Multi-Access Edge Server Virtualizing IoT Device Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IoT devices face challenges such as limited computing resources, unreliable communication due to power-saving modes, high compliance testing burdens for OEMs, network overloading from failed communications, and inefficiencies in managing and securing large numbers of devices.
Innovation Solution
Implementing a client virtualization system that hosts device management clients on multi-access servers, allowing for centralized management, efficient communication, reduced resource usage on IoT devices, and enhanced security through virtualized security services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If device management clients are hosted locally on each IoT device, then device autonomy and direct control are improved, but device complexity and resource consumption increase
Solution Approach 1:
The patent extracts the device management client functionality from the IoT device and hosts it on the multi-access server instead. This removes the complexity of running management clients locally on resource-constrained devices while maintaining the ability to manage devices autonomously through the virtualized client environment on the server.
Solution Approach 2:
The multi-access server provides a universal platform that hosts virtualized device management clients for multiple different IoT devices simultaneously. This single server infrastructure replaces the need for individual management clients on each device, providing a multi-functional solution that handles device management, security, and communication for diverse device types.
2Reliability
If security services are implemented locally on each IoT device, then device security is improved, but resource consumption and power usage increase
Solution Approach 1:
The patent extracts security service functionality from individual IoT devices and consolidates it on the multi-access server. By moving security operations to the server, devices consume less power while maintaining security through the virtualized security services that run in the hosted client environment.
Solution Approach 2:
The patent merges security services from multiple individual devices into a centralized security infrastructure on the multi-access server. This consolidation provides comprehensive security coverage while reducing the cumulative power consumption that would result from each device running its own security services locally.
3Use of energy by moving object
If device management clients are hosted on multi-access servers, then resource usage on IoT devices is reduced, but network dependency increases
Solution Approach 1:
The patent introduces the multi-access server as an intermediary between the centralized management system and IoT devices. This intermediary hosts the virtualized clients, enabling resource-efficient device operation while managing network communications. The server acts as a buffer that handles communication protocols and retry logic, improving reliability despite network dependencies.
4Ease of manufacture
If virtualized device management clients are implemented, then compliance testing burden is reduced, but system complexity increases
Solution Approach 1:
The patent creates a virtualized copy of the device management client environment on the multi-access server. This virtual copy allows compliance testing to be performed in a controlled, standardized environment that can be replicated across different devices, reducing the burden of testing each physical device individually while managing complexity through virtualization abstraction.
Data Source
AI summary
An exemplary security virtualization system implemented by a multi-access edge compute (“MEC”) server identifies a security policy for a device that is separate from and communicatively coupled to the MEC server. The security virtualization system intercepts data transmitted to the device from an application server, and applies a security service to the intercepted data in accordance with the security policy identified for the device. Subsequent to the applying of the security service, the security virtualization system delivers, to the device by way of a secure connection between the security virtualization system and the device, sanitized data that corresponds to the intercepted data and has been sanitized by way of the security service. Corresponding methods and systems are also disclosed.


