IoT Edge Computer System with Logically Separated Virtual Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional IoT edge computer systems face challenges in securely processing and protecting sensitive data for different user groups due to inadequate data security measures, particularly in environments where data from various sources converges, making them vulnerable to unauthorized access and cyber attacks.
Innovation Solution
The implementation of a logically separated edge computer system with multiple virtual operating environments, each isolated from the others, utilizing virtualization and sandboxing to ensure data security and confidentiality, with configured virtual network connections and firewalls to prevent unauthorized access, and a basic operating system to control and secure these environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If all data is collected and transferred to a single endpoint (data center or cloud), then data processing capability is improved, but data security and vulnerability to unauthorized access deteriorate
Solution Approach 1:
The system segments data processing across multiple virtual operating environments (first virtual environment for system data, second virtual environment for operational data) rather than consolidating all data in a single endpoint. This segmentation maintains processing capability while improving security by isolating different data types and user groups in separate logical environments with controlled access.
2Productivity
If data from various sources converges at a single location, then data analysis efficiency is improved, but vulnerability to cyber attacks and unauthorized access increases
Solution Approach 1:
The system divides the data processing infrastructure into multiple isolated virtual operating environments. The first virtual environment processes system telemetry data while the second virtual environment processes operational data from external systems. This segmentation maintains analytical efficiency by enabling parallel processing while reducing vulnerability by ensuring that a security breach in one environment cannot compromise the other.
Solution Approach 2:
The patent introduces a base operating system as an intermediary layer that manages and controls access between the virtual operating environments and external systems. This intermediary enforces security policies, controls data flow, and prevents direct unauthorized access to sensitive data, thereby maintaining analysis efficiency while protecting against cyber threats.
3Reliability
If virtual operating environments are logically separated, then data security and confidentiality are improved, but system complexity increases
Solution Approach 1:
The base operating system provides universal functionality by managing multiple virtual operating environments through a common set of security policies, access controls, and resource management mechanisms. This multi-functional approach enables the system to handle different data types and user groups through a unified architecture, improving data security while minimizing the complexity increase that would result from entirely separate systems.
Data Source
AI summary
The invention relates to an IoT computer system (1), in particular what is known as an edge computer system, in which a first virtual operating environment (2) and a second virtual operating environment (3) are set up, wherein the virtual operating environments (2, 3) are logically separate from one another, and an arrangement having such an IoT computer system (1) and at least one external system or device (13, 14, 15, 16) to which the IoT computer system (1) is connected.
