Data Relay Device Security Rule Optimization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data relay devices with multiple security functions face increased load and reduced throughput due to unnecessary execution of security processes, especially when a security problem is detected, leading to inefficiencies and performance degradation.

Innovation Solution

A data relay device that executes security functions in a predetermined order and uses a determination result to change rules for subsequent processes, skipping unnecessary steps by denying relay and updating rules to avoid executing subsequent security functions on problematic data from specific sources, thereby reducing the load and improving throughput.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security functions are executed sequentially on inputted data, then security coverage is improved, but device load increases and throughput decreases

Engineering Contradiction:
Improvesecurity coverageVSAvoidthroughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by executing security functions in a predetermined sequence and stopping further execution once a security problem is detected. The system performs firewall processing, then anti-virus processing, then spam filtering in order, and halts subsequent processing when an issue is found in earlier stages, preventing unnecessary execution of later security functions on already problematic data

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements skipping by allowing the data relay device to bypass remaining security function executions when a security problem is detected in earlier functions. Instead of sequentially executing all planned security functions, the system skips the remaining ones after detecting an issue, thereby reducing device load while maintaining security effectiveness

Inventive Principle:
Principle #21Skipping (Rushing through)

2Measurement precision

If all security functions are executed on every data packet, then security detection accuracy is improved, but processing time increases

Engineering Contradiction:
Improvesecurity detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary security checks in a predetermined sequence (firewall → anti-virus → spam filtering) and stops further processing once a security issue is detected in an earlier stage, preventing waste of processing time on packets that already have identified security problems

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

When a security problem is detected in earlier security functions, the system skips execution of subsequent security functions on that data packet, thereby reducing processing time while maintaining detection accuracy through the sequential execution of necessary checks

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS8151340B2Data relay device and data relay method
Publication Date: 2012.04.03 FUJITSU LTD
  • US8151340B2 patent drawing
  • US8151340B2 patent drawing
  • US8151340B2 patent drawing

AI summary

A data relay device has a plurality of security functions sequentially executes security functions on inputted data based on a predetermined rule, to determine whether or not to permit the relay of the data, and denies the relay of the data the relay is determined to be rejected. The data relay device has a determination result acquisition unit that acquires a determination result indicating permission or rejection of relay of the data, and a rule change unit that changes, based on the determination result acquired by the determination result acquisition unit, a rule defined for any one of the security functions located forward of the security function that has determined relay rejection, so that the relay of the communication data is determined to be rejected.