Security Broker for Edge Computing Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Edge computing environments face challenges in ensuring the security of communications between cloud and edge resources due to the lack of robust physical security and mature security measures, making it difficult to authenticate and authorize access to data flows effectively.
Innovation Solution
A security broker is introduced to monitor and manage communications between cloud and edge resources, utilizing authentication modules, PKI decryption algorithms, and sensitivity scanning to authenticate and authorize message sources, and to identify and purge sensitive information, while also formatting messages into suitable file formats for transfer across isolated systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If edge computing environments use distributed computing systems with resources located at the edge, then computational and storage resources can be placed close to data sources, but the system lacks robust physical security and mature security measures compared to data centers
Solution Approach 1:
A security broker is introduced as an intermediary component between cloud resources and edge resources. The broker receives requests from cloud resources, authenticates them using authentication modules, verifies authorization, and then forwards approved requests to edge resources. This mediator approach allows the distributed edge computing system to achieve security measures comparable to data centers without requiring physical security infrastructure at edge locations.
2Reliability
If the security broker authenticates and authorizes each message source and destination, then secure access control is achieved, but the communication process becomes more complex
Solution Approach 1:
The security broker performs authentication and authorization checks in advance, before messages are routed to their destinations. By pre-validating message sources and intended destinations against authorized lists, the system establishes security controls upfront rather than adding complex validation at each communication step. This preliminary action simplifies the overall communication process while maintaining strong access control.
3Reliability
If the security broker monitors and scans response messages for sensitive information, then sensitive data protection is improved, but the message processing time increases
Solution Approach 1:
The patent employs automated sensitive data discovery tools and algorithms to scan response messages for sensitive information patterns. These automated systems replace manual or mechanical review processes, enabling rapid identification and redaction of sensitive data such as personally identifiable information (PII). The automated approach maintains high security standards while minimizing the time added to message processing through efficient pattern recognition and automated redaction capabilities.
Data Source
AI summary
A disclosed security broker receives a request message addressed to a message queue associated with an edge resource, identifies the message source, and leverages an authentication module to verify that the source has authorization to access the targeted message queue. The security broker may then deliver the request message to the targeted edge resource message queue. If the edge resource and security broker are physically isolated, the security broker may format the request message as a file, store the file to a storage device, and transfer the storage device to the edge resource, which may then process the file and upload the request message to the edge resource's message queue module. The security broker also monitors a response message from the edge resource, purges sensitive data from the response. If the broker and cloud resource are physically isolated, the response may be formatted and delivered as a file.


