Edge Server Selection for Privacy and Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computing systems face challenges in maintaining privacy and security over public networks, particularly due to the unrestrained discovery of edge servers by third-party entities, which can lead to interference and reduced quality of service.
Innovation Solution
An enhanced services network is implemented, utilizing a rule set to select edge servers that limit discoverability, minimize geographic and network distance, and establish more secure connections, ensuring privacy and security through client-side and resource-side edge servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If edge servers are made discoverable by third-party entities, then network accessibility and ease of connection are improved, but privacy and security are worsened due to interference and reduced quality of service
Solution Approach 1:
The patent introduces a rule set as an intermediary mechanism that mediates between edge servers and third-party entities. This rule set controls and filters interactions, allowing legitimate network accessibility while blocking harmful third-party interference. The rule set acts as a gatekeeper that selectively permits or denies access based on predefined security and privacy criteria.
Solution Approach 2:
The patent changes the operational parameters of edge servers by implementing selective discoverability. Instead of making all edge servers fully discoverable or completely hidden, the system dynamically adjusts discoverability parameters based on security requirements, client identity, and connection context. This allows the system to optimize between accessibility and security on a per-connection basis.
2Speed
If edge servers are selected to minimize geographic and network distance, then connection speed and latency are improved, but discoverability and potential interference are worsened
Solution Approach 1:
The patent applies local quality by implementing location-aware edge server selection that considers geographic proximity for performance optimization while applying different discoverability rules to different geographic regions or network zones. The rule set can configure edge servers in specific locations to have varying levels of discoverability based on local security requirements and trust levels.
Solution Approach 2:
The patent segments the edge server infrastructure into multiple groups with different discoverability characteristics. Instead of treating all edge servers uniformly, the system divides them into segments that can be selectively exposed or hidden based on security policies, allowing fast local connections while limiting broader discoverability of the entire network infrastructure.
3Ease of operation
If standard connections are established without additional security measures, then ease of connection is improved, but security and privacy are worsened
Solution Approach 1:
The patent implements preliminary security actions by establishing secure connections through authenticated edge servers before actual data transmission begins. The rule set pre-configures security parameters, authentication mechanisms, and encryption protocols that are automatically applied when connections are established, ensuring security is built-in from the outset rather than added later.
Solution Approach 2:
The authenticated edge server acts as an intermediary that facilitates secure connections between clients and the enhanced services network. This intermediary validates identities, establishes encrypted channels, and manages security credentials, making the security process transparent to users while maintaining high security standards.
Data Source
AI summary
An enhanced services network provides enhanced privacy and/or security over public networks to client subscribers of the service. Client devices access the enhanced services network over a public communications network (e.g., the Internet, cellular network, etc.) via a client-side edge server of the enhanced services network. The enhanced services network interfaces with client-requested network resources hosted by third-party server devices via a resource-side edge server. The particular client-side edge server and/or resource-side edge server that is utilized for a particular client session may be selected by the enhanced services network according to a rule set. The rule set may seek to achieve one or more target goals, such as: (1) limit discoverability of the enhanced services network, (2) minimize or reduce geographic/network distance between an edge server and a target computing device, and/or (3) establish connections that are more secure than the connections originally requested by the client.


