Hybrid Cloud Security Agent Caching for Disaster Recovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based security systems face challenges in providing continuous security processing, especially during disasters like network congestion or server overload, where the cloud is unavailable, leading to security gaps for mobile devices accessing the internet.

Innovation Solution

A hybrid architecture that combines client-side and cloud-based security processing, using a lightweight agent on mobile devices to cache security policies and perform local security processing during cloud unavailability, ensuring continuous security without relying solely on cloud services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Power

If cloud-based security processing is used, then security processing capability is improved, but system reliability deteriorates when cloud is unavailable

Engineering Contradiction:
Improvesecurity processing capabilityVSAvoidsystem availability during disaster
Core Design Contradiction:
PowerVSReliability

Solution Approach 1:

The system performs preliminary actions by caching security policies, configuration data, and threat intelligence locally on endpoint devices before cloud unavailability occurs. This allows the security agent to continue operating with cached data when the cloud becomes unavailable, thus maintaining system reliability while preserving cloud-based processing capabilities during normal operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security system is segmented into cloud-based components and local endpoint components that can operate independently. The cloud provides centralized security processing and policy management, while the endpoint agent maintains local caching and can autonomously enforce security policies when disconnected, resolving the contradiction between centralized processing power and distributed reliability.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If all security processing is performed in the cloud, then device complexity is reduced, but loss of time increases during cloud unavailability

Engineering Contradiction:
Improvedevice processing burdenVSAvoidsecurity response time during disaster
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

Security policies, rules, and threat intelligence are downloaded and cached locally on endpoint devices before cloud unavailability. This preliminary action ensures that when the cloud becomes unavailable, the endpoint agent can immediately enforce security policies without needing to query the cloud, thus reducing time loss while keeping device complexity manageable through selective caching of essential data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements local quality by enabling the endpoint agent to perform autonomous security decisions locally when cached data is available, while relying on cloud processing for complex threat analysis during normal operation. This creates different operational modes that optimize for either speed (local) or processing capability (cloud) depending on connectivity status.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If cloud-based security services are used, then scalability is improved, but loss of information occurs when cloud connectivity is lost

Engineering Contradiction:
Improvescalability of security serviceVSAvoidsecurity policy availability during disaster
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The system performs preliminary caching of security policies, configuration information, and threat intelligence data locally on endpoint devices. This ensures that even when cloud connectivity is lost, the essential security information remains available locally, preventing information loss while maintaining the scalability benefits of cloud-based security services during normal operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The endpoint agent creates local copies of security policies and threat intelligence data from the cloud. These copies enable the system to maintain security functionality during cloud unavailability, preventing information loss while allowing the cloud service to remain the primary source for updates and new information, thus preserving scalability.

Inventive Principle:
Principle #26Copying

4Loss of energy

If cloud-based security processing is used, then bandwidth consumption on device is reduced, but device complexity increases due to hybrid architecture

Engineering Contradiction:
Improvebandwidth consumptionVSAvoidhybrid architecture complexity
Core Design Contradiction:
Loss of energyVSDevice complexity

Solution Approach 1:

Security policies and configuration data are cached locally on endpoint devices before use. This preliminary action reduces the need for continuous cloud communication, thereby reducing bandwidth consumption and energy loss. The hybrid architecture complexity is managed by implementing the caching mechanism at the application layer without requiring fundamental changes to device hardware or operating system architecture.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20230269137A1Disaster recovery for cloud-based private application access
Publication Date: 2023.08.24 ZSCALER INC
  • US20230269137A1 patent drawing
  • US20230269137A1 patent drawing
  • US20230269137A1 patent drawing

AI summary

Systems and methods include receiving one or more disaster recovery configurations via a cloud-based system; storing the one or more received disaster recovery configurations in one or more components of the cloud-based system; identifying activation of a disaster recovery mode; and providing private application access based on one or more disaster recovery configurations.