Edge Computing Shared Memory Access for Multi-Tenant Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional edge computing approaches for multi-tenant data protection in IoT and MEC networks inefficiently utilize intermediate nodes, leading to increased processing time and resource waste due to encryption/decryption only at originating and destination nodes, without leveraging intermediate node processing capacities.
Innovation Solution
Implementing a platform resource manager (PRM) with shared memory access (SMA) to configure, monitor, and control memory regions with varying access privileges, allowing secure data sharing among tenants and optimizing resource utilization through workload metadata and service authorizations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption/decryption is performed only at originating and destination nodes, then data security is maintained, but intermediate node processing capacities are wasted and processing time increases
Solution Approach 1:
The patent segments the encryption/decryption process into multiple stages performed at different nodes along the data path. Instead of performing all cryptographic operations only at endpoints, intermediate nodes are assigned specific processing tasks such as partial decryption, transformation, or re-encryption, dividing the workload to improve overall processing efficiency while maintaining security through controlled access at each segment
Solution Approach 2:
The patent introduces intermediary nodes with authorized access capabilities that act as mediators between originating and destination nodes. These intermediate nodes are granted controlled access to decrypt, process, and re-encrypt data, enabling them to perform useful work on the data stream without compromising end-to-end security. The intermediary nodes operate under defined authorization policies that balance security requirements with resource utilization
2Productivity
If intermediate nodes are used for data processing, then resource utilization improves, but data protection complexity increases
Solution Approach 1:
The patent implements dynamic authorization mechanisms where intermediate node access rights are not fixed but adapt based on data sensitivity, node trust levels, and operational context. Authorization policies are dynamically adjusted to grant or revoke intermediate node access permissions, enabling flexible resource utilization while managing protection complexity through context-aware decision-making rather than static complex configurations
Solution Approach 2:
The patent changes key parameters such as encryption keys, authorization levels, and access policies at different stages of data transmission. By varying cryptographic parameters and authorization states dynamically along the data path, the system enables intermediate nodes to perform processing with appropriate access levels without requiring all nodes to implement the full complexity of end-to-end security mechanisms
3Productivity
If shared memory access is implemented with fine-grained partitioning, then resource allocation efficiency improves, but system complexity increases
Solution Approach 1:
The patent applies local quality by implementing fine-grained memory partitioning where different regions of shared memory are allocated with different access privileges, security levels, and authorization requirements specific to each tenant or workload. Instead of uniform memory management, each memory segment is tailored to its specific usage requirements, enabling efficient resource allocation to multiple tenants while managing complexity through localized rather than global control mechanisms
Solution Approach 2:
The patent adds a new dimension of control by introducing hierarchical memory addressing and multi-level authorization schemes. Memory access is controlled not just by traditional flat permissions but by adding dimensional layers such as tenant-specific address spaces, security domains, and access hierarchy levels. This dimensional approach enables fine-grained resource allocation efficiency while organizing system complexity into manageable hierarchical structures rather than flat complex permission matrices
Data Source
AI summary
Various approaches for implementing multi-tenant data protection are described. In an edge computing system deployment, a system includes memory and processing circuitry coupled to the memory. The processing circuitry is configured to obtain a workflow execution plan that includes workload metadata defining a plurality of workloads associated with a plurality of edge service instances executing respectively on one or more edge computing devices. The workload metadata is translated to obtain workload configuration information for the plurality of workloads. The workload configuration information identifies a plurality of memory access configurations and service authorizations identifying at least one edge service instance authorized to access one or more of the memory access configurations. The memory is partitioned into a plurality of shared memory regions using the memory access configurations. A memory access request for accessing one of the shared memory regions is processed based on the service authorizations.


