Trusted Platform Data Segmentation for Edge Computing Overhead

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In IoT automation environments, existing systems face challenges in efficiently managing access to sensitive data while minimizing computational overhead, particularly in edge devices that need to encrypt and process data securely.

Innovation Solution

A method and system that classify data and analytics operations into trusted and non-trusted computing platforms, allowing only unrestricted data to be communicated outside the trusted platform, thereby reducing the need for widespread encryption and enhancing data privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data encryption is applied to protect restricted data in edge devices, then data privacy is preserved, but computational overhead and memory resource consumption increase significantly

Engineering Contradiction:
Improvedata privacyVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments data into restricted data and unrestricted data categories. Only unrestricted data is transmitted outside the trusted platform, eliminating the need for encryption of all data. This segmentation approach reduces computational overhead while maintaining data privacy for restricted data that remains within the secure environment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security measures to different data types based on their sensitivity. Restricted data receives full protection through confinement to the trusted platform, while unrestricted data is allowed to communicate freely. This localized security approach optimizes resource usage by applying encryption-like protection only where necessary.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If all data is encrypted and transmitted outside the trusted platform, then data accessibility is improved, but security risks increase and resource consumption increases

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides data into restricted and unrestricted categories, allowing unrestricted data to be easily accessible outside the trusted platform while keeping restricted data secure within the platform. This segmentation enables selective accessibility without compromising overall security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The trusted platform acts as an intermediary that mediates access to restricted data. Applications can request data through controlled interfaces, and the platform selectively provides unrestricted data while protecting restricted data. This intermediary mechanism balances accessibility and security by controlling the flow of information.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If edge devices perform full data processing and encryption, then data privacy is maintained, but device complexity and resource requirements increase

Engineering Contradiction:
Improvedata privacyVSAvoidedge device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the heavy encryption and security management functions from edge devices and relocates them to the trusted platform. Edge devices only need to communicate unrestricted data through controlled interfaces, significantly reducing their complexity and resource requirements while maintaining overall data privacy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The trusted platform serves as an intermediary that handles complex security operations. Edge devices interact with this intermediary through simplified interfaces, avoiding the need to implement complex encryption and security management locally. This reduces edge device complexity while maintaining security through the intermediary's protection mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11868501B2System device and method for managing access to data in an automation environment
Publication Date: 2024.01.09 SIEMENS AG
  • US11868501B2 patent drawing
  • US11868501B2 patent drawing
  • US11868501B2 patent drawing

AI summary

A system device and a method for managing access to data in an automation environment are disclosed. The data is associated with assets in an automation environment, where the data includes one of restricted data and unrestricted data. The automation environment is accessible via one or more computing platforms including a plurality of computing resources that are classifiable into a trusted computing platform and a non-trusted computing platform. The method includes classifying analytics operations performable on the data into a first operation set that is executable on the trusted computing platform. The analytics operations are associated with one or more applications executable on at least one of the computing platforms. The method includes enabling access to at least one of the unrestricted data and a first unrestricted output of the first operation set outside the trusted computing platform by a communication operation.