Security Broker for Edge Computing Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Edge computing environments face challenges in ensuring the security of communications between cloud and edge resources due to the lack of robust physical security and mature security measures, making it difficult to authenticate and authorize access to data flows effectively.

Innovation Solution

A security broker is introduced to monitor and manage communications between cloud and edge resources, utilizing authentication modules, PKI decryption algorithms, and sensitivity scanning to authenticate and authorize message sources, and to identify and purge sensitive information, while also formatting messages into suitable file formats for transfer across isolated systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If edge computing environments use distributed computing systems with resources located at the edge, then computational and storage resources can be placed close to data sources, but the system lacks robust physical security and mature security measures compared to data centers

Engineering Contradiction:
Improvedistributed computing capabilityVSAvoidsecurity measure maturity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

A security broker is introduced as an intermediary component between cloud resources and edge resources. The broker receives requests from cloud resources, authenticates them using authentication modules, verifies authorization, and then forwards approved requests to edge resources. This mediator approach allows the distributed edge computing system to achieve security measures comparable to data centers without requiring physical security infrastructure at edge locations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the security broker authenticates and authorizes each message source and destination, then secure access control is achieved, but the communication process becomes more complex

Engineering Contradiction:
Improveaccess control securityVSAvoidcommunication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security broker performs authentication and authorization checks in advance, before messages are routed to their destinations. By pre-validating message sources and intended destinations against authorized lists, the system establishes security controls upfront rather than adding complex validation at each communication step. This preliminary action simplifies the overall communication process while maintaining strong access control.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the security broker monitors and scans response messages for sensitive information, then sensitive data protection is improved, but the message processing time increases

Engineering Contradiction:
Improvesensitive data protectionVSAvoidmessage processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent employs automated sensitive data discovery tools and algorithms to scan response messages for sensitive information patterns. These automated systems replace manual or mechanical review processes, enabling rapid identification and redaction of sensitive data such as personally identifiable information (PII). The automated approach maintains high security standards while minimizing the time added to message processing through efficient pattern recognition and automated redaction capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12095819B2Security broker for edge computing environment
Publication Date: 2024.09.17 DELL PROD LP
  • US12095819B2 patent drawing
  • US12095819B2 patent drawing
  • US12095819B2 patent drawing

AI summary

A disclosed security broker receives a request message addressed to a message queue associated with an edge resource, identifies the message source, and leverages an authentication module to verify that the source has authorization to access the targeted message queue. The security broker may then deliver the request message to the targeted edge resource message queue. If the edge resource and security broker are physically isolated, the security broker may format the request message as a file, store the file to a storage device, and transfer the storage device to the edge resource, which may then process the file and upload the request message to the edge resource's message queue module. The security broker also monitors a response message from the edge resource, purges sensitive data from the response. If the broker and cloud resource are physically isolated, the response may be formatted and delivered as a file.