Safe and credible Internet of Things edge computing gateway

By combining generative adversarial deception modules, zero-knowledge proof modules, and decentralized threat intelligence modules with generative adversarial networks and blockchain technology, the passive defense and privacy leakage problems of IoT edge computing gateways are solved, achieving highly realistic dynamic defense and real-time intelligence sharing, thereby improving the network's defense and collaborative response capabilities.

CN122069110APending Publication Date: 2026-05-19CHENGDU ZONGHENG INTELLIGENT CONTROL TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHENGDU ZONGHENG INTELLIGENT CONTROL TECH CO LTD
Filing Date
2026-04-20
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

IoT edge computing gateways face problems such as passive defense, easy detection of static honeypots, privacy leaks of device status, threat intelligence silos, and slow response, making it difficult to deal with advanced persistent threats.

Method used

By employing generative adversarial deception modules, zero-knowledge proof modules, and decentralized threat intelligence modules, and combining generative adversarial networks, zero-knowledge proofs, and blockchain technologies, an intelligent security hub is constructed to achieve proactive detection, federated learning, and trusted intelligence sharing.

Benefits of technology

It achieves dynamic defense against highly realistic deception environments, proactively identifies latent threats, protects privacy, and enables real-time intelligence sharing, thereby enhancing the network's defense capabilities and collaborative response capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122069110A_ABST
    Figure CN122069110A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of network security, and discloses a secure and credible Internet of Things edge computing gateway, which comprises a generative countermeasure deception module, which internally comprises a generator and a discriminator, and dynamically generates a high-simulation virtual deception service through countermeasure training to trap attacks; the zero-knowledge subnet certification module is used for generating a local certification and a Hash commitment by coordinating downlink equipment and generating an aggregated zero-knowledge certification based on an encryption accumulator so as to confirm the overall state of the equipment cluster on the premise of protecting privacy; and the decentralized threat intelligence module packages the captured attack features into verifiable digital certificates, realizes credible threat intelligence sharing among multiple gateways by calling an intelligent contract deployed in a block chain, and feeds the shared intelligence back to the generative anti-cheating module to update a cheating strategy of the generative anti-cheating module. According to the invention, the gateway is converted into an intelligent security center with intelligent confrontation, active detection and federal defense capabilities.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the fields of Internet of Things (IoT), edge computing, and network security technology, and specifically relates to a secure and reliable IoT edge computing gateway. Background Technology

[0002] As a key node connecting the physical and digital worlds, IoT edge computing gateways are facing increasingly severe and sophisticated cybersecurity threats. Traditional defense methods, such as firewalls and static intrusion detection systems, are mostly passive and reactive, making them inadequate for dealing with zero-day attacks and advanced persistent threats.

[0003] To enhance proactiveness, existing technologies have employed honeypot deployments to lure attacks; however, these honeypots are typically static and easily detected by attackers. Meanwhile, to establish trust among edge nodes for collaborative computing, some solutions use blockchain to record device status. However, traditional integrity proof methods may leak sensitive device information and are merely passive records of status, failing to proactively detect latent threats. Furthermore, threat intelligence captured by individual edge nodes often forms information silos, lacking a reliable and efficient mechanism for sharing this intelligence and establishing coordinated defenses, resulting in a slow response of the entire IoT system to new types of attacks. Summary of the Invention

[0004] This invention aims to at least partially solve the aforementioned technical problems. Therefore, the objective of this invention is to provide a secure and reliable IoT edge computing gateway that, through the integration of a collaborative mechanism of generative anti-spoofing, zero-knowledge proof proactive detection, and decentralized threat intelligence federation, transforms the gateway from a passive defense node into an intelligent security hub with intelligent adversarial, proactive detection, and federated learning capabilities.

[0005] The technical solution adopted in this invention is as follows:

[0006] A secure and reliable IoT edge computing gateway includes a processor, a memory, and multiple functional modules stored in the memory and executed by the processor.

