Trust Status Broker for Secure Edge Application Mobility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In edge computing, ensuring secure deployment and execution of applications across multiple operator platforms while maintaining trust and quality of service is challenging due to the federated nature of networks, where applications need to move seamlessly and securely across different operator platforms as users change locations.

Innovation Solution

The introduction of a Trust Status Broker (TSB) within the Multi-Access Edge Computing (MEC) architecture facilitates security verification by acting as a proxy for application providers, utilizing Trusted Execution Environments (TEEs) and Confidential Computing principles to establish and maintain trust across operator platforms, ensuring secure deployment and execution of edge applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If applications are deployed across multiple operator platforms to enable user mobility, then user experience and service continuity are improved, but security and trust verification become more complex

Engineering Contradiction:
Improveapplication mobilityVSAvoidsecurity verification
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a Trust Status Broker (TSB) as an intermediary component that mediates between application providers and operator platforms. The TSB maintains trust status information and provides verification services, simplifying the security architecture by centralizing trust management rather than requiring complex peer-to-peer verification across multiple platforms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The TSB is designed as a universal trust management service that operates across different operator platforms and supports multiple application types. It provides standardized trust verification mechanisms that work consistently regardless of the underlying platform, reducing the complexity of implementing platform-specific security solutions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If trust verification mechanisms are implemented across federated operator platforms, then security and integrity are improved, but deployment complexity and overhead increase

Engineering Contradiction:
Improvetrust verificationVSAvoiddeployment overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary trust verification by having operator platforms pre-validate applications against trust criteria before deployment. The TSB maintains pre-established trust status information that can be quickly verified during deployment, avoiding the need for complex real-time verification processes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The trust verification system is designed to be self-service oriented, where the TSB automatically manages trust status information and provides verification services without requiring manual intervention. Application providers can independently verify trust status through standardized interfaces, reducing deployment overhead.

Inventive Principle:
Principle #25Self-service

3Duration of action of moving object

If applications follow users across different geographic locations and operator platforms, then service continuity is improved, but maintaining security policies and trust levels becomes more difficult

Engineering Contradiction:
Improveservice continuityVSAvoidpolicy management
Core Design Contradiction:
Duration of action of moving objectVSDevice complexity

Solution Approach 1:

The system dynamically adapts trust verification based on the application's movement across platforms. The TSB maintains persistent trust status information that travels with the application, allowing continuous verification without requiring re-validation at each platform transition, thus maintaining service continuity while simplifying policy management.

Inventive Principle:
Principle #15Dynamics

4Reliability

If secure deployment mechanisms are implemented in federated edge cloud environments, then application integrity and confidentiality are improved, but system complexity and operational overhead increase

Engineering Contradiction:
Improveapplication integrityVSAvoidoperational overhead
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The TSB acts as an intermediary that simplifies secure deployment operations by centralizing trust management. Application providers interact with the TSB through standardized interfaces rather than dealing with complex platform-specific security mechanisms, reducing operational overhead while maintaining integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20230362016A1Secure application computing environment in a federated edge cloud
Publication Date: 2023.11.09 INTEL CORP
  • US20230362016A1 patent drawing
  • US20230362016A1 patent drawing
  • US20230362016A1 patent drawing

AI summary

Systems and methods for a secure application computing environment in a federated Edge Cloud are disclosed herein. Application information corresponding to an application from an application provider may be received in a secure environment of a device such as an edge computing node. A trust level for execution of the application may be associated based at least in part on the application information, and based on the associated trust level, a trusted platform may be selected to deploy or launch the application.