How to Convince Your Security Team That Your AI App Is Secure Enough for the Edge�
Based on true stories
Erik Nordmark, ZEDEDA
#onesummit
Original Cloud-Native System
IoT Gateway
#onesummit
Desired Edge Cloud-Native System
Edge Server w GPU
#onesummit
Lab Edge Cloud-Native System
#onesummit
Real-world Deployment
#onesummit
Real-world Issues - Connectivity
#onesummit
Real-world Issues - Power
#onesummit
Then Security Happens
#onesummit
Security Review Questions
#onesummit
Security Review Questions (more specific)
#onesummit
DIY Edge Security Approach
#onesummit
DIY Edge Security Approach
#onesummit
Project EVE Approach
SaaS
Web Console
Edge Virtualization Engine (EVE)
Any Gateway at IoT Scale
Hardware
Free self-service
SaaS
Open Source
EVE API
App Marketplace
Any Application
VM or Container
APP
APP
APP
APP
No Compromise to Security
(TPM and vTPM)
Historian, SCADA
or On-Premises System
Any Cloud
Adam
Controller
Eden driver
Sandbox
#onesummit
EVE Architecture
containerd
User Edge Compute Hardware
Open API
Partition A
Partition B
EVE managed, workload-centric storage
EVE services
EVE Controller
Disk overhead: 500M
RAM overhead: 500M�CPU overhead: 1 core
Hypervisor (Xen, KVM, ACRN)
On host/dom0
Dom 2
Dom 1
EVE Controller
#onesummit
EVE Robustness Elements
#onesummit
EVE Robustness and Security Elements
#onesummit
Example EVE Security - handle stolen disk or server
#onesummit
Join us - as Users or Developers
#onesummit
#onesummit