[0007] The multiple functional modules include the following three core modules that work together:

[0008] Generative Adversarial Deception Module: This module is configured to dynamically generate one or more virtual deception services that mimic the behavior of real network services, protocols, or devices using Generative Adversarial Network (GAN) technology. These services serve as highly realistic decoys, designed to proactively capture, identify, and analyze network attack behaviors targeting this gateway and its downstream devices, thereby securely collecting attack samples and attacker behavioral characteristics.

[0009] Zero-Knowledge Subnet Proof Module: This module is configured to coordinate a group(s) of IoT devices connected to it to generate an aggregated zero-knowledge proof. The core function of this proof is to verify to a verifier (such as a cloud platform or other gateway) that the overall state of the group of IoT devices conforms to a preset security policy without disclosing the specific state information of any individual device (such as firmware version, IP address, configuration parameters, etc.).

[0010] Decentralized Threat Intelligence Module: This module is configured to encapsulate attack signatures (such as malware signatures and attack traffic patterns) captured by the generative adversarial deception module during the trapping attack process into a standardized, verifiable digital credential. Subsequently, this module interacts with a smart contract deployed on a consortium blockchain to achieve trusted, efficient, and automated sharing of this threat intelligence among multiple IoT edge computing gateways.

[0011] To achieve the aforementioned generative anti-spoofing functionality, the generative anti-spoofing module includes a generator and a discriminator in its specific implementation. The generator is a neural network model specifically designed to create the virtual spoofing service; the discriminator is another neural network model configured to learn and distinguish between the traffic characteristics of real network services and the data generated when the attacker interacts with the virtual spoofing service, and outputs a feedback signal based on the distinction result. This feedback signal guides the generator to iteratively optimize, continuously improving the realism and deception effect of the created virtual spoofing service.

[0012] To ensure the efficiency and security of zero-knowledge proofs, the zero-knowledge proofs generated by the zero-knowledge subnet proof module are preferably zk-SNARK (zero-knowledge concise non-interactive knowledge proof) or zk-STARK (zero-knowledge scalable transparent knowledge proof) proofs. Meanwhile, the specific content of the preset security policy can be a combination of one or more security rules. In one specific embodiment, this policy is defined as follows: the firmware hash value of each device in the group of IoT devices is within a predefined firmware version whitelist maintained by the gateway or synchronized from the cloud.

[0013] To transform a passive state proof process into an active threat detection action, the zero-knowledge subnet proof module is further configured to interact with the generative adversarial deception module. Specifically, during the process of coordinating downstream devices to generate the zero-knowledge proof, it proactively obtains from the generative adversarial deception module and injects one or more deceptive challenges targeting fictitious targets (such as a non-existent IP address or service port) into the downstream device subnet. Normal devices will ignore these challenges, while abnormal devices infected with malware and performing network scans may respond. This module proactively identifies abnormal devices within the subnet by monitoring and analyzing the devices' responses to these deceptive challenges.

[0014] To ensure the standardization and interoperability of threat intelligence, the verifiable digital credential encapsulated in the decentralized threat intelligence module is a digital object conforming to the W3C Verifiable Credential standard. The data structure of this credential explicitly contains the payload of the threat intelligence, which may specifically include: the hash value of the attack payload, a digital description of the network behavior pattern of the attack source, or the binary signature of specific malware.

[0015] To achieve decentralized consensus on threat intelligence, the decentralized threat intelligence module is configured to initiate a consensus voting process within the blockchain network by submitting a verifiable digital credential containing newly discovered threat intelligence to the smart contract. Other member gateways in the network will verify and vote on the validity of the credential. When the number of participating nodes and the approval ratio meet the preset conditions in the smart contract, the smart contract will automatically execute and write the threat intelligence contained in the credential into the blockchain's distributed ledger, completing a trusted record.

[0016] To construct a closed-loop, adaptive defense system, the decentralized threat intelligence module is further configured to perform a reverse information synchronization operation. It periodically reads threat intelligence shared by other gateways and confirmed through consensus from the blockchain, and inputs this latest, reliable intelligence into the local generative adversarial deception module to update its deception strategy.

