Edge Multi-tenant Resource Management via Admission Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multi-tenant edge/cloud computing environments, existing resource management frameworks fail to effectively manage and control non-dominant resources, leading to potential bottlenecks and malicious exploitation, which can degrade performance and result in denial-of-service attacks.
Innovation Solution
An improved resource management framework incorporating Resilience Root of Trust (RRoT) and Differentiated Behavior Fingerprinting (DBF) for admission control, which monitors and balances dominant and non-dominant resource allocations using a hybrid centralized-distributed telemetry approach, and enforces lightweight monitoring and policy enforcement on distributed networking elements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If RMO framework only manages dominant resources, then resource allocation simplicity is maintained, but non-dominant resources become vulnerable to malicious exploitation
Solution Approach 1:
The patent segments resource management into two distinct components: dominant resource management (handled by existing RMO frameworks) and non-dominant resource management (handled by the new admission control mechanism). This segmentation allows each component to focus on specific resource types while maintaining overall system security without requiring complete redesign of the resource management architecture.
Solution Approach 2:
The patent introduces an admission control mechanism as an intermediary layer between job requests and non-dominant resources. This intermediary monitors resource allocation ratios, enforces policies, and prevents malicious exploitation of non-dominant resources while allowing legitimate workloads to access resources proportionally.
2Productivity
If non-dominant resources are left unmanaged, then resource allocation overhead is reduced, but malicious users can exploit these resources for attacks
Solution Approach 1:
The patent implements preliminary action by establishing admission control policies and monitoring mechanisms before malicious exploitation can occur. The system proactively tracks resource allocation ratios and prevents unauthorized access to non-dominant resources, rather than reacting to attacks after they happen.
Solution Approach 2:
The patent implements a feedback mechanism where the admission control continuously monitors resource allocation patterns, compares them against established policies, and adjusts resource allocation decisions in real-time. This feedback loop enables the system to detect and prevent malicious exploitation while maintaining efficient resource allocation for legitimate workloads.
3Reliability
If proportional allocation of non-dominant resources is enforced, then malicious exploitation is prevented, but resource management complexity increases
Solution Approach 1:
The patent applies parameter changes by introducing specific monitoring parameters (resource allocation ratios, policy thresholds) and control parameters (admission decisions, allocation limits) to the resource management system. These parameter-based controls enable automated enforcement of proportional allocation without requiring complex manual intervention or system redesign.
Data Source
AI summary
A resource management framework may be used to improve performance of dominant and non-dominant resources for edge multi-tenant applications. The resource management framework may include an admission control mechanism, which may be used to balance disproportionate resource allocations by controlling allocation of unconstrained resources proportional to the requested dominant resources based on resource availability. The admission control mechanism may provide ongoing monitoring of dominant and non-dominant resource utilization, such as using a hybrid centralized-distributed telemetry collection approach. The resource management framework may also include a lightweight resource monitoring and policy enforcement mechanism on distributed networking elements to reduce or eliminate the exploitations of non-dominant resources.


