A plug-and-play AI security gateway serially connected at a broadband portal

CN122824544APending Publication Date: 2026-09-25廖长林
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611117799.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-27
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

[0002]现有AI能力部署存在以下缺陷:AI能力均为单设备部署,手机、电脑、电视等需要单独安装AI应用、单独注册登录、单独购买会员,无法覆盖家庭所有联网设备;现有AI安全网关均为企业级设备,需要专业IT人员配置,部署成本高;现有AI安全方案均为端侧软件或云端服务,无法在网络入口实现全流量透明处理,存在隐私泄露风险

Benefits of technology

[0003]本发明的目的在于提供一种串接在宽带入口的即插即用AI安全网关,无需安装客户端、无需修改网络配置、无需大模型厂商配合,即可实现全网络AI流量的统一处理,覆盖所有联网设备。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FT_1
    Figure FT_1
  • Figure FT_2
    Figure FT_2
  • Figure FT_3
    Figure FT_3
Patent Text Reader

Abstract

The application discloses a plug-and-play AI security gateway connected in series at a wideband entrance, and belongs to the technical field of edge computing and artificial intelligence. The gateway comprises an independent hardware shell, and is internally provided with a network processing module, an AI traffic identification module, a security encryption module and a model scheduling module, is specially used for processing generative large model interactive traffic, and directly forwards non-AI traffic at a line speed. The gateway can work in a series connection mode, a single-device direct connection mode or a side hanging mode, supports PoE power supply and cross-network segment remote access. After deployment, the gateway can transparently proxy AI traffic of all devices in a local area network without installing a client or modifying network configuration, realizes unified access of multiple models, data desensitization and content filtering. The application solves the problems of single-device deployment of existing AI capabilities and complex deployment of enterprise-level gateways, and provides an AI security solution with zero configuration and full coverage for home and office scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of edge computing, network security, and artificial intelligence, and specifically to a stand-alone AI security gateway device deployed at the broadband access point of a home or small office network. Background Technology

[0002] The existing AI capability deployment has the following drawbacks: AI capabilities are all deployed on a single device, requiring separate installation of AI applications, separate registration and login, and separate membership purchases for mobile phones, computers, TVs, etc., which cannot cover all networked devices in the home; existing AI security gateways are all enterprise-grade devices, requiring professional IT personnel for configuration, resulting in high deployment costs; existing AI security solutions are all edge software or cloud services, which cannot achieve full traffic transparency at the network entry point, posing a risk of privacy leakage. Summary of the Invention

[0003] The purpose of this invention is to provide a plug-and-play AI security gateway that connects to the broadband gateway, enabling unified processing of AI traffic across the entire network and covering all connected devices without requiring client installation, network configuration modification, or cooperation from large model manufacturers. Attached Figure Description

[0004] Figure 1 This is a schematic diagram of the hardware structure of the gateway of the present invention; Figure 2 This is a schematic diagram of the deployment mode of the gateway of the present invention; Figure 3 This is a flowchart illustrating the workflow of the gateway of the present invention. Detailed Implementation

