Securing data sent between computing devices
Methods and systems for securing data are disclosed. The data may be secured by encrypting the data. The data may be sent from one edge device to another edge device. To secure the transmission of the data between edge devices, the selection of an encryption algorithm to encrypt the data may be based on progressive rules and other attributes. The progressive rules may be determined by an edge orchestrator and send to all edge devices. The other attributes may include identifiers of the one edge device and the other edge device and classification of the data.
1 . A method for securing data, the method comprising:
obtaining, by a first edge device, the data for encryption by the first edge device;
obtaining, by the first edge device and from an edge orchestrator, first progressive rules that are regularly updated, the first progressive rules being determined based on a first current time from a global time standard and on classifications of data sensitivity;
obtaining, by the first edge device, a classification of sensitivity of the data;
selecting, by the first edge device, an encryption algorithm and a public key based at least in part on the classification of the sensitivity of the data and using the first progressive rules;
encrypting, by the first edge device, the data with the encryption algorithm using the public key to obtain encrypted data;
sending, by the first edge device, the encrypted data and the classification to a second edge device;
obtaining, by the first edge device and from another edge device, second encrypted data and a second classification;
obtaining, by the first edge device and from the edge orchestrator, second progressive rules based on a second current time from the global time standard and on the classifications of data sensitivity;
selecting, by the first edge device, a decryption algorithm and a private key based at least in part on the second classification using the second progressive rules; and
decrypting, by the first edge device, the second encrypted data with the decryption algorithm using the private key to obtain second data.
2 . The method of claim 1 , wherein the first progressive rules and the second progressive rules indicate different encryption algorithms are to be used while the first progressive rules and second progressive rules are in force, and the first progressive rules and second progressive rules being in force during different periods of time.
3 . The method of claim 2 , further comprising:
providing, by the first edge device, computer implemented services using the second data.
4 . The method of claim 1 , wherein selecting the encryption algorithm and the public key comprises:
obtaining an identifier of the first edge device;
obtaining an identifier of the second edge device; and
performing a lookup in the first progressive rules using the identifier of the first edge device, the identifier of the second edge device, and the classification to obtain an identifier of the encryption algorithm and an identifier of the public key.
5 . The method of claim 4 , wherein encrypting the data comprises:
configuring an encryption application to perform the encryption algorithm using the identifier of the encryption algorithm to obtain a configured encryption application; and
ingesting the data and the public key into the configured encryption application using the identifier of the public key to obtain the encrypted data.
6 . The method of claim 4 , further comprising:
providing, by the first edge device, computer implemented services using the second data.
7 . The method of claim 1 , further comprising:
providing, by the first edge device, computer implemented services using the second data.
8 . A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations for securing data, the operations comprising:
obtaining, by a first edge device, the data for encryption by the first edge device;
obtaining, by the first edge device and from an edge orchestrator, first progressive rules based on a first current time from a global time standard and on classifications of data sensitivity;
obtaining, by the first edge device, a classification of sensitivity of the data;
selecting, by the first edge device, an encryption algorithm and a public key based at least in part on the classification of the sensitivity of the data and using the first progressive rules;
encrypting, by the first edge device, the data with the encryption algorithm using the public key to obtain encrypted data; and
sending, by the first edge device, the encrypted data and the classification to a second edge device;
obtaining, by the first edge device and from another edge device, second encrypted data and a second classification;
obtaining, by the first edge device and from the edge orchestrator, second progressive rules based on a second current time from the global time standard and on the classifications of data sensitivity;
selecting, by the first edge device, a decryption algorithm and a private key based at least in part on the second classification using the second progressive rules; and
decrypting, by the first edge device, the second encrypted data with the decryption algorithm using the private key to obtain second data.
9 . The non-transitory machine-readable medium of claim 8 , wherein the first progressive rules and the second progressive rules indicate different encryption algorithms are to be used while the first progressive rules and second progressive rules are in force, and the first progressive rules and second progressive rules being in force during different periods of time.
10 . The non-transitory machine-readable medium of claim 9 , the operations further comprising:
providing, by the first edge device, computer implemented services using the second data.
11 . The non-transitory machine-readable medium of claim 8 , wherein selecting the encryption algorithm and the public key comprises:
obtaining an identifier of the first edge device;
obtaining an identifier of the second edge device; and
performing a lookup in the first progressive rules using the identifier of the first edge device, the identifier of the second edge device, and the classification to obtain an identifier of the encryption algorithm and an identifier of the public key.
12 . The non-transitory machine-readable medium of claim 11 , wherein encrypting the data comprises:
configuring an encryption application to perform the encryption algorithm using the identifier of the encryption algorithm to obtain a configured encryption application; and
ingesting the data and the public key into the configured encryption application using the identifier of the public key to obtain the encrypted data.
13 . The non-transitory machine-readable medium of claim 11 , the operations further comprising:
providing, by the first edge device, computer implemented services using the second data.
14 . The non-transitory machine-readable medium of claim 8 , the operations further comprising:
providing, by the first edge device, computer implemented services using the second data.
15 . A data processing system, comprising:
a processor; and
a memory coupled to the processor to store instructions, which when executed by the processor, cause the processor to perform operations for securing data, the operations comprising:
obtaining, by a first edge device, the data for encryption by the first edge device;
obtaining, by the first edge device and from an edge orchestrator, first progressive rules based on a first current time from a global time standard and on classifications of data sensitivity;
obtaining, by the first edge device, a classification of sensitivity of the data;
selecting, by the first edge device, an encryption algorithm and a public key based at least in part on the classification of the sensitivity of the data and using the first progressive rules;
encrypting, by the first edge device, the data with the encryption algorithm using the public key to obtain encrypted data;
sending, by the first edge device, the encrypted data and the classification to a second edge device;
obtaining, by the first edge device and from another edge device, second encrypted data and a second classification;
obtaining, by the first edge device and from the edge orchestrator, second progressive rules based on a second current time from the global time standard and on the classifications of data sensitivity;
selecting, by the first edge device, a decryption algorithm and a private key based at least in part on the second classification using the second progressive rules; and
decrypting, by the first edge device, the second encrypted data with the decryption algorithm using the private key to obtain second data.
16 . The data processing system of claim 15 , wherein the first progressive rules and the second progressive rules indicate different encryption algorithms are to be used while the first progressive rules and second progressive rules are in force, and the first progressive rules and second progressive rules being in force during different periods of time.
17 . The data processing system of claim 16 , the operations further comprising:
providing, by the first edge device, computer implemented services using the second data.
18 . The data processing system of claim 15 , wherein selecting the encryption algorithm and the public key comprises:
obtaining an identifier of the first edge device;
obtaining an identifier of the second edge device; and
performing a lookup in the first progressive rules using the identifier of the first edge device, the identifier of the second edge device, and the classification to obtain an identifier of the encryption algorithm and an identifier of the public key.
19 . The data processing system of claim 18 , wherein encrypting the data comprises:
configuring an encryption application to perform the encryption algorithm using the identifier of the encryption algorithm to obtain a configured encryption application; and
ingesting the data and the public key into the configured encryption application using the identifier of the public key to obtain the encrypted data.
20 . The data processing system of claim 15 , the operations further comprising:
providing, by the first edge device, computer implemented services using the second data.