Edge Gateway Zero Trust Orchestration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The manual deployment of hardware appliances in datacenters for establishing connectivity between cloud resources and on-premises networks is prone to errors and hampers scalability, while traditional authentication methods create security loopholes.

Innovation Solution

An automated system for orchestrating an edge gateway that is authorized, authenticated, and validated before provisioning, using Zero Trust Orchestration (ZTO) schemes to establish secure connectivity between datacenters and cloud resources, and employing secure communication protocols to mitigate authentication risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual deployment of hardware appliances is used for establishing connectivity, then deployment control is possible, but error rate increases and scalability is hampered

Engineering Contradiction:
Improvedeployment controlVSAvoiderror rate
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The edge gateway performs self-provisioning by automatically authenticating with the controller and obtaining configuration parameters without human intervention. The gateway independently completes registration, receives configuration, and establishes connectivity autonomously, eliminating manual configuration steps that cause errors while maintaining deployment control through automated policy enforcement.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary authentication and authorization actions before the edge gateway begins providing network services. The gateway authenticates with the controller in advance, receives configuration parameters beforehand, and validates its identity before operational deployment, ensuring error-free operation from the start while maintaining controlled deployment through pre-validation.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If manual deployment of hardware appliances is used, then deployment control is possible, but productivity decreases

Engineering Contradiction:
Improvedeployment controlVSAvoidscalability
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The edge gateway autonomously performs self-provisioning, self-authentication, and self-configuration by communicating with the controller. This automated self-service process eliminates the need for manual administrator intervention for each deployment, enabling rapid scaling while maintaining controlled deployment through automated policy enforcement and configuration management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual deployment process with an automated electronic orchestration system. The controller electronically manages edge gateway deployment, authentication, and configuration through automated communications, substituting human administrator actions with automated software-based processes that enable scalable productivity while maintaining deployment control through programmable policies.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If traditional authentication methods (username/password or private key) are used, then registration is achieved, but security loopholes are created

Engineering Contradiction:
Improveregistration capabilityVSAvoidsecurity loopholes
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication credentials (username/password or private keys) from the transmission process between controller and edge gateway. Instead of transporting sensitive credentials over the network, the system uses public key infrastructure where the edge gateway proves its identity through cryptographic signatures without exposing secret keys or passwords during communication, eliminating security loopholes while maintaining registration capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system introduces cryptographic protocols as an intermediary mechanism between the controller and edge gateway for authentication. Rather than directly transmitting sensitive credentials, the authentication process uses cryptographic intermediaries (digital certificates, public key infrastructure) that enable secure verification of identity without exposing sensitive information, thereby closing security loopholes while preserving registration functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12301411B2System and method for zero trust orchestration of an edge gateway within a cloud or multi-cloud network
Publication Date: 2025.05.13 AVIATRIX SYSTEMS INC
  • US12301411B2 patent drawing
  • US12301411B2 patent drawing
  • US12301411B2 patent drawing

AI summary

An edge gateway deployed within an overlay network interconnecting a first public cloud network with an on-premises network is described. Coupled to a controller, the edge gateway is configured to receive a configuration file and attestation data from a controller, analyze the configuration file to obtain at least a first network address being used as an interface for secure communications with the controller, establish a secure interconnect with the controller based on the attestation data, and conduct a provisioning operation to initiate a request to the controller for edge gateway software thereby automated provisioning the edge gateway without human intervention. The edge gateway experiences automated provisioning based on a configuration file and attestation data upload.