[0005] The present invention will now be described in detail with reference to the accompanying drawings and embodiments: Example 1: Deployment of AI Security Gateway in a Home Setting Users connect this gateway in series between their home's optical modem and wireless router. After powering on, the gateway automatically identifies the network topology and completes transparent proxy configuration. Users' mobile phones, computers, smart speakers, and other devices do not need to install any software; all AI requests are automatically processed through the gateway. The gateway anonymizes sensitive information in prompts sent to large models and filters inappropriate content from returned messages, while also supporting unified scheduling of multiple large models. Users can view AI usage reports and manage device permissions through the management interface. Non-AI traffic is forwarded directly at line speed, without affecting the user's normal internet speed. Example 2: Status Indicator Logic In a preferred embodiment, the concealed soft-light status indicator adopts internationally recognized status color logic: during the initial device startup and network configuration process, it displays a slow-breathing yellow light to indicate configuration in progress; after successful network configuration, it displays a solid green light for 2 minutes to allow the user to confirm that the device is working properly, and then automatically turns off; during routine restarts, it displays a solid green light for 30 seconds after successful network configuration and then automatically turns off; under normal operating conditions, the indicator remains off, with no continuous light pollution; when the device experiences network failure or configuration failure, it displays a slow-flashing red light, and automatically returns to its normal state logic after the fault is resolved. The indicator uses a low-brightness soft-light design, with light shining through the gaps in the housing, without exposed glaring LED beads, so as not to disturb the user's rest; Example 3: Automatic bypass for network anomalies When the gateway detects an upstream network outage, a malfunction in its own proxy service, or a system crash, it automatically switches to bypass mode, forwarding all network traffic directly at line speed without any parsing, decryption, or processing, ensuring uninterrupted home network access for users. After the fault is recovered, the gateway automatically switches back to normal proxy mode. The entire process is seamless for the user, ensuring no network outages or inability to access the internet. Example 4: Ultimate Deployment of PoE Power Supply In another embodiment, the gateway supports PoE power supply, requiring only one network cable to connect to the upstream device to complete power supply and data connection at the same time, without the need for an additional power adapter, thus enabling a single network cable to complete power supply and data transmission simultaneously. Example 5: Multi-device AI membership sharing in a small office setting Multiple computers within the company need to share an AI membership account. By deploying this gateway in front of the router, all AI requests are initiated through the gateway. The gateway performs device fingerprint spoofing and frequency control on requests to prevent account bans. Simultaneously, the gateway automatically selects the most cost-effective large model based on the request type, significantly reducing the cost of using AI. Example 6: Router Integration The AI ​​traffic processing system of the present invention can be integrated into a home wireless router, reusing the router's network processing module and network port hardware, without the need for additional independent hardware, to realize the AI ​​traffic proxy and multi-model scheduling functions described in the present invention; Example 7: Pure Software Deployment The system of the present invention can be deployed in the form of software firmware in users' existing general computing devices such as NAS, soft routers, and personal computers, without the need for additional hardware, to realize the AI ​​traffic transparent proxy function within the local area network; Example 8: Upgraded version with screen In another embodiment, the gateway housing is equipped with a touch screen that can display real-time information such as network connection status, AI traffic statistics, device online status, and cost-saving data. Users can directly complete device settings, account binding, and permission configuration through the touch screen without relying on a mobile phone or computer. Example 9: Upgraded Form of Biometric Identification In another embodiment, the gateway integrates a fingerprint recognition module. Parents can unlock the gateway with a single fingerprint and switch to adult mode, while the gateway automatically switches to child mode and filters content when used by a child. Biometric data is encrypted and stored locally in a hardware security module, without being uploaded to the cloud, thus ensuring privacy and security. Example 10: Implementation of Multi-Standard Security Encryption The hardware security encryption module supports at least one of the following: Chinese national cryptographic algorithms, international standard algorithms, and post-quantum encryption algorithms. The appropriate algorithm can be flexibly selected based on the compliance requirements of the deployment region. Uplink data undergoes de-identification processing before leaving the gateway to ensure that sensitive information is not leaked. Example 11: Smart Home Hub Integration The gateway supports smart home interconnection protocols such as Matter and can serve as a local smart home hub. Users can control smart devices such as lights, air conditioners, and curtains via voice commands. All commands are executed locally without cloud intermediaries, ensuring family privacy. Example 12: Offline AI and Smart Home Control When the upstream internet connection is interrupted, the gateway automatically switches to the local end-side mini-model to continue providing AI services, while maintaining