[0017] As a concrete implementation of the updated deception strategy, the generative adversarial deception module is configured to intelligently adjust its behavior in generating virtual deception services after receiving the latest threat intelligence read from the blockchain. Specific adjustments include, but are not limited to: simulating the type of protocol (e.g., generating a virtual CoAP service against a newly discovered CoAP protocol attack), simulating vulnerability features (e.g., simulating a vulnerability with a specific CVE number), or adjusting response data to more accurately match the attacker's probing behavior, thereby achieving targeted trapping of known attack types.

[0018] To extend the trust capabilities of this gateway to collaborative computing scenarios, the multiple functional modules further include a collaborative computing admission control module. This module is configured to request and verify the validity of the latest zero-knowledge proofs generated by the respective zero-knowledge subnet proof modules of other participants before this gateway needs to join a distributed computing task (such as federated learning, distributed data processing, etc.) involving other edge computing gateways. This serves as admission credentials for participating in collaborative computing, ensuring that all participating node clusters are in a secure and trustworthy state.

[0019] To ensure the security of the gateway's core functions and sensitive data, the gateway of this invention also includes a trusted execution environment. This trusted execution environment is a hardware-isolated secure area used to securely perform the following critical operations: securely storing and executing the discriminator model of the generative anti-spoofing module to prevent the model from being stolen or tampered with; providing a secure computing environment for the generation process of the zero-knowledge proof, protecting intermediate computational states from being leaked; and securely storing the private key used to sign the verifiable digital credentials to ensure the unforgeability of the intelligence source.

[0020] The beneficial effects of this invention are as follows:

[0021] This invention utilizes generative adversarial networks to transform defenses from static traps into dynamically evolving deceptive environments, enabling more effective trapping and analysis of advanced, persistent attacks, thus achieving intelligent and adversarial defense.

[0022] This invention combines the privacy-preserving characteristics of zero-knowledge proofs with the proactive detection function of deceptive challenges, achieving a synergistic effect that can prove subnet security without compromising privacy, while also proactively discovering latent threats in the process.

[0023] This invention utilizes blockchain, smart contracts, and verifiable credentials to construct a decentralized, automated, and trustworthy threat intelligence sharing and response system, enabling the discovery of a single node to be transformed into the collective defense capability of the entire network in near real time.

[0024] The three core modules of this invention are not simply superimposed, but form a complete and self-consistent technical closed loop of "deception capture - detection verification - intelligence sharing - feedback deception". Its overall architecture and the technical effects produced by the collaboration have significant progress. Attached Figure Description

[0025] Figure 1 This is a block diagram illustrating the functional structure and collaborative relationships of the IoT edge computing gateway of the present invention. Detailed Implementation

[0026] The technical solutions of the present invention will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.

[0027] like Figure 1 As shown in the figure, the core functions of a secure and reliable IoT edge computing gateway in this embodiment are implemented by multiple collaborative software modules running on a processor.

[0028] The Generative Adversarial Deception module aims to construct a dynamically evolving, highly realistic deception environment. Its core is a Generative Adversarial Network (GAN), specifically implemented as follows:

[0029] The generator is a deep neural network, preferably a Long Short-Term Memory (LSTM) network or a variant thereof (such as GRU), because it excels at learning and generating data with time-series characteristics. Its input is a random noise vector, and optionally, a conditional vector (e.g., a specific attack type label obtained from a decentralized threat intelligence module). Its output is a simulated sequence of network traffic packets or an executable virtual service configuration, such as a simulated Modbus TCP slave service with a known CVE vulnerability.

[0030] The discriminator is another deep neural network, preferably a convolutional neural network (CNN), because it can effectively extract spatial and structural features from the raw traffic data. Its input is a network traffic sample (which can come from the real network or from the generator), and its output is a scalar value representing the probability that the input sample is real.

[0031] The goal of the training process is to teach the generator to deceive the discriminator. The adversarial training process is as follows:

[0032] Step 1.1, Data Preparation: Collect two types of datasets: real traffic datasets (traffic from normal devices and services connected to the gateway) and attack traffic datasets (known attack samples or attack traffic captured through other honeypots).

