Extending Network Security to Edge Devices via Local Connections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Local connections between network nodes and edge devices often lack security controls, making them vulnerable to attacks and compromising the security of the network if left unsecured.

Innovation Solution

Extending network security to local connections by having edge devices communicate with a network manager to obtain security keys and credentials, establishing a secure channel, and exchanging routing information to operate securely within the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network security is extended to local connections between network nodes and edge devices, then security of communications is improved, but device complexity and implementation difficulty increase

Engineering Contradiction:
Improvesecurity of communicationsVSAvoidcomplexity of securing local connections
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by enabling network nodes to perform multiple functions: they act as both network communication endpoints and security gateways for locally connected edge devices. The network node establishes secure channels for both network traffic and local connection traffic, making the security infrastructure multi-functional and reducing the need for separate security mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The network node serves as an intermediary between edge devices and the network. It mediates security by establishing secure channels between edge devices and other network nodes, handling authentication, and managing security credentials. This intermediary approach simplifies the security implementation at edge devices while maintaining strong security controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication and security credentials are implemented for edge devices, then security against attacks is improved, but ease of operation and device setup deteriorate

Engineering Contradiction:
Improvesecurity against attacksVSAvoidease of device setup
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service by enabling edge devices to automatically obtain security credentials and establish secure channels without manual configuration. The network manager automatically provisions security credentials to edge devices, and the secure channel establishment occurs automatically when edge devices connect to network nodes, eliminating the need for users to manually configure security settings.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary action by pre-provisioning security credentials to edge devices through the network manager before the devices need to communicate securely. The network manager establishes the security infrastructure in advance, so when edge devices connect to the network, the security credentials are already in place and ready for immediate use.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3967016B1Extending network security to locally connected edge devices
Publication Date: 2023.10.04 LANDIS GYR TECH INC
  • EP3967016B1 patent drawingFigure 1
  • EP3967016B1 patent drawingFigure 2
  • EP3967016B1 patent drawingFigure 3

AI summary

In some embodiments, a secure local connection between a network node of a network and an edge device attached to the network node is provided by extending the security of the network to this local connection. The edge device attached to the network node communicates with a network manager of the network to obtain security keys and security credentials for the edge device. Using the security keys and the security credentials, the edge device can establish a secure channel between the network node and the edge device over the local connection. The edge device further communicates with the network manager to exchange routing information and to obtain a network address for the edge device. The edge device can then communicate, through the network node, with other network nodes in the network using the security keys, the security credentials, and the network address.