normal control of smart home devices within the local area network. Users can still turn lights on and off, adjust the temperature, and ask questions to the local AI via voice commands at home; basic functions are not affected even when the internet is down. Example 13: AI Reply Caching Acceleration The gateway has a built-in large model response caching module that automatically hits the local cache for semantically similar requests and returns the results directly. When family members ask the same or similar questions again, the gateway directly returns the cached results, improving response speed by 2-3 times while reducing API call costs to the large model platform. Example 14: Smart Home Protocol Extension The gateway supports the Thread / Zigbee protocol and can act as a Matter border router, directly connecting to local smart home devices without the need for an additional smart home gateway. After purchasing this gateway, users can achieve whole-house smart control without needing to buy a separate smart home hub device. Example 15: Full Device Ad Blocking and Encrypted Internet Access The gateway has a built-in global ad blocking and VPN module that automatically identifies and filters ads, promotional links, and paid content in large-scale user responses. Users can enable full-device ad blocking with a single click on the management console, filtering web and video ads on all connected devices. It also supports encrypted internet access to protect user privacy. Example 16: Sharing Computing Power During Idle Time The gateway supports idle computing power sharing. Users can enable this function on the management console, contributing the gateway's local computing power to the edge computing network when idle, helping other users handle AI inference tasks. Points earned by users can be redeemed for AI membership time or model call quotas, thus utilizing the gateway's idle computing power. Example 17: Security Activation and Reset Mechanism The gateway is configured with an inactive mechanism. Identity generation is not triggered during production testing and channel demonstrations. When users enable advanced features requiring identity verification, a corresponding digital identity is generated on demand based on the hardware root ID. A normal reset only clears the user's personal configuration; it does not delete the hardware identity or binding information to prevent accidental data loss. Completely clearing the device requires strong identity verification to prevent device theft. Example 18: Single-device direct connection deployment In office or home environments, users connect one Ethernet port of this gateway to a switch and the other Ethernet port to their computer. Once powered on, the gateway automatically identifies the network topology and completes transparent proxy configuration. Only AI requests from this computer are automatically processed through the gateway; other devices on the local network remain unaffected, and non-AI traffic is forwarded directly at line speed. The entire process requires no client installation or network configuration modification on the computer, achieving zero-configuration, single-device deployment. This mode is suitable for scenarios requiring protection of only a single high-value terminal device, simplifying deployment and focusing user value. Example 19: Remote Access Across Network Segments When users are away from home, they can connect to their home gateway via mobile devices such as smartphones through an end-to-end encrypted tunnel automatically established by the gateway. They can then use the associated AI membership service, remotely view their child's AI usage records, and adjust parental control settings. All remote traffic is end-to-end encrypted; the gateway does not require port forwarding or public IP configuration. The cloud only forwards packets and does not store user interaction data or plaintext content. Example 20: Connected in series between the switch and the terminal device In office or complex home network environments, users connect one Ethernet port of this gateway to a switch and the other Ethernet port to a computer. After powering on, the gateway automatically identifies the network topology and completes transparent proxy configuration. Only AI requests from this computer are automatically processed through the gateway; other devices connected to the switch remain unaffected, and non-AI traffic is forwarded directly at line speed. The entire process requires no client installation or network configuration modification on the computer, achieving zero-configuration deployment. Example 21: Local Wake-up Privacy Voice Interaction The gateway has a built-in local wake-word detection module, which defaults to a low-power listening state, without continuous recording or uploading any ambient sounds. After the user speaks the preset wake-word, the gateway starts recording, and automatically exits wake-up mode and returns to low-power mode if no valid command is received within 5 seconds. After waking up, the user can directly issue voice commands without opening a mobile app or selecting a device. Basic queries and smart home control commands are recognized and executed directly locally. Sensitive commands involving mode switching, permission changes, or privacy viewing require prior registration of the parent's identity via local voiceprint verification before execution. Complex voice requests are transmitted end-to-end to the user's bound device or a user-specified large-scale model service. The processing result is automatically pushed to the nearest online audio device (smart speaker, TV, mobile phone) within the local area network for playback; the gateway does not require a built-in speaker. Throughout the voice interaction process, the gateway does not store or upload the user's raw voice data. When a guest wakes up the gateway, it automatically enters guest mode, only enabling basic AI question-and-answer functions, without accessing family privacy data or using the registered user's personal payment credit. The guest conversation cache is automatically cleared after 2 hours of inactivity, leaving no records.

