Dynamic Trusted Edge Gateway for Classification-Based Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional static authorization mechanisms in industrial cloud platforms fail to adapt to dynamic changes in industrial device security status, are vulnerable to evolving cyber threats, and cannot provide fine-grained control over edge devices.

Innovation Solution

A dynamic trusted edge gateway system that integrates static identity factors with dynamic information indicators, comprising an information collection module, local cache module, identity collaboration module, multi-point deployment support module, security event log collaboration module, and trust evaluation result receiving module, to enable flexible and dynamic trust authorization for industrial terminals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static authorization mechanisms are used, then device access control is simplified, but the system cannot adapt to dynamic changes in device security status

Engineering Contradiction:
Improveadaptability to device status changesVSAvoidauthorization mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic authorization by continuously monitoring device status parameters (security level, trust score, operational state) and automatically adjusting access permissions in real-time. The authorization mechanism transitions from static to dynamic, allowing the system to adapt to changing device conditions without manual intervention.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system establishes a feedback loop where device status information is continuously collected and fed back to the authorization module. Based on this feedback, the system automatically adjusts authorization decisions, creating a closed-loop control mechanism that responds to real-time device conditions.

Inventive Principle:
Principle #23Feedback

2Reliability

If static authorization is used, then implementation is simple, but it cannot deal with evolving cyber threats

Engineering Contradiction:
Improvesecurity against cyber threatsVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements continuous security monitoring and evaluation, where the system continuously assesses device trust scores and security status. This continuous action ensures that security measures are always current and effective against evolving threats, rather than relying on fixed pre-established rules.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system dynamically changes security parameters such as trust score thresholds, access permission levels, and monitoring intensity based on real-time device behavior and threat detection. This allows the security system to adapt its parameters to counter evolving cyber threats effectively.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If static authorization is used, then control is straightforward, but fine-grained control over different devices is difficult to achieve

Engineering Contradiction:
Improveauthorization control easeVSAvoidfine-grained control precision
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent applies different authorization policies and control levels to different devices based on their specific characteristics, security status, and operational requirements. Each device receives customized control parameters rather than uniform treatment, enabling fine-grained control while maintaining operational simplicity through automated differentiation.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12445500B2Dynamic trusted edge gateway for industrial terminals based on classification and hierarchical management and its implementation method
Publication Date: 2025.10.14 HANGZHOU DIANZI UNIV
  • US12445500B2 patent drawing
  • US12445500B2 patent drawing

AI summary

A dynamic trusted edge gateway for industrial terminals based on classification and hierarchical management includes a information collection module, a local cache module, an identity collaboration module, a multi-point deployment support module, a security event log collaboration module, a trust evaluation result receiving module and a security policy execution module. The information collection module is configured to establish a connection with industrial terminals and collect a multi-dimension information of the industrial terminals and transmit the multi-dimension information to the local cache module and the trust evaluation result receiving module. The security event log collaboration module is configured to perform information exchange and event sharing with an industrial control security device and an industrial IoT security device, and transmit a security event information and a status data of the industrial control security device and industrial IoT security device to the trust evaluation result receiving module.