A highly integrated edge computing security gateway with end-to-end encryption suitable for industrial environments

By integrating firewall, routing, switching, storage, and encryption/decryption modules, the edge computing security gateway solves the problems of low integration and poor security of industrial field devices, and achieves efficient and secure data transmission and processing.

CN115694920BActive Publication Date: 2026-05-26CHINA TRANSPORT INFORMATION TECH GRP CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA TRANSPORT INFORMATION TECH GRP CO LTD
Filing Date
2022-10-11
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Existing industrial site security gateway devices have low integration, poor security, and poor scalability, resulting in redundant deployment and wasted resources. Furthermore, they cannot achieve high-level encrypted transmission at low-level nodes and links, increasing the cost and failure risk at the project site.

Method used

It adopts a fully encrypted, highly integrated edge computing security gateway, which integrates firewall, routing, switching, storage, edge computing power and high and low computing power encryption and decryption modules. It is connected through a high-speed data bus to achieve high-strength encryption and flexible data processing capabilities, supporting lightweight applications and intensive data processing.

Benefits of technology

It improves the integration and security of equipment, reduces the number of devices and resource waste, reduces the burden of on-site commissioning and maintenance, and achieves security and efficiency of encrypted data transmission throughout the entire process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115694920B_ABST
    Figure CN115694920B_ABST
Patent Text Reader

Abstract

This invention discloses a highly integrated edge computing security gateway with end-to-end encryption suitable for industrial environments. It comprises a routing module with firewall functionality, a switching module, a storage module, an edge computing module, a high-performance security encryption / decryption module, a low-performance security encryption / decryption module, and an industrial field interface module. All modules are connected via an internal high-speed data bus. The routing module coordinates the operation of all modules within the security gateway. This invention can be applied to numerous fields with network security connectivity requirements, such as factories, construction sites, and transportation networks, significantly expanding the application scenarios of related equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to network security devices, and more particularly to a fully encrypted, highly integrated edge computing security gateway suitable for industrial environments. Background Technology

[0002] In industrial field networks, security gateways that combine firewall and gateway functions are frequently used. These security gateways combine firewall and gateway functions through software or hardware, integrating network and security functions to a certain extent, reducing the number of devices and making deployment easier. However, existing security gateways still suffer from the following problems: 1. Low device integration, typically requiring supporting network transmission equipment such as switches to complete network construction and deployment; 2. Poor device security, lacking effective high-strength encryption measures for external network transmission. Whenever high-level encrypted transmission is needed, regardless of the amount of encryption payload, dedicated encryption machines are required. This inevitably results in high-level encrypted transmission capabilities only being available on higher-level core information nodes, while lower-level nodes and links outside these core nodes cannot perform high-level encryption operations, leaving their data transmission unprotected; 3. Poor device scalability. Many lightweight applications in industrial settings, such as statistics, publishing, forms, and data collection, while having extremely low resource consumption, require additional servers and dedicated processing equipment, leading to significant waste of network interfaces, on-site equipment, and integration difficulties; 4. Even in projects with relatively small network loads, a large number of redundant devices must be deployed for security, resulting in huge waste of project site costs, space, and energy; 5. The large number of redundant devices creates a huge burden and risk of failure for on-site debugging and maintenance. Summary of the Invention

[0003] To address this, the present invention provides a highly integrated edge computing security gateway with end-to-end encryption suitable for industrial sites. This security gateway is more convenient for industrial site network construction and maintenance, significantly improves the gateway's functional integration and application flexibility, and greatly enhances the security of the entire transmission process.

[0004] To achieve the objectives of this invention, the following technical solution is adopted:

[0005] A highly integrated edge computing security gateway with end-to-end encryption suitable for industrial sites includes a routing module with firewall functionality, a switching module, a storage module, an edge computing power module, a high-computing-power security encryption / decryption module, a low-computing-power security encryption / decryption module, and an industrial site interface module. Each module is connected via an internal high-speed data bus. The routing module is used to coordinate the operation of each module in the security gateway.

[0006] The security gateway, wherein: the routing module runs on a low-computing-power routing chip and is used to coordinate and allocate computing resources and complete task switching.

[0007] The security gateway wherein: the routing module communicates at high speed with other internal modules through the switching module, or communicates directly with the switching module of a remote access device.

[0008] The security gateway, wherein the storage module is used to provide storage support for the local processing of lightweight computing tasks of data accessed by the security gateway.

[0009] The security gateway, wherein the high-computing-power security encryption / decryption module is used to perform hardware encryption / decryption processing on selected data within the module.

[0010] The security gateway, wherein the low-computing-power security encryption / decryption module is used to perform hardware encryption / decryption processing on the data communicated by the industrial field interface module within the module.