[0033] Step 1.2, Discriminator Training: Fix the generator parameters, sample from the real traffic dataset, and have the generator produce a batch of fake traffic data. Feed both batches of data to the discriminator simultaneously, and calculate the loss based on the difference between the discriminator's prediction and the real label. This loss is used to update the discriminator's network weights, making it more discriminative.

[0034] Step 1.3, Generator Training: With the discriminator parameters fixed, the generator generates a new batch of fake traffic data and feeds it to the discriminator. The generator's goal is to mislead the discriminator into believing this fake data is real. Therefore, the discriminator's output (the probability of judging it as real) is used as the generator's optimization objective. The loss is calculated and backpropagated to update the generator's network weights. To ensure training stability, the Wasserstein loss function combined with gradient penalty (WGAN-GP) is preferred.

[0035] Step 1.4, Alternating Iteration: Repeat steps 1.2 and 1.3 until the discriminator can no longer effectively distinguish between generated data and real data. At this point, the generator has the ability to generate highly realistic deception services.

[0036] After training, the generator is deployed on the gateway. When the decentralized threat intelligence module synchronizes a piece of intelligence about a new CoAP protocol attack from the blockchain, the characteristics of this intelligence (such as protocol type and attack payload pattern) are encoded into a conditional vector and input to the generator. Based on this, the generator creates a highly realistic virtual CoAP service as bait. When an attacker interacts with this service, all traffic and behavioral data are fully recorded for subsequent analysis and generation of new threat intelligence.

[0037] The zero-knowledge subnet proof module is used to efficiently prove the overall security of its downstream device cluster while protecting privacy. To achieve this, this invention proposes an aggregation proof scheme based on Merkle trees.

[0038] In one embodiment, the default security policy is defined as "the firmware hash of all downstream devices must be within a known security version whitelist". This whitelist is pre-built as a Whitelist Merkle Tree, and its root hash (Whitelist Root) is exposed and stored in the gateway.

[0039] The aggregation proof generation process is as follows:

[0040] Step 2.1, Device-side - Local Certificate Generation: The gateway sends a certificate request to each downstream device. Each device performs the following operations:

[0041] a. Calculate the hash value of its current firmware.

[0042] b. Obtain the Merkle Path of its firmware hash in the whitelisted Merkle tree from the gateway.

[0043] c. Generate a local zk-SNARK proof that confirms "I know a firmware hash and a Merkle path that can correctly compute the publicly available whitelist root hash".

[0044] d. Calculate the hash commitment of the Local Proof and send this commitment to the gateway.

[0045] Step 2.2, Gateway Side - Prove Aggregation: The gateway performs the following operations:

[0046] a. Collect all hash commitments sent by all devices.

[0047] b. Using these commitments as leaf nodes, construct a new commitment Merkle tree and calculate its root hash.

[0048] c. Generate a top-level aggregated zk-SNARK proof. The core of this proof is to demonstrate that: "I know a commitment Merkle tree whose root hash is Commitment Root, and I know that the original data (i.e., Local Proof) corresponding to each leaf node of the tree is a valid local proof."

[0049] Step 2.3, Proof Delivery: The gateway ultimately provides the verifier (such as the cloud platform) with this single, concise Aggregated Proof and Commitment Root. The verifier only needs to verify this aggregated proof to be certain that the firmware of all downstream devices is secure, without needing to know the firmware information of any individual device throughout the process.

[0050] When initiating the aforementioned aggregated proof generation process, the zero-knowledge subnet proof module requests a deceptive challenge from the generative anti-spoofing module, such as a PING request against a fictitious IP address. This request is broadcast along with proof coordination instructions. Legitimate devices will ignore this invalid request, but infected devices performing network scans may respond, thus being captured by the gateway.

[0051] The decentralized threat intelligence module builds a trusted, automated federated threat intelligence network.

