Multi-tenancy Security System for Private Edge Computing Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current techniques for accessing functionalities of a private multi-access edge computing (pMEC) device are cumbersome and resource-intensive, requiring multiple credentials, which can lead to security breaches and resource wastage.
Innovation Solution
A security system that manages credentials by storing user security levels in a data structure and provides secure access to pMEC devices via a multi-tenancy environment, allowing users to access different functionalities with a single credential while conserving resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple credentials are required for accessing different functionalities of pMEC device, then security access control is improved, but device complexity and ease of operation deteriorate
Solution Approach 1:
The patent merges multiple separate credentials into a single unified credential that provides access to multiple functionalities of the pMEC device. The credential database stores multiple credentials associated with different functionalities, and the system evaluates security policies for each functionality using the single credential, thereby combining what was previously separate authentication processes into one unified access mechanism.
Solution Approach 2:
The patent implements a universal credential system where a single credential can be used to access multiple different functionalities of the pMEC device. The credential database and policy evaluation mechanism are designed to handle multiple functionalities universally, allowing one credential to serve multiple purposes rather than requiring dedicated credentials for each function.
2Reliability
If multiple credentials are required for accessing different functionalities of pMEC device, then security access control is improved, but ease of operation worsens
Solution Approach 1:
The patent merges multiple separate credentials into a single unified credential that provides access to multiple functionalities of the pMEC device. The credential database stores multiple credentials associated with different functionalities, and the system evaluates security policies for each functionality using the single credential, thereby combining what was previously separate authentication processes into one unified access mechanism.
Solution Approach 2:
The patent implements a universal credential system where a single credential can be used to access multiple different functionalities of the pMEC device. The credential database and policy evaluation mechanism are designed to handle multiple functionalities universally, allowing one credential to serve multiple purposes rather than requiring dedicated credentials for each function.
3Reliability
If multiple credentials are managed for pMEC device access, then security coverage is improved, but loss of time and resource consumption worsen
Solution Approach 1:
The patent performs preliminary actions by pre-storing multiple credentials in the credential database and pre-configuring security policies for different functionalities before access is needed. When a user presents a credential, the system has already prepared the evaluation framework, allowing for faster authentication without requiring real-time credential creation or manual configuration for each access request.
Solution Approach 2:
The patent merges multiple separate credentials into a single unified credential that provides access to multiple functionalities of the pMEC device. The credential database stores multiple credentials associated with different functionalities, and the system evaluates security policies for each functionality using the single credential, thereby combining what was previously separate authentication processes into one unified access mechanism.
Data Source
AI summary
A device may receive and store credentials identifying security levels of users for access to functionalities of an on-premises device, and may receive a credential of a user and a request to access a functionality of the on-premises device. The device may determine whether a security level of the credential matches a first security level of the credentials, and may reject the request when the security level fails to match the first security level. The device may determine, when the security level matches the first security level, whether a computing resource of the on-premises device matches a computing resource of the first security level, and may provide the user with access to the computing resource when the computing resource matches the computing resource of the first security level. The device may reject the request when the computing resource fails to match the computing resource of the first security level.


