Multi-tenant Edge Architecture for Scalable Container Allocation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing edge systems are single-node systems lacking scalability and redundancy, which makes them unsuitable for mission-critical applications. Additionally, they have limitations in security, performance, and reliability for edge computing.
Innovation Solution
The proposed solution is a scalable, robust, and secure multi-tenant edge architecture that supports cross-server containerized application allocation, multi-tenant namespace management, and data layer deployment. This architecture provides geographic-based allocation of containerized applications, public and private services with quality of service guarantees, and built-in security through managed namespaces and multi-tenant authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If single-node edge systems are used, then device complexity is reduced, but scalability and reliability deteriorate
Solution Approach 1:
The edge system is divided into multiple independent nodes (edge servers, gateways, devices) that can operate autonomously. Each node runs containerized applications that can be deployed across multiple servers, enabling the system to segment functionality while maintaining overall reliability through distributed architecture.
Solution Approach 2:
The patent implements nested architecture where containers are deployed within edge servers, which are organized into clusters. The multi-tenant namespace structure nests multiple applications and services within a unified edge platform, allowing scalable expansion while maintaining manageable complexity through hierarchical organization.
2Ease of operation
If single-node edge systems are used, then ease of operation is improved, but scalability deteriorates
Solution Approach 1:
The edge platform provides universal functionality through standardized containerized applications that can run across multiple node types (edge servers, gateways, devices). The multi-tenant namespace and common data layer enable the same platform to support diverse applications from different vendors, achieving scalability without sacrificing ease of operation through unified management interfaces.
Solution Approach 2:
The system dynamically deploys and scales containerized applications across edge nodes based on demand. The common orchestration layer automatically manages application allocation, allowing the system to adapt its scale and configuration without requiring manual intervention, thus maintaining ease of operation while achieving scalability.
3Power
If centralized cloud computing is used, then processing power is improved, but latency deteriorates
Solution Approach 1:
The patent transitions from purely centralized cloud processing to a multi-dimensional computing architecture that operates at multiple levels: edge devices, edge servers, and cloud. This dimensional expansion allows computing power to be distributed geographically closer to data sources while maintaining access to centralized cloud resources for heavy processing tasks.
Solution Approach 2:
Edge servers and gateways act as intermediaries between devices and the cloud, enabling local processing and data management closer to the data source. This intermediary layer reduces latency by handling time-sensitive operations locally while still leveraging cloud computing power for more demanding tasks through the common data layer.
4Object-affected harmful factors
If multi-tenant namespace management is implemented, then security is improved, but device complexity deteriorates
Solution Approach 1:
The common orchestration layer automatically manages namespace creation, allocation, and isolation for multiple tenants without requiring manual configuration. The system self-service approach handles security isolation and resource allocation automatically based on tenant requirements, improving security while reducing operational complexity through automated management.
Solution Approach 2:
The patent uses parameter-based isolation mechanisms where namespaces are defined by configurable parameters such as tenant identifiers, resource quotas, and access policies. By changing and managing these parameters centrally through the common data layer and orchestration layer, the system achieves robust security isolation without requiring complex manual namespace management at individual nodes.
Data Source
AI summary
Aspects of the present disclosure provide systems, methods, and computer-readable storage media that support cross-server containerized application allocation, multi-tenant namespace management, and data layer deployment in an edge environment. To illustrate, containers associated with an application are deployed to edge servers based on a geographic characteristic of the edge server with respect to an edge device receiving services from the application. A common data layer is provided across the edge environment to manage communications between the different containers, and between the application and other applications of the edge environment. Managing the communication is based on namespaces and/or a modality (e.g., private or public) associated with the application. Authentication configuration of the application is used to determine edge resource access for the containers of the application. A common orchestration layer is provided across the edge environment to manage scaling and configuration updates of the application.