[0011] The security gateway, wherein: the high-computing-power security encryption / decryption module is used to establish an encrypted VPN channel through the local proxy service of the routing module, and to encrypt and decrypt data transmitted through the VPN channel. Attached Figure Description

[0012] Figure 1 A schematic diagram of the overall architecture of a fully encrypted, highly integrated edge computing security gateway suitable for industrial environments;

[0013] Figure 2 This is a schematic diagram of the overall architecture of the security module;

[0014] Figure 3 This diagram illustrates the distribution of high-performance and low-performance security encryption / decryption modules in security gateways and security terminals.

[0015] Figure 4 A schematic diagram of the connection structure between the high-performance security encryption / decryption module and the routing module;

[0016] Figure 5 A schematic diagram of the connection structure between the low-computing-power security encryption / decryption module and the routing module;

[0017] Figure 6 This is a schematic diagram of another working mode for the low-computing-power security encryption / decryption module. Detailed Implementation

[0018] The following is in conjunction with the appendix Figure 1-6 The specific embodiments of the present invention will be described in detail below.

[0019] like Figure 1As shown, the fully encrypted, highly integrated edge computing security gateway suitable for industrial sites of the present invention includes a routing module with firewall functionality, a switching module, a storage module, an edge computing power module, a high-computing-power security encryption / decryption module, a low-computing-power security encryption / decryption module, and an industrial site interface module.

[0020] The modules are connected via an internal high-speed data bus, and their operation is coordinated by firmware running within the routing module. This gives the highly integrated edge computing security gateway not only basic routing gateway, firewall, and switch functions, but also strong hardware encryption / decryption capabilities, high storage, and high computing power. This enables the gateway to handle the secure transmission of critical data in both public and private network environments, and to handle lightweight field applications as well as high-computing applications requiring intensive data processing.

[0021] The routing module with firewall functionality can run on a low-computing-power routing chip, coordinating and allocating computing resources through a Linux system to complete task switching. In this invention, the firewall and routing functions run entirely on a single processor, sharing CPU and RAM. Therefore, no additional hardware connection is required, and the most efficient RAM-level data transmission is utilized, ensuring a tight integration and efficient data exchange between the egress firewall and routing functions. Furthermore, the routing module's idle computing power (when both CPU and RAM usage are below the threshold) can simultaneously handle low-computing applications accessing data from the on-site security gateway.

[0022] The switching module and routing module are connected via a 1000BASE-TX (or similar) interface, ensuring high-speed data throughput and high flexibility. The routing module can communicate directly with other internal devices at high speed through the switching module, and can also communicate directly with remote devices connected to the switching module. Simultaneously, remote devices connected to the switching module can also communicate directly with each other through the switching module.

[0023] The switching module can support 1000BASE-TX (or higher) and 1000BASE-FX (or higher) interfaces, and is compatible with low-speed interface access, providing multiple options for flexible configuration of the compatibility of the gateway local and remote devices and the deployment distance of remote devices.

[0024] The switching module supports ring network protocols and port aggregation, laying the foundation for flexible configuration of gateway device connectivity and expansion of gateway performance. The switching module's ports support both electrical (TX) and optical (FX) interfaces, suitable for different connected devices, connection distances, and field environments. The electrical interface can be equipped with PoE functionality, supplying power to external devices according to standard PoE functions and handshake protocols. When cascading gateways, they can be configured in three modes: standard single-port mode, high-reliability ring network mode, and multi-port aggregation speed superposition mode. When multi-port aggregation is configured between two transmission devices (e.g., between security gateways or remote devices), the total speed is equivalent to the sum of the speeds of each port, while providing a certain degree of physical redundancy in reliability, but still remaining on the same link.

[0025] The storage module connects to the routing module via USB, mSATA (or similar interfaces), allowing direct read and write operations from the routing module's internal high-speed bus, ensuring high-speed data throughput and stable read / write performance. It can provide storage support for local processing of lightweight computing tasks that handle gateway access data.

[0026] like Figure 3 , 4 As shown, the high-performance encryption / decryption module connects to the routing module via USB, PCIe, or mSATA (or similar) interfaces. It can communicate directly from the routing module's internal high-speed bus, ensuring high-speed data throughput and stable encryption / decryption performance. Depending on transmission needs, the high-performance encryption / decryption module can utilize the routing module's local proxy service to establish an encrypted VPN channel. In this mode, all data transmitted through the VPN channel undergoes encryption / decryption processing. Because the encryption / decryption operations are entirely performed by the high-performance encryption / decryption module, with the routing module only coordinating data transmission, real-time encryption / decryption capabilities within the local system can be provided with minimal overhead on the routing module's processing power. This ensures that critical data transmitted through the security gateway is transmitted in encrypted form outside the gateway, providing powerful processing capabilities and robust anti-eavesdropping and anti-espionage security.