[0052] Once the generative adversarial deception module detects an attack, the decentralized threat intelligence module generates a verifiable digital credential (VC) compliant with W3C standards. Its data structure is as follows (JSON-LD format):

[0053] {

[0054] "@context": ["https: / / www.w3.org / 2018 / credentials / v1"],

[0055] "id": "urn:uuid:...",

[0056] "type": ["VerifiableCredential", "ThreatIntelligenceCredential"],

[0057] "issuer": "did:example:gateway123",

[0058] "issuanceDate": "2025-10-27T12:00:00Z",

[0059] "credentialSubject": {

[0060] "id": "did:example:attacker_ip_...",

[0061] "threatType": "Malware",

[0062] "indicator": {

[0063] "type": "FileHash",

[0064] "value": "sha256:...",

[0065] "algorithm": "SHA-256"

[0066] },

[0067] "networkPattern": "TCP port scan on ports 1000-2000"

[0068] },

[0069] "proof": { ...} / / Digital signature

[0070] }

[0071] The VC is signed by the gateway's private key stored in the TEE.

[0072] The gateway interacts with smart contracts deployed on the consortium blockchain. The smart contracts must contain at least the following core function interfaces:

[0073] 1. function proposeThreat(bytes32 vcHash, string vcUri) external: Called by the gateway that discovers the threat, submits the hash of the VC and the storage URI to create a new intelligence proposal.

[0074] 2. function voteOnProposal(uint proposalId, bool approval) external: Called by other member gateways to vote on the proposal.

[0075] 3. function resolveProposal(uint proposalId) external: Called by any node after the voting period ends. Based on the voting results (e.g., more than 2 / 3 of the members agree), the proposal status is updated to confirmed or rejected, and the confirmed vcHash is recorded in the on-chain state variable.

[0076] The workflow of the decentralized threat intelligence module is as follows:

[0077] S3.1, Capture and Generation: This gateway captures attacks, generates and signs VCs within the TEE.

[0078] S3.2, Proposal: Call the proposeThreat function to put the VC hash on the chain.

[0079] S3.3 Consensus: When other gateway nodes hear a new proposal, they download the original VC text for verification and analysis, and then call voteOnProposal to vote.

[0080] S3.4 Confirmation and Recording: After the vote is passed, resolveProposal is invoked, and the threat intelligence is officially recorded as trusted intelligence.

[0081] S3.5 Synchronization and Feedback: This module of this gateway and all other gateways will periodically read the confirmed threat intelligence list from the chain and provide it to their respective generative adversarial deception modules as conditional vectors to update and optimize deception strategies, forming a defense closed loop.

[0082] When this gateway wants to join a federated learning task, the collaborative computing admission control module requires other participating gateways to provide their latest aggregated zero-knowledge proofs. The collaborative computing admission control module uses the public verification keys of these gateways to verify the validity of these proofs. Only gateways with valid proofs are allowed to join the collaborative computing, thus ensuring the baseline trustworthiness of the entire computing cluster.

[0083] A Trusted Execution Environment (TEE) is a hardware-isolated security zone (such as Intel SGX or ARM TrustZone). It provides protection for critical assets and operations.

[0084] 1. Secure storage: The TEE securely stores the discriminator model file, the gateway private key used to sign the VC, and the proving key used to generate ZKP.

[0085] 2. Secure computation: The signing process of VC and the generation process of ZKP are executed within TEE to prevent the leakage of sensitive keys and intermediate computation values.

[0086] 3. Secure Call: The gateway's operating system (non-secure world) interacts with the TEE (secure world) through a well-defined secure API, such as calling a signVC(vc_payload) function, which completes the signing within the TEE and returns the signing result, while the private key never leaves the TEE.

[0087] Through the above embodiments, the IoT edge computing gateway of the present invention not only elaborates on the internal implementation details of each module, but more importantly, reveals the deep collaborative mechanism between them, forming a complete, self-consistent, and reproducible intelligent security defense system.

