Dynamic Trusted Edge Gateway for Classification-Based Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional static authorization mechanisms in industrial cloud platforms fail to adapt to dynamic changes in industrial device security status, are vulnerable to evolving cyber threats, and cannot provide fine-grained control over edge devices.
Innovation Solution
A dynamic trusted edge gateway system that integrates static identity factors with dynamic information indicators, comprising an information collection module, local cache module, identity collaboration module, multi-point deployment support module, security event log collaboration module, and trust evaluation result receiving module, to enable flexible and dynamic trust authorization for industrial terminals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If static authorization mechanisms are used, then device access control is simplified, but the system cannot adapt to dynamic changes in device security status
Solution Approach 1:
The patent implements dynamic authorization by continuously monitoring device status parameters (security level, trust score, operational state) and automatically adjusting access permissions in real-time. The authorization mechanism transitions from static to dynamic, allowing the system to adapt to changing device conditions without manual intervention.
Solution Approach 2:
The system establishes a feedback loop where device status information is continuously collected and fed back to the authorization module. Based on this feedback, the system automatically adjusts authorization decisions, creating a closed-loop control mechanism that responds to real-time device conditions.
2Reliability
If static authorization is used, then implementation is simple, but it cannot deal with evolving cyber threats
Solution Approach 1:
The patent implements continuous security monitoring and evaluation, where the system continuously assesses device trust scores and security status. This continuous action ensures that security measures are always current and effective against evolving threats, rather than relying on fixed pre-established rules.
Solution Approach 2:
The system dynamically changes security parameters such as trust score thresholds, access permission levels, and monitoring intensity based on real-time device behavior and threat detection. This allows the security system to adapt its parameters to counter evolving cyber threats effectively.
3Ease of operation
If static authorization is used, then control is straightforward, but fine-grained control over different devices is difficult to achieve
Solution Approach 1:
The patent applies different authorization policies and control levels to different devices based on their specific characteristics, security status, and operational requirements. Each device receives customized control parameters rather than uniform treatment, enabling fine-grained control while maintaining operational simplicity through automated differentiation.
Data Source
AI summary
A dynamic trusted edge gateway for industrial terminals based on classification and hierarchical management includes a information collection module, a local cache module, an identity collaboration module, a multi-point deployment support module, a security event log collaboration module, a trust evaluation result receiving module and a security policy execution module. The information collection module is configured to establish a connection with industrial terminals and collect a multi-dimension information of the industrial terminals and transmit the multi-dimension information to the local cache module and the trust evaluation result receiving module. The security event log collaboration module is configured to perform information exchange and event sharing with an industrial control security device and an industrial IoT security device, and transmit a security event information and a status data of the industrial control security device and industrial IoT security device to the trust evaluation result receiving module.