[0027] like Figure 5As shown, the low-computing-power security encryption / decryption module connects to the routing module via a UART (or similar) interface, enabling direct communication from the routing module's internal bus. This ensures a direct data communication link and stable encryption / decryption performance. The low-computing-power security encryption / decryption module is essentially a microsystem with independent computing and processing capabilities, featuring a dedicated encryption / decryption algorithm acceleration engine and dedicated storage space. Therefore, it can be paired with an industrial field interface module for direct measurement and control communication with other devices in the industrial field. Data communicated through the industrial field interface module can be encrypted / decrypted using algorithms such as AES, RSA, and ECC via the module's internal hardware acceleration resources. This provides low-speed real-time encryption / decryption capabilities within the local system with minimal impact on the routing module's processing power. It ensures that critical data transmitted through the security gateway is transmitted in encrypted form outside the gateway, providing efficient processing capabilities and robust security against eavesdropping and data theft.

[0028] like Figure 6 As shown, in addition to encrypting and decrypting data communicated by directly connected industrial field interface modules, the low-computing-power security encryption and decryption module can also encrypt and decrypt other data sent by the routing module (such as data from other industrial field interface modules on the local machine, some data sent by the security terminal, or other data that the local policy deems necessary to process).

[0029] like Figure 2 As shown, a terminal (referring to a non-gateway type, similar to the low-power security encryption / decryption module with an industrial field interface module described above, used for direct measurement and control communication with other devices (other field industrial equipment) in the industrial field, can be used in a standalone terminal for single-device measurement and control, also known as a low-cost terminal or secure terminal. This low-cost terminal can perform hardware encryption and decryption processing on the data communicated by the industrial field interface module within the module, and then conduct encrypted communication with a secure gateway that also has a low-power security encryption / decryption module. This ensures that critical data transmitted between the terminal and the secure gateway is transmitted in encrypted form outside the terminal and gateway, providing efficient processing capabilities and anti-eavesdropping and anti-espionage security capabilities.

[0030] Therefore, in the deployment and use of security gateways and security terminals, the low-computing-power encryption / decryption modules and high-computing-power encryption / decryption modules on the security terminals and security gateways can be turned on respectively according to the on-site project requirements.

[0031] In this invention, the following are examples of strategies that can be adopted: The security terminal or security gateway can also perform network security judgment. When it is determined that the network between the two is a secure network (e.g., an internal network), the security terminal does not perform encryption processing before transmitting data to the security gateway, or only performs encryption processing on key data (e.g., product processing technology, processing parameters, product structure, etc.) to save bandwidth and improve data transmission speed.

[0032] Security gateways can also determine whether to use encryption for data transmission between two communicating gateways based on the physical distance between them or the degree of IP address overlap. For example, if the distance between two security gateways does not exceed a predetermined distance (e.g., 100 kilometers), it can be determined that the two security gateways are communicating within the same city, so no encryption is required for the communication data or only for critical data. If the distance exceeds the predetermined distance, it is considered to be non-local communication, and all communication data is encrypted. For IP addresses, the degree of overlap between the IP addresses of the two security gateways from left to right can be determined based on whether it reaches or exceeds a predetermined value (e.g., 90%). If it does, the communication between the two security gateways is considered relatively secure, so no encryption is required for the communication data or only for critical data. If not, it is considered to be non-local communication, and all communication data is encrypted. Preferably, in order to better balance security and transmission bandwidth, the two security gateways in this invention first determine the physical distance and IP address overlap before communication. Only when both conditions are met, such as the distance between the two security gateways not exceeding the predetermined distance and the overlap of the IP addresses of the two security gateways from left to right reaching or exceeding the predetermined value, will the data transmission method of not encrypting the communication data or only encrypting the key data be selected when the two security gateways communicate.

[0033] This invention can also generate more complex encryption and decryption combinations depending on whether the data source is an external secure terminal or the local machine (e.g., secure terminal plaintext - gateway low encryption - gateway high encryption, secure terminal low encryption - gateway low decryption - gateway high encryption; these are all possible and reasonable combinations, which can be encrypted and decrypted separately or without additional processing. These encryption and decryption operations are performed in the corresponding hardware modules, hardly occupying the main computing power of the routing module).

[0034] Ultimately, in the external transmission of data through the security gateway, various encryption modes can be employed, including plaintext mode, high-computing-power encryption mode, low-computing-power encryption mode, and a combination of high-computing-power and low-computing-power encryption modes. Simultaneously, mixed transmission of ciphertext and plaintext with varying degrees of encryption is permitted, with each packet undergoing its own tagging and identification process. This enables end-to-end data encryption from data acquisition to processing and uploading, significantly improving transmission security and reducing the processing burden on the routing module.

