Trust Status Broker for Secure Edge Application Mobility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In edge computing, ensuring secure deployment and execution of applications across multiple operator platforms while maintaining trust and quality of service is challenging due to the federated nature of networks, where applications need to move seamlessly and securely across different operator platforms as users change locations.
Innovation Solution
The introduction of a Trust Status Broker (TSB) within the Multi-Access Edge Computing (MEC) architecture facilitates security verification by acting as a proxy for application providers, utilizing Trusted Execution Environments (TEEs) and Confidential Computing principles to establish and maintain trust across operator platforms, ensuring secure deployment and execution of edge applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If applications are deployed across multiple operator platforms to enable user mobility, then user experience and service continuity are improved, but security and trust verification become more complex
Solution Approach 1:
The patent introduces a Trust Status Broker (TSB) as an intermediary component that mediates between application providers and operator platforms. The TSB maintains trust status information and provides verification services, simplifying the security architecture by centralizing trust management rather than requiring complex peer-to-peer verification across multiple platforms.
Solution Approach 2:
The TSB is designed as a universal trust management service that operates across different operator platforms and supports multiple application types. It provides standardized trust verification mechanisms that work consistently regardless of the underlying platform, reducing the complexity of implementing platform-specific security solutions.
2Reliability
If trust verification mechanisms are implemented across federated operator platforms, then security and integrity are improved, but deployment complexity and overhead increase
Solution Approach 1:
The system performs preliminary trust verification by having operator platforms pre-validate applications against trust criteria before deployment. The TSB maintains pre-established trust status information that can be quickly verified during deployment, avoiding the need for complex real-time verification processes.
Solution Approach 2:
The trust verification system is designed to be self-service oriented, where the TSB automatically manages trust status information and provides verification services without requiring manual intervention. Application providers can independently verify trust status through standardized interfaces, reducing deployment overhead.
3Duration of action of moving object
If applications follow users across different geographic locations and operator platforms, then service continuity is improved, but maintaining security policies and trust levels becomes more difficult
Solution Approach 1:
The system dynamically adapts trust verification based on the application's movement across platforms. The TSB maintains persistent trust status information that travels with the application, allowing continuous verification without requiring re-validation at each platform transition, thus maintaining service continuity while simplifying policy management.
4Reliability
If secure deployment mechanisms are implemented in federated edge cloud environments, then application integrity and confidentiality are improved, but system complexity and operational overhead increase
Solution Approach 1:
The TSB acts as an intermediary that simplifies secure deployment operations by centralizing trust management. Application providers interact with the TSB through standardized interfaces rather than dealing with complex platform-specific security mechanisms, reducing operational overhead while maintaining integrity.
Data Source
AI summary
Systems and methods for a secure application computing environment in a federated Edge Cloud are disclosed herein. Application information corresponding to an application from an application provider may be received in a secure environment of a device such as an edge computing node. A trust level for execution of the application may be associated based at least in part on the application information, and based on the associated trust level, a trusted platform may be selected to deploy or launch the application.