Claims

1. A plug-and-play AI security gateway connected in series at a broadband entry point, characterized in that, Includes a separate hardware housing, with the following features inside: At least two wired Ethernet interfaces, one for connecting an upstream optical modem or router and the other for connecting a downstream router or terminal device; a network processing module for enabling line-speed forwarding of network traffic; and an AI traffic recognition module for recognizing generative large model interaction traffic in the network, including user prompts and large model generated content. The security encryption module is used to implement hardware-level encryption and desensitization of sensitive data; The model scheduling module is used to connect to multiple large model services and achieve unified forwarding of AI requests. The AI ​​traffic identification module and model scheduling module are specifically designed to process the interactive traffic of generative large models. They only decrypt traffic from predefined large model domain names. Non-large model traffic is not SSL decrypted, parsed, or stored. It is directly forwarded at line speed through the network processing module without decryption or modification. The gateway can work in serial mode, single-device direct connection mode, or side-mount mode. Serial mode includes connection between the optical modem and the router, between the router and the switch, and between the switch and the terminal device. Single-device direct connection mode is connected between the switch or router and a single terminal device to provide AI traffic proxy services for that single terminal device. After deployment, no client needs to be installed on the terminal, no modification to the terminal network configuration is required, and no large model vendor adaptation is needed. It can transparently proxy the AI ​​traffic of all devices in the local area network, realizing unified access to multiple models, data anonymization, and content filtering functions. Configuration is automatically completed after plugging in and connecting to the network. In the event of network anomalies or proxy failures, the gateway automatically bypasses all traffic and forwards it directly at line speed, ensuring uninterrupted internet access for users.

2. The gateway according to claim 1, characterized in that, The outer surface of the independent hardware housing, apart from the necessary network port and power opening, only has a hidden reset hole, with no exposed physical buttons or display screen; it only has a hidden soft-light status indicator light, which does not require manual setting by the user. During the device startup and network configuration process, the light status indicates the configuration progress. After successful network configuration, the light indicates normal working status for a preset time, and then automatically turns off. Under normal working status, the indicator light remains off, with no continuous light pollution. It only lights up to indicate fault or abnormal conditions, achieving an appearance design without additional user interaction. Users can complete the deployment simply by connecting via network cable.

3. The gateway according to claim 1, characterized in that, The gateway has a built-in physical intrusion detection and self-destruct unit. When the shell is detected to be illegally opened, it automatically triggers an irreversible hardware fuse mechanism to destroy the locally stored keys and sensitive configuration information. Factory reset only clears the user's personal configuration and data, does not delete the hardware root ID, and does not clear the generated device digital identity. To completely clear the device identity, verification of the bound account password or factory return operation is required to prevent the device from being stolen.

4. The gateway according to claim 1, characterized in that, The gateway's security encryption module is hardware-programmed once during the production phase to create a globally unique, tamper-proof, and non-exportable hardware root ID, which serves as the root of trust for local encryption and key storage, supporting all local network and AI functions. When a user enables advanced functions requiring identity verification, the gateway can generate a corresponding decentralized digital identity based on the hardware root ID, used for data asset verification, device ownership transfer, and cross-functional permission verification. Users can choose to scan the gateway's QR code through the management terminal to associate the digital identity with an anonymous account to use cross-network functions such as remote access and cloud synchronization. User registration or account binding is not mandatory; gateways without associated accounts can use all local core functions normally. User-configured local encrypted storage is not uploaded to the cloud by default. The association process does not collect users' personal identification information, and the transfer of device ownership requires verification by the original associated account.

5. The gateway according to claim 1, characterized in that, The gateway automatically generates and stores a user AI data asset report, which includes the total duration of AI service usage by the user through the gateway, total number of calls, number of privacy data interceptions, total amount of membership fee savings, and estimated value of the generated data assets. Users can view and share the report through the management terminal.

6. The gateway according to claim 1, characterized in that, It also includes a locally running lightweight AI model store, where users can select, download, or update secure, edge-side models provided by official or third-party providers in the management console. These models are used to process specific types of AI tasks locally and offline.

