Edge Proxy Service Mesh for Heterogeneous Endpoint Connectivity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Secure inter-service communication in hierarchical edge computing platforms is challenging due to diversity in runtime execution environments and limited compute and storage resources at endpoints, particularly in IoT gateways.
Innovation Solution
A hierarchical edge computing platform with an edge orchestrator, edge proxy, and service mesh using FIDO-device-onboard protocol for secure routing and authentication, along with a downstream connectivity module that securely couples distributed endpoints to a mesh communication tunnel, enabling secure service-to-service communication across the edge estate.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a conventional service mesh is extended to distributed heterogeneous endpoints, then service-to-service communication coverage is improved, but device complexity and difficulty of implementation increase due to diversity in runtime execution environments
Solution Approach 1:
The patent introduces a service gateway as an intermediary component that sits between the conventional service mesh and heterogeneous distributed endpoints. This gateway acts as a mediator that translates and adapts service mesh protocols to work across diverse runtime environments including IoT gateways, edge servers, and cloud platforms, thereby extending service mesh coverage without directly complicating each endpoint's implementation
Solution Approach 2:
The service gateway is designed with multi-functional capabilities to handle various runtime execution environments uniformly. It provides universal support for different endpoint types (IoT gateways, edge servers, cloud platforms) through a single standardized interface, allowing the service mesh to communicate with heterogeneous endpoints without requiring separate implementation approaches for each device type
2Reliability
If security protocols such as FIDO-device-onboard are implemented across all endpoints, then authentication security is improved, but compute and storage resource consumption increases at resource-constrained devices
Solution Approach 1:
The service gateway serves as a security intermediary that handles complex FIDO-device-onboard authentication protocols. Instead of requiring resource-constrained endpoints to directly execute heavy cryptographic operations, the gateway performs these security functions centrally, allowing endpoints to authenticate with minimal local computational overhead while maintaining strong security guarantees
Solution Approach 2:
The implementation uses partial action by selectively applying full FIDO security protocols only where necessary (at the service gateway level), while allowing resource-constrained endpoints to use lighter-weight authentication mechanisms. This partial application of security measures maintains overall system security while reducing resource consumption at constrained devices
3Reliability
If secure routing based on edge estate data and ownership authorization is implemented, then communication security is improved, but processing time and operational complexity increase
Solution Approach 1:
The system performs preliminary action by pre-establishing security policies, ownership authorizations, and routing rules during service registration and onboarding phases. Edge estate data and authorization credentials are cached and validated in advance, so that during actual service communication, the service gateway can make rapid routing decisions based on pre-validated security contexts rather than performing full security checks in real-time
Data Source
AI summary
A disclosed edge computing platform includes an edge orchestrator (EO) and one or more distributed endpoints. The EO includes an edge proxy, an edge control plane resource, and a service mesh. The service mesh includes a plurality of services, each of which is paired with a corresponding Envoy proxy. The edge proxy communicatively couples the service mesh to a mesh communication tunnel. The edge control plane resource is configured to enable secure routing based on edge estate data maintained in an external store and ownership authorization data in accordance with a suitable authentication technology (e.g. FDO). Each distributed endpoint includes a downstream connectivity module (DCM) including a DCM proxy coupling the distributed endpoint to the mesh communication tunnel. The distributed endpoints may include edge compute endpoints and external compute fabrics. Disclosed teachings enable secure service-to-service communication across the entire edge estate irrespective of types and location of services.


