Edge Proxy Trust Evaluation for Industrial Edge Node Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Edge computing in industrial networks faces challenges in ensuring the trustworthiness of computing results from edge nodes, particularly due to security risks and the lack of effective methods to verify the integrity and correctness of data between industrial clouds and edge nodes, which is critical for timely and secure data processing.

Innovation Solution

A judgment method for edge node computing result trustworthiness based on trust evaluation, where edge nodes register with a proxy, undergo initial trust value evaluation using evidence collection and processing, and subsequent trust updates, incorporating accuracy, integrity, and timeliness metrics, with fuzzy evaluation and entropy weight methods to determine trust levels and prevent malicious activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If edge nodes directly access the Internet to enable mobility and reduce cloud dependency, then service mobility and response time are improved, but security risks and data integrity issues increase

Engineering Contradiction:
Improveresponse timeVSAvoidsecurity risks
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an edge proxy as an intermediary between edge nodes and the Internet. The edge proxy collects evidence from edge nodes, evaluates their trustworthiness, and mediates their access to external networks. This allows edge nodes to maintain direct Internet access for mobility and speed while the proxy filters out security risks through trust evaluation mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary trust evaluation before edge nodes access the Internet or process sensitive data. The edge proxy continuously collects evidence about edge node behavior and pre-assesses their trustworthiness, so that when security decisions are needed, the evaluation is already complete, enabling fast response without compromising security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If trust evaluation mechanisms are implemented to ensure computing result correctness, then data integrity and security are improved, but system complexity and computational overhead increase

Engineering Contradiction:
Improvedata integrityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the trust evaluation system into distinct functional modules: evidence collection module, evidence processing module, and trust evaluation module. The edge proxy separates trust management functions from edge node computing functions. This segmentation makes the complex trust evaluation system more manageable and allows parallel processing, reducing overall system complexity while maintaining comprehensive security checks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements self-service mechanisms where edge nodes automatically generate their own evidence data (computing logs, resource usage records) and the edge proxy automatically processes this evidence without requiring manual intervention. The system uses automated algorithms for trust evaluation, reducing operational complexity while ensuring continuous integrity monitoring.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If multiple evidence collection methods are used to accurately evaluate edge node trustworthiness, then evaluation accuracy is improved, but time consumption and processing overhead increase

Engineering Contradiction:
Improveevaluation accuracyVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements periodic evidence collection where the edge proxy collects trust evidence at regular intervals rather than continuously. This periodic sampling maintains accurate evaluation of edge node behavior while significantly reducing the time consumption and processing overhead compared to continuous monitoring. The evaluation accuracy is preserved by collecting sufficient evidence points over each period.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent uses adaptive evidence collection that adjusts the number and depth of evidence gathering based on current trust levels. For edge nodes with high trust scores, fewer and lighter evidence checks are performed. For nodes with lower or uncertain trust scores, more comprehensive evidence collection is conducted. This partial action approach maintains evaluation accuracy for critical cases while reducing overall time consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11956372B2Judgment method for edge node computing result trustworthiness based on trust evaluation
Publication Date: 2024.04.09 CHONGQING UNIV OF POSTS & TELECOMM
  • US11956372B2 patent drawing
  • US11956372B2 patent drawing
  • US11956372B2 patent drawing

AI summary

The present invention relates to a judgment method for edge node computing result trustworthiness based on trust evaluation, and belongs to the technical field of data processing. By means of the present invention, a security mechanism for trustworthiness of a computing result output by an industrial edge node is guaranteed, the industrial edge node is prevented from outputting error data, and attacks of false data of malicious edge nodes are resisted, it is guaranteed that trustworthy computing results not be tampered are input in the industrial cloud, and a site device is made to receive correct computing results rather than malicious or meaningless messages, thereby improving efficiency and security of industrial production.