Edge Controller Group Authentication via Lightweight Cryptographic Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current industrial edge controllers lack a secure and credible operation mechanism, which is essential for improving security and credibility in edge computing environments, particularly due to high bandwidth demands, energy consumption, and difficulties in ensuring real-time performance and data security during transmission and storage.

Innovation Solution

A revocable lightweight group authentication method and system for edge controllers, involving the generation of private keys and certificates, secure channel communication, and signature verification to authenticate edge controllers and ensure secure data access, while allowing for efficient revocation of unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cloud computing centralized model is used, then data management and analysis capability is improved, but bandwidth demand and energy consumption increase significantly

Engineering Contradiction:
Improvedata processing capabilityVSAvoidenergy consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The patent segments the centralized cloud computing model into distributed edge computing nodes. By deploying authentication and data processing capabilities at the edge (near data sources) rather than centralizing them in the cloud, the system reduces bandwidth consumption for data transmission while maintaining processing capability. Edge controllers perform local authentication and data validation, eliminating the need to transmit all data to centralized cloud servers.

Inventive Principle:
Principle #1Segmentation

2Productivity

If cloud computing centralized model is used, then data management capability is improved, but real-time performance deteriorates

Engineering Contradiction:
Improvedata management capabilityVSAvoidreal-time performance
Core Design Contradiction:
ProductivityVSSpeed

Solution Approach 1:

The patent introduces a new dimensional architecture by adding edge computing layers between data sources and centralized cloud systems. This multi-dimensional structure enables simultaneous local real-time processing at the edge and centralized management at the cloud, resolving the contradiction between real-time performance and comprehensive data management capability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If traditional security mechanisms are applied to edge controllers, then security coverage is improved, but device complexity and computational overhead increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the core authentication functionality from complex traditional security mechanisms and implements a streamlined group signature-based authentication system specifically designed for edge controllers. This extracted authentication mechanism provides essential security coverage while maintaining low computational overhead suitable for resource-constrained edge devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the security mechanism parameters by implementing lightweight cryptographic algorithms and optimized key management procedures tailored for edge computing environments. These parameter adjustments maintain security effectiveness while reducing computational complexity and resource consumption on edge controllers.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If comprehensive authentication mechanisms are implemented, then security credibility is improved, but processing time and system overhead increase

Engineering Contradiction:
Improvesecurity credibilityVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-establishing group public keys and authentication credentials during device initialization and registration phases. This advance preparation enables rapid authentication during actual edge controller operations, maintaining high security credibility while minimizing real-time processing time and system overhead.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11799843B2Revocable lightweight group authentication method and system for edge controller, and medium
Publication Date: 2023.10.24 GUANGZHOU UNIVERSITY
  • US11799843B2 patent drawing

AI summary

A revocable lightweight group authentication method and system for an edge controller is described here. When the edge controller needs to be registered, an edge server generates a private key of the edge controller and sends the private key to the edge controller, and meanwhile adds the edge controller to a group list of the edge server; the edge server updates a certificate of the edge controller, adds the certificate to a certificate list of the edge server and sends the certificate to the edge controller so that the edge controller updates the private key according to the updated certificate; and then the edge controller generates a signature according to the updated private key, and sends the signature to the edge server so that the edge server authenticates the edge controller after determining that the signature meets preset requirements.