Edge Gateway Identity Validation for Malicious Fleet Onboarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Edge gateways in edge computing environments are vulnerable to new attack vectors due to reduced logical and physical security, allowing malicious actors to exploit entry points for ransomware, MITM attacks, and data leakage, with potential physical access by adversaries.

Innovation Solution

Implementing a unique identifier system for edge gateways during onboarding, where the edge management system verifies and generates a unique identifier for each legitimate gateway, adding it to packet headers for validation, and rejecting unauthorized traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If edge gateways are deployed geographically distributed at far-edge locations, then computation power and accessibility are improved, but security controls and attack vulnerability are worsened

Engineering Contradiction:
Improvegeographic deployment flexibilityVSAvoidsecurity control effectiveness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by generating unique identifiers for edge gateways during the onboarding process before they are deployed to geographic locations. This pre-establishment of identity markers enables subsequent automated validation without requiring additional handshakes or complex security protocols at deployment time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism - a unique identifier embedded in packet headers - that mediates between the edge gateway and the edge management system. This intermediary element enables automated identity validation, allowing distributed gateways to maintain security controls without requiring sophisticated physical security infrastructure at each location.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If traditional physical security controls are removed for distributed edge gateways, then deployment ease is improved, but susceptibility to physical access attacks is worsened

Engineering Contradiction:
Improvedeployment simplicityVSAvoidphysical access vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent replaces mechanical/physical security controls with an information-based validation system. Instead of relying on physical security infrastructure at distributed locations, the system uses unique identifiers embedded in digital packet headers to authenticate edge gateways. This substitution eliminates the need for physical security measures while maintaining authentication capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If unique identifier validation is implemented for all packets, then network traffic integrity is improved, but processing overhead is worsened

Engineering Contradiction:
Improvenetwork traffic integrityVSAvoidvalidation processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the unique identifier validation process with the existing packet header structure. By embedding the identifier directly in the packet header that is already being processed for routing and management purposes, the system validates network traffic integrity without requiring separate validation handshakes or additional processing steps.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12580890B2Preventing the introduction of malicious-edge-gateway the edge management's fleet via network interceptor and identity validation
Publication Date: 2026.03.17 DELL PROD LP
  • US12580890B2 patent drawing
  • US12580890B2 patent drawing
  • US12580890B2 patent drawing

AI summary

One method includes verifying, by a gateway management system, an edge gateway, upon successful verification of the edge gateway, generating an identifier that is unique to the edge gateway, and storing the identifier in the edge gateway. When the edge gateway intercepts a packet, the edge gateway may add the unique identifier to a header of the packet. When the gateway management system receives the packet with the modified header, the gateway management system can use the identifier as a basis to perform a validation process and then either drop the packet if the validation is unsuccessful, or execute the packet if the validation process is successful.