Edge Computing Security State Transfer and Traffic Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Edge computing environments face vulnerabilities due to the lack of dynamic security information transfer between application instances, leaving new instances vulnerable to known attacks, and conventional security procedures fail to automatically apply the current security state of one instance to another.
Innovation Solution
Systems and methods for dynamically transferring the security state of a first application instance to a second instance, including dynamic security information retrieval and application, network traffic redirection, and multi-stage network traffic filtering to enhance security in edge computing environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dynamic security features are applied to application instances in edge computing environments, then security protection is improved, but the complexity of managing and transferring security state between instances increases
Solution Approach 1:
The patent implements copying by creating a security state object that captures the security features of a first application instance and transferring this copy to a second applicationinstance. This allows the security state to be replicated without manually copying individual security features, reducing management complexity while maintaining comprehensive protection.
Solution Approach 2:
The patent introduces a security state object as an intermediary that mediates between different application instances. This intermediary encapsulates the security state information and facilitates its transfer, abstracting the complexity of security feature management from the application instances themselves.
2Stability of the object's composition
If security features are dynamically transferred between application instances, then security consistency is improved, but the time required for security state transfer increases
Solution Approach 1:
The patent implements preliminary action by pre-defining the security state object structure and preparing the transfer mechanism before actual security state transfer is needed. The security state object is designed in advance to capture all necessary security features, enabling rapid transfer when required without delays from ad-hoc feature identification.
Solution Approach 2:
By using a structured copy of the security state object, the patent enables efficient serialization and transmission of security state information. The pre-defined object structure allows for optimized copying operations that minimize transfer time while ensuring complete and accurate replication of security features.
3Reliability
If multi-stage network traffic filtering is implemented, then security filtering capability is improved, but the processing overhead and system resources required increase
Solution Approach 1:
The patent implements segmentation by dividing the security filtering process into multiple stages handled by different components. The security state object is processed in stages: first capturing security features, then transferring the state, and finally applying filters. This segmentation allows each stage to be optimized independently, reducing overall processing overhead.
Solution Approach 2:
The patent applies local quality by implementing security filtering at different levels (network level, application level, data level) with appropriate filtering strategies for each stage. The multi-stage approach allows lightweight filtering at early stages and more intensive filtering only when necessary, optimizing resource consumption.
Data Source
AI summary
Examples of the present disclosure describe systems and methods for providing enhanced security in edge computing environments. A first aspect describes a method for moving security features dynamically applied to an application at a first deployment location to an application at a second deployment location. A second aspect describes a method for locally expanding/contracting an instance of a deployed application. A third aspect describes a method for redirected network traffic associated with detected malicious conduct from a first application deployment environment to a secured second application deployment environment. A fourth aspect describes a method for performing multi-stage network traffic filtering.


