Secure Multi-tenancy Framework for Edge Resource Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing edge environments lack a robust framework for secure multi-tenancy, leading to challenges in resource sharing, data privacy, and compliance with industry-specific regulations.

Innovation Solution

A comprehensive framework for secure multi-tenancy in edge environments, which includes resource isolation, access control, encryption, threat detection, and compliance adherence, ensuring secure sharing of resources and data privacy among multiple tenants.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If resources are shared among multiple tenants in edge environments, then resource utilization efficiency is improved, but security and data privacy are compromised

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidsecurity and data privacy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments resources into isolated tenant-specific allocations using virtualization techniques. Each tenant receives dedicated virtualized resources (compute, storage, network) that are logically separated through hypervisors or containerization, allowing shared physical infrastructure while maintaining security boundaries. This resolves the contradiction by enabling resource sharing without compromising security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a centralized management system as an intermediary between multiple tenants and edge resources. This system orchestrates resource allocation, enforces access control policies, and manages isolation mechanisms, thereby enabling secure multi-tenant resource sharing without direct tenant-to-tenant exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If resource isolation is implemented for multiple tenants, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs universal virtualization layers and standardized isolation mechanisms that can serve multiple tenants simultaneously. The same hypervisor or container runtime provides isolation for all tenants, reducing the need for tenant-specific complex configurations. The centralized management system further simplifies complexity by providing unified orchestration across all isolated resources.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If access control mechanisms are implemented, then data privacy is improved, but operational ease is reduced

Engineering Contradiction:
Improvedata privacyVSAvoidoperational ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service access control where the centralized management system automatically enforces privacy policies and manages access permissions based on predefined tenant configurations. The system autonomously handles authentication, authorization, and policy enforcement without requiring manual intervention for each access request, thereby maintaining data privacy while preserving operational ease.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250199868A1Secure multi-tenancy for edge environments
Publication Date: 2025.06.19 DELL PROD LP
  • US20250199868A1 patent drawing
  • US20250199868A1 patent drawing
  • US20250199868A1 patent drawing

AI summary

In a system for providing secure multi-tenancy including a plurality of edge nodes, and each edge node may receive, from a central management system, resource isolation instructions associated with a first tenant and a second tenant. In response, the edge node may allocate a first set of resources to the first tenant, and a second set of resources to the second tenant. The edge node may then process data associated with the first and second tenants using the assigned sets of resources.