[0088] This invention is not limited to the above-described optional embodiments. Anyone can derive other various forms of products under the guidance of this invention. However, regardless of any changes made in their shape or structure, any technical solution that falls within the scope of the claims of this invention shall be protected by this invention.

Claims

1. A secure and reliable IoT edge computing gateway, characterized in that, It includes a processor, a memory, and multiple functional modules stored in the memory and executed by the processor; The multiple functional modules include: A generative anti-spoofing module includes a generator and a discriminator. The generator is configured to dynamically generate virtual spoofing services, and the discriminator is configured to distinguish between real network traffic and the interaction traffic of the virtual spoofing services, and generate a feedback signal. The feedback signal is used to guide the generator to iteratively optimize the generated virtual spoofing services in order to lure network attacks. The zero-knowledge subnet proof module is configured to: coordinate a group of IoT devices connected to it to generate local proofs and hash commitments about their own state; collect all hash commitments of the group of IoT devices to construct a cryptographic accumulator; and generate an aggregated zero-knowledge proof based on the cryptographic accumulator and all local proofs. This aggregated zero-knowledge proof is used to verify that the overall state of the group of IoT devices conforms to a preset security policy without disclosing the specific state information of individual devices. The decentralized threat intelligence module is configured to: encapsulate the attack features captured by the generative adversarial deception module into a verifiable digital credential; submit the digital credential to initiate a consensus process among multiple gateways by invoking a smart contract deployed on the blockchain; and periodically read consensus-confirmed threat intelligence from the blockchain and provide the intelligence as a conditional input to the generative adversarial deception module to update its deception strategy.

2. The IoT edge computing gateway according to claim 1, characterized in that, The cryptographic accumulator is a Merkle tree, and the aggregated zero-knowledge proof is used to verify the correctness of a Merkle tree root hash, and at the same time verify that the local proof corresponding to each leaf node of the Merkle tree is valid.

3. The IoT edge computing gateway according to claim 1, characterized in that, The preset security policy includes ensuring that the firmware hash value of each device in the group of IoT devices is within a predefined whitelist stored in the form of a Merkle tree; the local proof is a zero-knowledge proof that the firmware hash of the corresponding device is a leaf node in the whitelist Merkle tree.

4. The IoT edge computing gateway according to claim 1, characterized in that, The zero-knowledge subnet proof module is further configured to, during the process of coordinating the generation of the aggregated zero-knowledge proof, obtain from the generative adversarial deception module and inject one or more deceptive challenges against fictitious targets into downstream devices, and identify anomalous devices based on the devices' responses to the deceptive challenges.

5. The IoT edge computing gateway according to claim 1, characterized in that, The verifiable digital credential is a digital object that conforms to the W3C Verifiable Credentials standard, and its content includes the hash value of the attack payload, the network behavior pattern of the attack source, or the signature of the malware.

6. The IoT edge computing gateway according to claim 1, characterized in that, The smart contract defines interface functions for submitting threat intelligence proposals, voting on proposals, and recording the intelligence to the blockchain when the voting meets preset consensus conditions.

7. The IoT edge computing gateway according to claim 1, characterized in that, The generative anti-spoofing module adjusts the protocol type, vulnerability characteristics, or response data simulated by the virtual spoofing service it generates based on threat intelligence read from the blockchain, in order to specifically lure known attack types.

8. The IoT edge computing gateway according to claim 1, characterized in that, The plurality of functional modules also include: The collaborative computing admission control module is configured to require and verify the validity of the latest aggregated zero-knowledge proofs provided by the other participating gateways and generated by their respective zero-knowledge subnet proof modules before joining a distributed computing task involving other edge computing gateways.

9. The IoT edge computing gateway according to claim 1, characterized in that, It also includes a trusted execution environment, which is securely configured internally: Store and execute the discriminator model of the generative anti-spoofing module; The proof key used to generate the zero-knowledge proof of the aggregate is stored; and Store the private key used to sign the verifiable digital certificate.

10. The IoT edge computing gateway according to claim 1, characterized in that, The generator is a long short-term memory network, and the discriminator is a convolutional neural network.