
2Productivity
If application information is exposed to orchestrator, then transfer coordination is improved, but service provider control and security deteriorates
Solution Approach 1:
The patent extracts sensitive information (application information and user information) from the data that is transmitted to the orchestrator. Only encrypted identifiers and non-sensitive metadata are extracted for transmission to the orchestrator, while the sensitive portions are taken out and transmitted through separate encrypted channels, allowing coordination without exposure of harmful information.
Solution Approach 2:
The patent changes the parameter of information representation by encrypting sensitive data and transforming it into encrypted identifiers. The orchestrator works with these transformed parameters (encrypted strings rather than plaintext information), maintaining coordination capability while changing the security parameter from exposed to protected.
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
Provided are a method and apparatus for transferring an edge computing application. The method includes: receiving, by a first edge computing application of a first edge computing host, a first message sent by an edge computing platform of the first edge computing host, where the first message includes edge computing application information of a second edge computing host; and sending, by the first edge computing application, a second message to a second edge computing application of the second edge computing host according to the edge computing application information of the second edge computing host, where the second message carries user context information. The transfer of an edge computing application is initiated by an edge computing application of an edge computing host, and user context information directly passes through between edge computing platforms of the edge computing hosts, so that the user context information will not be exposed to the edge computing platforms and an edge computing orchestrator, improving the security of the user context information.