Edge Service Security Agents for Denial-of-Service Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional edge computing systems face instability and service degradation due to denial-of-service attacks, distributed denial-of-service attacks, and changes in user terminal locations, leading to poor service experiences.

Innovation Solution

A method and system that utilize a security controller and security agents to identify and isolate insecure endpoint devices, generate link abnormality information, and redirect normal endpoint devices to alternative security agents, ensuring continuous stable edge service by managing edge links and handling abnormalities such as DOS attacks and abnormal link quality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If edge computing resources are deployed in a distributed manner close to terminals, then service delay is reduced, but service stability deteriorates under abnormal conditions such as DOS attacks

Engineering Contradiction:
Improveservice response speedVSAvoidservice stability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system segments the edge computing network into multiple independent edge computing device clusters, each capable of autonomous operation. This segmentation allows the system to isolate affected clusters during attacks while maintaining service continuity in unaffected clusters, thus resolving the contradiction between distributed deployment for low latency and stability under attack conditions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A security controller is introduced as an intermediary component that monitors and manages security across all edge computing device clusters. The security controller receives security status information from clusters, identifies insecure clusters under attack, and isolates them to protect the overall system, thereby maintaining service stability while preserving the distributed architecture's speed advantages.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If multiple endpoint computing devices connect to a single security agent, then resource utilization is improved, but service quality deteriorates when one device becomes insecure

Engineering Contradiction:
Improvesecurity agent resource utilizationVSAvoidedge service quality
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system dynamically adjusts the mapping between endpoint computing devices and security agents based on security status. When a device is identified as insecure, the system dynamically reconfigures connections to isolate the affected device while maintaining optimal resource utilization for secure devices, thus resolving the contradiction between high resource utilization and service quality maintenance.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements a feedback mechanism where security agents continuously monitor the security status of connected endpoint devices. When abnormal security status is detected, the system receives security status information, identifies the insecure device, and adjusts resource allocation accordingly, ensuring that insecure devices do not degrade service quality for secure devices while maintaining overall resource efficiency.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12034766B2Method and system for providing edge service, and computing device
Publication Date: 2024.07.09 HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
  • US12034766B2 patent drawing
  • US12034766B2 patent drawing
  • US12034766B2 patent drawing

AI summary

A method for providing an edge service includes a first security agent that performs data stream transmission with a plurality of endpoint computing devices through an edge link, and each endpoint computing device obtains, using the first security agent, an edge service provided by an edge server. The first security agent determines, based on a data stream transmitted between each endpoint computing device and the first security agent, an abnormal endpoint computing device in the plurality of endpoint computing devices. The first security agent generates link abnormality information, and the link abnormality information includes an address of the abnormal endpoint computing device. The first security agent sends the link abnormality information to the security controller. The security controller receives the link abnormality information, and generates edge link information including an address of a second security agent based on the link abnormality information.