Edge Token Authentication for Cloud Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Centralized trust-based security protocols in cloud computing environments are resource-intensive and inefficient, especially in edge computing scenarios where intermittent or non-existent communication with remote servers occurs, making them unsuitable for geographically remote locations with numerous local devices that require individual authentication.

Innovation Solution

A distributed token strategy is implemented, where an edge computing device generates an edge token for network authentication and storage tokens for local device authentication, both derived from a client token, allowing for localized authentication without relying on remote servers, thereby reducing resource usage and improving efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized trust-based security protocols are used for device authentication in cloud computing environments, then authentication reliability is maintained, but resource consumption increases and authentication efficiency decreases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the centralized authentication process into distributed local authentication operations. Each edge computing device obtains authentication credentials from the centralized system once, then performs independent local authentication with connected devices without continuous remote server involvement. This segmentation maintains authentication reliability through initial centralized verification while dramatically reducing ongoing resource consumption by eliminating repeated remote communications.

Inventive Principle:
Principle #1Segmentation

2Reliability

If centralized trust-based security protocols are used for device authentication, then authentication security is maintained, but authentication speed decreases due to remote server dependency

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent implements preliminary action by having edge computing devices obtain authentication credentials (edge tokens and storage tokens) from the centralized remote server in advance, before actual authentication operations are needed. These pre-obtained tokens enable subsequent local authentication operations to proceed at high speed without real-time remote server dependency, thus maintaining security through initial verification while achieving fast local authentication execution.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If centralized authentication via remote servers is used, then comprehensive device verification is achieved, but system efficiency decreases in edge computing scenarios with intermittent network connectivity

Engineering Contradiction:
Improvedevice verification completenessVSAvoidsystem efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables self-service authentication where edge computing devices use locally stored tokens to independently verify connected devices without requiring remote server involvement. The edge computing device acts as its own authentication authority, using pre-obtained edge tokens and storage tokens to perform local authentication operations. This self-service approach maintains verification completeness through cryptographic token validation while dramatically improving system efficiency by eliminating remote server dependencies and network communication requirements.

Inventive Principle:
Principle #25Self-service

4Reliability

If remote server authentication is implemented for each local device, then centralized security control is maintained, but device complexity and network dependency increase

Engineering Contradiction:
Improvecentralized security controlVSAvoidnetwork dependency
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication decision-making capability from the remote server and places it locally at the edge computing device. The remote server's role is reduced to issuing initial credentials, while the actual authentication logic and token validation are extracted and executed locally. This extraction maintains centralized security control through the initial credential issuance mechanism while eliminating ongoing network dependency and reducing device complexity by removing the need for continuous remote server communication infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11595369B2Promoting system authentication to the edge of a cloud computing network
Publication Date: 2023.02.28 SEAGATE TECH LLC
  • US11595369B2 patent drawing
  • US11595369B2 patent drawing
  • US11595369B2 patent drawing

AI summary

Apparatus and method for local authentication of a collection of processing devices, such as but not limited to storage devices (e.g., SSDs, etc.). In some embodiments, an edge computing device is coupled between the collection of processing devices and an external network. The edge computing device performs a network authentication over the external network with a remote server using an edge token. The edge computing device further performs a local authentication of the collection using storage tokens of the respective processing devices, with the local authentication not utilizing the external network or the remote server. Both the edge token and the storage tokens may be generated from a client token of a client device.