Edge Server Application Security Management System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manufacturing sites face security risks due to applications used in controlling and maintaining manufacturing apparatuses, which can lead to misuse or exposure of sensitive data, and existing systems do not adequately address the need for users to understand and manage these risks before application execution.

Innovation Solution

An application security management system comprising an edge server, application distribution management server, and evaluation management server that evaluates applications based on a security risk list, allowing only authorized functions and data access, and notifies users of potential risks, thereby ensuring secure execution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If an application is distributed to be executed on edge devices, then the application can perform its intended functions, but security risks arise from potential misuse of functions and data access

Engineering Contradiction:
Improveapplication functionalityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by requiring application developers to create security risk lists that describe intended functions and data access before distribution. The evaluation management server reviews these risk lists in advance to determine whether to approve distribution, preventing harmful applications from being deployed without proper security assessment

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback through the edge server's access control unit, which continuously monitors application execution against the approved security risk list. When the application attempts to access functions or data beyond its authorized scope, the system detects this deviation and terminates the application, providing real-time feedback control

Inventive Principle:
Principle #23Feedback

2Loss of information

If users are provided with security risk information before application execution, then users can make informed decisions, but the complexity of the distribution process increases

Engineering Contradiction:
Improvesecurity risk transparencyVSAvoiddistribution process complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent segments the security management process into distinct components: the evaluation management server handles risk list creation and approval, the distribution management server manages the catalog and user interface, and the edge server enforces access control during execution. This segmentation allows each component to focus on specific tasks, reducing overall system complexity while maintaining comprehensive security transparency

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The evaluation management server acts as an intermediary between application developers and the distribution management server. It pre-evaluates applications and approves their security risk lists before distribution, filtering out malicious applications in advance. This intermediary layer simplifies the distribution process by ensuring only evaluated applications are distributed

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the edge server monitors and controls application access in real-time, then security is enhanced, but system performance and execution speed may be reduced

Engineering Contradiction:
Improvesecurity controlVSAvoidapplication execution speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The access control rules are established in advance through the security risk list created by the developer and approved by the evaluation management server. The edge server loads these pre-defined rules into memory before application execution, so that during runtime, the monitoring process involves simple comparisons against stored rules rather than complex real-time analysis, minimizing performance impact

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10805335B2Application security management system and edge server
Publication Date: 2020.10.13 FANUC LTD
  • US10805335B2 patent drawing
  • US10805335B2 patent drawing
  • US10805335B2 patent drawing

AI summary

An application security management system and an edge server which enable an application developed by an application developer to be executed only in a state that matches a security risk reported by the developer are provided. In an application security management system, an evaluation management server that manages evaluation of an application developed by an application developer and executed by an edge server registers the application and an access report list related to the usability of a function of the edge device and/or the accessibility of processing data of the edge device after evaluation in an application DB. A distribution management server system that manages distribution of the evaluated application notifies a user who issued a purchase request of the access report list upon receiving the purchase request for the application and distributes the application and the access report list to the edge server when authorization data is received only.