Distributed Security Message Processing with Time Constraints

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing layered security systems face challenges in maintaining a central data store for threat data and distributing content intelligence across a network, leading to repeated processing of both good and bad content, which can degrade system performance.

Innovation Solution

A distributed security message processing system where processing nodes and authority nodes communicate in real-time, with time constraints to optimize message processing, ensuring that security requests are only initiated if they can be performed within specified time limits, thereby improving cache hit ratios and reducing processing delays.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security requests are transmitted to authority nodes for centralized processing, then security data accuracy is improved, but system response time deteriorates due to network latency and centralized bottlenecks

Engineering Contradiction:
Improvesecurity data accuracyVSAvoidsystem response time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements local quality by enabling processing nodes to autonomously determine whether to perform security operations locally or remotely based on time constraints. Each node assesses its own capabilities and the urgency of security requests, making decentralized decisions that optimize both accuracy and response time for local conditions

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts the security operation execution location based on real-time conditions. Processing nodes evaluate time constraints and system state to determine whether to execute security operations locally or transmit requests to authority nodes, creating a flexible hybrid architecture that adapts to varying performance requirements

Inventive Principle:
Principle #15Dynamics

2Loss of time

If security operations are performed locally at processing nodes, then system response time is improved, but security data consistency deteriorates due to distributed decision-making

Engineering Contradiction:
Improveprocessing delayVSAvoidsecurity data consistency
Core Design Contradiction:
Loss of timeVSStability of the object's composition

Solution Approach 1:

The patent implements feedback mechanisms where processing nodes transmit security request information to authority nodes, which provide guidance on whether local execution is appropriate. This feedback loop ensures that distributed decisions maintain overall system consistency while enabling fast local responses when conditions permit

Inventive Principle:
Principle #23Feedback

3Reliability

If the system transmits all security requests to authority nodes, then security operation reliability is improved, but system productivity deteriorates due to repeated processing and network overhead

Engineering Contradiction:
Improvesecurity operation reliabilityVSAvoidsystem throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial action by having processing nodes perform security operations locally only when time constraints are satisfied and local capabilities are sufficient. This partial execution approach eliminates unnecessary network transmissions and centralized processing for routine or time-sensitive operations, thereby improving system throughput while maintaining reliability for critical operations

Inventive Principle:
Principle #16Partial or excessive action

4Productivity

If the system allows local security operation execution, then system productivity is improved by reducing network traffic, but security operation control deteriorates due to decentralized execution

Engineering Contradiction:
Improvesystem throughputVSAvoidsecurity operation control
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by having processing nodes evaluate time constraints and determine execution location before performing security operations. This advance decision-making framework ensures that local executions are pre-approved based on system policies and constraints, maintaining control while enabling productivity improvements

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2283670B1Security message processing within constrained time
Publication Date: 2019.02.20 ZSCALER INC
  • EP2283670B1 patent drawingFigure 1
  • EP2283670B1 patent drawingFigure 2
  • EP2283670B1 patent drawingFigure 3~4

AI summary

Systems, methods and apparatus for handling security messages in a distributed security system. Requests, replies, and/or updates have varying time constraints. Processing node managers and authority node managers determine the best transmission times and/or the ignoring of such data to maximize information value.