Virtual Gateway Proxy for Secure Edge-to-Cloud Data Publishing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is no easy way to generate data from remote wellsites and see its effect in the cloud, and connecting a customer's edge gateway to the cloud without custom development is difficult, posing security and usability challenges.
Innovation Solution
A system with a virtual gateway and developer adapter enables secure data transmission from edge devices to a data aggregator, using TCP/UDP ports, MQTT/AMQP, HTTPS, and hardware ports, with encryption and secure protocols, allowing data partitioning and transmission over cellular, satellite, or Ethernet protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a hardware-based gateway is used to connect edge systems to the cloud, then data security and authentication are improved, but device complexity and difficulty of deployment increase
Solution Approach 1:
The patent creates a virtual gateway that replicates the functionality of a physical gateway in software form. This virtual gateway can be deployed on standard computers, servers, or cloud instances, eliminating the need for complex hardware installations while maintaining security functions like authentication and data encryption.
Solution Approach 2:
The patent replaces the mechanical/hardware-based gateway system with a software-based virtual gateway. Instead of requiring physical gateway devices with specialized hardware components, the system uses software applications that run on conventional computing platforms, thereby reducing deployment complexity while maintaining security capabilities.
2Adaptability or versatility
If custom development is performed on a gateway to connect it to the cloud, then connection flexibility is improved, but development time and complexity increase
Solution Approach 1:
The virtual gateway is designed as a universal platform that can connect to various cloud services and edge devices without requiring custom development. It provides pre-built connectors and interfaces that work with multiple protocols and platforms, allowing users to deploy and configure the gateway without writing custom code.
Solution Approach 2:
The patent incorporates pre-configured connection templates and pre-built integration components that are prepared in advance. Users can select and deploy pre-configured connection settings rather than performing custom configuration, significantly reducing development time while maintaining the ability to adapt to different cloud environments.
3Ease of operation
If edge data is published directly to the cloud from a development machine, then ease of data publication is improved, but security and usability for subject matter experts deteriorate
Solution Approach 1:
The virtual gateway acts as an intermediary between the development machine and the cloud. It provides a secure bridge that handles authentication, authorization, and data encryption before transmitting information to the cloud. This intermediary layer maintains ease of use by abstracting security complexities while ensuring reliable security practices.
Solution Approach 2:
The system segments the data publication process into distinct functional layers: local data generation, virtual gateway processing (including security operations), and cloud transmission. This segmentation allows each component to be optimized independently, with the gateway handling security functions while maintaining simple interfaces for data publication.
Data Source
AI summary
The system and method in accordance with the present disclosure include an edge gateway to separate insecure protocols from the cloud and to securely transmit data to the cloud over a physical medium. Embodiments also include a virtual gateway that executes in a secure environment, and an adapter that enables a developer to have an endpoint to push data into an already segmented data area provided by the virtual gateway. The system and method allow a developer to publish data virtually to a data aggregator from a developer machine, or to publish data from a first gateway to a second virtual gateway to a data aggregator.


