Mobile Edge Compute Platform Security Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Balancing security and operational efficacy at the network perimeter in mobile and cloud technologies is challenging due to the amorphous nature of the network perimeter, making it difficult to provide adequate protection strategies and security policies for client network devices and applications operating in untrusted environments.

Innovation Solution

A platform of software and hardware components, including Mobile Edge Compute (MEC) Appliances and Controllers, with a security architecture that uses a Security Module to validate actions and provide a secure sandbox environment, facilitating scalability and extensibility, and allowing for the hosting of third-party applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If computational resources are provided at the network perimeter in untrusted environments, then operational efficacy and service extension are improved, but security risks increase

Engineering Contradiction:
Improveservice extension capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system segments the network edge computing environment into isolated containers or virtualized instances, allowing multiple third-party applications to run in separate secure compartments. This segmentation prevents a security compromise in one application from affecting other applications or the core network infrastructure, thus enabling service extension while mitigating security risks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary security management layer that sits between the untrusted third-party applications and the core network infrastructure. This intermediary layer enforces security policies, monitors application behavior, and controls access to network resources, allowing computational resources to be provided at the network perimeter while maintaining security through centralized policy enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security policies are strictly enforced at the network perimeter, then security protection is improved, but operational efficacy and scalability are hindered

Engineering Contradiction:
Improvesecurity protectionVSAvoidoperational efficacy
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security policy enforcement mechanism is designed to be dynamic rather than static. The system can adapt security policies based on the behavior, reputation, and risk profile of third-party applications. Well-behaved applications experience minimal security interference, while suspicious applications trigger enhanced security measures. This dynamic approach maintains high security protection while preserving operational efficacy for legitimate applications.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes security parameters such as policy strictness, monitoring intensity, and access control levels based on the operational context and risk assessment. For example, during off-peak hours or for low-risk applications, security parameters are relaxed to improve operational efficacy, while during high-risk periods or for suspicious applications, parameters are tightened to maintain security protection.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If third-party applications are hosted at the network edge, then service versatility is improved, but system complexity increases

Engineering Contradiction:
Improveservice versatilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal platform architecture that provides common security management, resource allocation, and application deployment capabilities across multiple third-party applications. Instead of managing each application separately, the system uses a multi-functional framework that handles diverse applications through standardized processes, reducing system complexity while maintaining service versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3982272A1Platform for computing at the mobile edge
Publication Date: 2022.04.13 INTEL CORP
  • EP3982272A1 patent drawingFigure 1
  • EP3982272A1 patent drawingFigure 2
  • EP3982272A1 patent drawingFigure 3

AI summary

Disclosed is a platform for providing computational resources at and/or near a mobile network perimeter. The platform may be used to provide computational resources adjacent a small cell radio via at least one Mobile Edge Compute ("MEC") Appliance and at least one MEC Controller. The MEC Appliance can serve as the data plane to support data flow traffic. The MEC Controller can provide a micro-services architecture designed for resiliency, scalability, and extensibility. The platform can be used to de-centralize the mobile network operator's core network and/or associated macro-cell network topologies, generating a platform with enhanced flexibility, reliability, and performance. The platform can include a security architecture for effective privacy and access within a distributed topology of the network at and/or near the edge of the mobile network perimeter.