IoT Edge Computer System with Logically Separated Virtual Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional IoT edge computer systems face challenges in securely processing and protecting sensitive data for different user groups due to inadequate data security measures, particularly in environments where data from various sources converges, making them vulnerable to unauthorized access and cyber attacks.

Innovation Solution

The implementation of a logically separated edge computer system with multiple virtual operating environments, each isolated from the others, utilizing virtualization and sandboxing to ensure data security and confidentiality, with configured virtual network connections and firewalls to prevent unauthorized access, and a basic operating system to control and secure these environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If all data is collected and transferred to a single endpoint (data center or cloud), then data processing capability is improved, but data security and vulnerability to unauthorized access deteriorate

Engineering Contradiction:
Improvedata processing capabilityVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments data processing across multiple virtual operating environments (first virtual environment for system data, second virtual environment for operational data) rather than consolidating all data in a single endpoint. This segmentation maintains processing capability while improving security by isolating different data types and user groups in separate logical environments with controlled access.

Inventive Principle:
Principle #1Segmentation

2Productivity

If data from various sources converges at a single location, then data analysis efficiency is improved, but vulnerability to cyber attacks and unauthorized access increases

Engineering Contradiction:
Improvedata analysis efficiencyVSAvoidvulnerability to cyber attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system divides the data processing infrastructure into multiple isolated virtual operating environments. The first virtual environment processes system telemetry data while the second virtual environment processes operational data from external systems. This segmentation maintains analytical efficiency by enabling parallel processing while reducing vulnerability by ensuring that a security breach in one environment cannot compromise the other.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a base operating system as an intermediary layer that manages and controls access between the virtual operating environments and external systems. This intermediary enforces security policies, controls data flow, and prevents direct unauthorized access to sensitive data, thereby maintaining analysis efficiency while protecting against cyber threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If virtual operating environments are logically separated, then data security and confidentiality are improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The base operating system provides universal functionality by managing multiple virtual operating environments through a common set of security policies, access controls, and resource management mechanisms. This multi-functional approach enables the system to handle different data types and user groups through a unified architecture, improving data security while minimizing the complexity increase that would result from entirely separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3707878B1IoT computer system and arrangement having such an IoT computer system and an external system
Publication Date: 2023.09.20 FUJITSU TECHNOLOGY SOLUTIONS GMBH
  • EP3707878B1 patent drawing

AI summary

The invention relates to an IoT computer system (1), in particular what is known as an edge computer system, in which a first virtual operating environment (2) and a second virtual operating environment (3) are set up, wherein the virtual operating environments (2, 3) are logically separate from one another, and an arrangement having such an IoT computer system (1) and at least one external system or device (13, 14, 15, 16) to which the IoT computer system (1) is connected.