Edge Switch Data Encryption Offloading for IoT Latency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices and cloud servers face challenges in efficiently performing data encryption and decryption due to limited computing power, leading to increased computational burdens and delays in data transmission.

Innovation Solution

Implementing data encryption and decryption operations at edge switches, utilizing computing devices with programmable circuit components to reduce computational loads and enhance processing efficiency, thereby transferring AES encryption and decryption algorithms from IoT devices and cloud servers to edge switches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data encryption and decryption are performed at IoT devices or cloud servers, then security of communication is ensured, but computational burden increases and processing efficiency decreases

Engineering Contradiction:
Improvesecurity of communicationVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the encryption and decryption operations from the original locations (IoT devices and cloud servers) and relocates them to edge switches. This separation allows the security function to be maintained while the computational burden is shifted to a more suitable platform with dedicated cryptographic hardware, thereby resolving the contradiction between ensuring security and maintaining processing efficiency.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The edge switch acts as an intermediary between IoT devices and cloud servers, performing encryption and decryption operations in the middle layer of the network architecture. This intermediary approach enables security to be maintained while distributing the computational load away from resource-constrained devices and overloaded cloud servers, thus improving overall system productivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If good encryption and decryption algorithms are used, then security is improved, but computing power consumption increases

Engineering Contradiction:
ImprovesecurityVSAvoidcomputing power consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent replaces general-purpose computational mechanisms with specialized cryptographic hardware (cryptographic accelerators, FPGAs, or dedicated security chips) at the edge switch. This substitution enables strong encryption algorithms to be executed with significantly lower energy consumption compared to using standard processors, thus resolving the contradiction between security and energy usage.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Extent of automation

If encryption and decryption operations are performed at cloud servers, then centralized security control is achieved, but computational resources are overwhelmed

Engineering Contradiction:
Improvecentralized security controlVSAvoidcomputational resource availability
Core Design Contradiction:
Extent of automationVSProductivity

Solution Approach 1:

The patent segments the security processing function from the centralized cloud server and distributes it to edge switches in the network. This segmentation maintains centralized security policy management while distributing the actual cryptographic operations to multiple edge locations, thereby preventing cloud server computational resources from being overwhelmed while preserving centralized control capabilities.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11936635B2Method, electronic device, and program product implemented at an edge switch for data encryption
Publication Date: 2024.03.19 EMC IP HLDG CO LLC
  • US11936635B2 patent drawing
  • US11936635B2 patent drawing
  • US11936635B2 patent drawing

AI summary

Embodiments of the present disclosure provide a method, an electronic device, and a program product implemented at an edge switch for data encryption. For example, the present disclosure provides a data encryption method implemented at an edge switch. The method may include receiving encryption and decryption information for an encryption operation or a decryption operation from a source device. In addition, the method may include encrypting a data packet received from the source device based on encryption information in the encryption and decryption information to generate an encrypted data packet. The method may further include sending the encrypted data packet to a target device indicated by the data packet. The embodiments of the present disclosure can reduce the computing loads of Internet of Things (IoT) devices, clouds, and servers while ensuring encryption performance, and can also reduce the time delay caused by encryption and decryption operations.