Multi-tenant Edge Architecture for Scalable Container Allocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing edge systems are single-node systems lacking scalability and redundancy, which makes them unsuitable for mission-critical applications. Additionally, they have limitations in security, performance, and reliability for edge computing.

Innovation Solution

The proposed solution is a scalable, robust, and secure multi-tenant edge architecture that supports cross-server containerized application allocation, multi-tenant namespace management, and data layer deployment. This architecture provides geographic-based allocation of containerized applications, public and private services with quality of service guarantees, and built-in security through managed namespaces and multi-tenant authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If single-node edge systems are used, then device complexity is reduced, but scalability and reliability deteriorate

Engineering Contradiction:
Improvesystem structureVSAvoidsystem reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The edge system is divided into multiple independent nodes (edge servers, gateways, devices) that can operate autonomously. Each node runs containerized applications that can be deployed across multiple servers, enabling the system to segment functionality while maintaining overall reliability through distributed architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements nested architecture where containers are deployed within edge servers, which are organized into clusters. The multi-tenant namespace structure nests multiple applications and services within a unified edge platform, allowing scalable expansion while maintaining manageable complexity through hierarchical organization.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Ease of operation

If single-node edge systems are used, then ease of operation is improved, but scalability deteriorates

Engineering Contradiction:
Improvesystem operationVSAvoidsystem scalability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The edge platform provides universal functionality through standardized containerized applications that can run across multiple node types (edge servers, gateways, devices). The multi-tenant namespace and common data layer enable the same platform to support diverse applications from different vendors, achieving scalability without sacrificing ease of operation through unified management interfaces.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically deploys and scales containerized applications across edge nodes based on demand. The common orchestration layer automatically manages application allocation, allowing the system to adapt its scale and configuration without requiring manual intervention, thus maintaining ease of operation while achieving scalability.

Inventive Principle:
Principle #15Dynamics

3Power

If centralized cloud computing is used, then processing power is improved, but latency deteriorates

Engineering Contradiction:
Improvecomputing powerVSAvoiddata processing speed
Core Design Contradiction:
PowerVSSpeed

Solution Approach 1:

The patent transitions from purely centralized cloud processing to a multi-dimensional computing architecture that operates at multiple levels: edge devices, edge servers, and cloud. This dimensional expansion allows computing power to be distributed geographically closer to data sources while maintaining access to centralized cloud resources for heavy processing tasks.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

Edge servers and gateways act as intermediaries between devices and the cloud, enabling local processing and data management closer to the data source. This intermediary layer reduces latency by handling time-sensitive operations locally while still leveraging cloud computing power for more demanding tasks through the common data layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Object-affected harmful factors

If multi-tenant namespace management is implemented, then security is improved, but device complexity deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidnamespace management
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The common orchestration layer automatically manages namespace creation, allocation, and isolation for multiple tenants without requiring manual configuration. The system self-service approach handles security isolation and resource allocation automatically based on tenant requirements, improving security while reducing operational complexity through automated management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses parameter-based isolation mechanisms where namespaces are defined by configurable parameters such as tenant identifiers, resource quotas, and access policies. By changing and managing these parameters centrally through the common data layer and orchestration layer, the system achieves robust security isolation without requiring complex manual namespace management at individual nodes.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12236222B2Scalable, robust, and secure multi-tenant edge architecture for mission-critical applications
Publication Date: 2025.02.25 ACCENTURE GLOBAL SOLUTIONS LTD
  • US12236222B2 patent drawing
  • US12236222B2 patent drawing
  • US12236222B2 patent drawing

AI summary

Aspects of the present disclosure provide systems, methods, and computer-readable storage media that support cross-server containerized application allocation, multi-tenant namespace management, and data layer deployment in an edge environment. To illustrate, containers associated with an application are deployed to edge servers based on a geographic characteristic of the edge server with respect to an edge device receiving services from the application. A common data layer is provided across the edge environment to manage communications between the different containers, and between the application and other applications of the edge environment. Managing the communication is based on namespaces and/or a modality (e.g., private or public) associated with the application. Authentication configuration of the application is used to determine edge resource access for the containers of the application. A common orchestration layer is provided across the edge environment to manage scaling and configuration updates of the application.