7. The gateway according to claim 1, characterized in that, The network processing module supports line-speed forwarding of 2.5Gbps and above.

8. The gateway according to claim 1, characterized in that, The gateway has a box-shaped casing and an interface layout of dual network ports plus a power port.

9. The gateway according to claim 1, characterized in that, The gateway supports Power over Ethernet (PoE) and can draw power directly from the upstream optical modem or router via a network cable. No additional power adapter is required; only a single network cable is needed to complete the power supply and data connection.

10. The gateway according to claim 1, characterized in that, The gateway supports remote access across network segments. Terminal devices outside the local area network can connect to the gateway and use its AI services through the end-to-end encrypted tunnel automatically established by the gateway, without the need to set up port mapping or configure public IP on the gateway.

11. The gateway according to claim 1, characterized in that, The housing is also equipped with a touch screen display for displaying network status, AI traffic statistics and device information, and supports device settings through local touch operation.

12. The gateway according to claim 1, characterized in that, It also includes a biometric data collection module, which collects fingerprint, facial or voiceprint information to enable user authentication, device unlocking and permission switching locally. Biometric data is encrypted and stored locally in a hardware security encryption module.

13. The gateway according to claim 1, characterized in that, The gateway has a built-in hardware security encryption module, and the root key of the encryption module and user sensitive data cannot be exported. The gateway performs local sensitive data identification and desensitization processing on the uplink traffic sent by users to the large model. The original sensitive data does not leave the hardware security encryption module, and only the desensitized data is sent to the large model.

14. The gateway according to claim 1, characterized in that, The gateway supports smart home interconnection protocols and can act as a local smart home hub. It enables voice control and scene automation of smart devices through a locally running large model, with control commands executed locally without cloud relay. The gateway has a built-in local wake-word detection module, which defaults to a low-power listening state, without continuous recording or uploading any ambient sounds. It only starts recording when a preset wake-word is detected, and automatically exits wake-up mode and returns to low-power mode if no command is received after a timeout. After wake-up, it can directly receive user voice commands without opening a mobile app or selecting a device. Ordinary query and device control commands are recognized and executed directly locally. Sensitive commands involving permission changes or mode switching require local voiceprint verification before execution. Complex voice requests are transmitted end-to-end to the user's bound device or the user-specified large model service. Processing results can be automatically pushed to the nearest online audio device within the local area network for playback. The gateway does not require a built-in speaker. Throughout the entire voice interaction process, the gateway does not store or upload the user's raw voice data.

15. The gateway according to claim 1, characterized in that, The gateway supports offline operation of large local models. When the upstream Internet is interrupted, it automatically switches to small local models to provide AI services, while maintaining the normal availability of smart home control, file sharing and other functions within the local area network. Basic functions are not affected when the network is disconnected.

16. The gateway according to claim 1, characterized in that, The gateway has a built-in large model response caching module that automatically hits the local cache for semantically similar requests and returns the results directly, eliminating the need to repeatedly call the large model API, thus improving response speed and reducing API costs.

17. The gateway according to claim 1, characterized in that, The gateway supports the Thread / Zigbee smart home protocol and can act as a Matter border router, directly connecting to local smart home devices without the need for an additional smart home gateway.

18. The gateway according to claim 1, characterized in that, The gateway has a built-in global ad blocking and VPN module that automatically identifies and filters ads, promotional links, and paid content in the large model answers. It can achieve full-device ad blocking and encrypted internet access without the need to install software on the terminal. Users can enable it with one click on the management terminal.

19. The gateway according to claim 1, characterized in that, The gateway supports an idle computing power sharing switch. Users can choose to enable it to contribute the gateway's idle local computing power to the edge computing network. The points earned can be redeemed for AI membership time or model call quota.

20. A plug-and-play AI security gateway system connected in series at a broadband entry point, characterized in that, The system includes standalone hardware configurations, router-integrated configurations, and pure software deployment configurations, and is configured to perform the method described in any one of claims 1 to 19.