[0035] Edge computing modules are high-performance computing systems independent of routing modules. They possess independent processors, RAM, external storage, and may even include inference accelerators (TPUs, optional) and human-machine interfaces (HDMI, etc., optional). They are designed for heavy computing tasks that the light computing power of routing modules cannot handle quickly, such as providing heavy-load task processing servers, AI computing power pattern recognition applications, etc., or serving as the human-machine interface for the entire gateway system. Edge computing modules do not participate in the routing processing functions or industrial control data processing functions of the routing module. Edge computing modules handle data throughput entirely through IP-based data packets, independently processing data and computationally intensive tasks.

[0036] Edge computing modules and routing modules can be directly connected via a 1000BASE-TX (or similar) interface, or indirectly connected via a switching module. This type of connection ensures high-speed data throughput and high flexibility. The latter can also bypass the routing module and communicate directly with the data source when handling heavy network data, thereby reducing the load on the routing module.

[0037] All of the above modules work together within the highly integrated edge computing security gateway to achieve complete network transmission, security encryption, and data processing services.

[0038] The highly integrated edge computing security gateway of the present invention fully integrates and solves most of the service and support needs of general network systems. It is very easy to deploy and has the advantages of small size, low power consumption and low cost.

[0039] The highly integrated edge computing security gateway of this invention can be configured with switching modules having two or more 1000BASE-FX (or higher) high-speed fiber optic interfaces. By configuring these two fiber optic interfaces in a ring network mode, a highly reliable ring network backbone network can be built in industrial sites using the switching modules of the highly integrated edge computing security gateway. In the highly reliable ring network backbone network, even if one fiber optic cable fails or is damaged, it can automatically switch to the other fiber optic cable, ensuring uninterrupted backbone network communication. Furthermore, the other 1000BASE-TX (or higher) high-speed electrical interfaces on the switching modules of the highly integrated edge computing security gateway can be connected to other nearby devices, such as other lower-level security gateways, other extended servers, storage devices, computers, security equipment, etc.

[0040] By deploying a highly integrated edge computing security gateway, the various functional modules within the gateway are comprehensively utilized. This allows for flexible fulfillment of most service and support needs in general network systems, resulting in a superior user experience and cost-effectiveness from an application perspective.

[0041] Highly integrated edge computing security gateways have the following advantages:

[0042] 1. It possesses the core functions of a firewall, routing gateway, industrial switch, and encryption machine, while simplifying the external network architecture and interface connections, making it easier to install, deploy, use, and maintain.

[0043] 2. The internal data flow can be deeply optimized, making it easier to improve performance.

[0044] 3. It can support lightweight computing applications that can synchronously process data accessed to the security gateway on-site.

[0045] 4. It can support intensive computing power and AI computing power applications at the desktop and rack level, and has powerful functional expansion capabilities.

[0046] 5. It has a human-computer interaction interface, which reduces the total on-site IT cost.

[0047] 6. It can be used as a core processing device to centrally process field data or as a convergence processing device to distribute field data.

[0048] 7. Establish a full-process encrypted application system that combines security gateways and security terminals.

[0049] 8. Form a high-strength, composite encryption application system that can combine high and low computing power hardware security encryption and decryption capabilities.

[0050] This invention can be used in many fields with network security connectivity requirements, such as factories, construction sites, and transportation networks, and can significantly expand the application scenarios of the corresponding equipment.

Claims

1. A full-encryption high-integration edge computing security gateway suitable for industrial sites, characterized in that: It includes a routing module with firewall functionality, a switching module, a storage module, an edge computing module, a high-computing-power security encryption / decryption module, a low-computing-power security encryption / decryption module, and an industrial field interface module. Each module is connected via an internal high-speed data bus. The routing module is used to coordinate the operation of each module in the security gateway. The spare computing power of the routing module is used for lightweight computing applications that process data accessed by the on-site security gateway. The high-computing-power security encryption / decryption module is used to perform hardware encryption / decryption processing on selected data within the module. It also establishes an encrypted VPN channel through the local proxy service of the routing module and performs encryption / decryption processing on data transmitted through the VPN channel. The low-computing-power security encryption / decryption module communicates directly with the internal bus of the routing module and performs hardware encryption / decryption processing on data communicated by the industrial field interface module within the module. Before communication, the security gateway first determines the physical distance and IP address overlap between the two security gateways. Only when both conditions are met—that the distance between the two security gateways does not exceed a predetermined distance and the overlap of their IP addresses from left to right reaches or exceeds a predetermined value—will the security gateway choose not to encrypt the communication data or only encrypt critical data during communication.

2. The security gateway of claim 1, wherein: The routing module runs on a low-computing-power routing chip and is used to coordinate and allocate computing resources and complete task switching.

3. The security gateway of claim 1, wherein: The routing module communicates at high speed with other internal modules through the switching module, or communicates directly with the switching module of a remote access device.

4. The security gateway of claim 1, wherein: The storage module provides storage support for the local processing of lightweight computing tasks that access data from the security gateway.