Edge Network Security with Selective Traffic Suspension

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security solutions that migrate to edge security face a tradeoff between costly processing power and increased throughput, often resulting in sub-standard security, particularly due to inefficient use of wide area network (WAN) bandwidth and unnecessary security processing for low-risk traffic.

Innovation Solution

Implementing selectively suspended network security processing, where a non-edge security processing device applies intensive security processing to a subset of network traffic, allowing edge devices to suspend security review for less risky traffic, thereby reducing the need for WAN bandwidth and lowering costs by eliminating unnecessary security inspections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If intensive security processing is applied to all network traffic at the edge, then security effectiveness is improved, but processing cost and device complexity increase

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidprocessing cost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies different security processing levels to different portions of network traffic based on risk assessment. High-risk traffic receives intensive security processing while low-risk traffic receives reduced processing, creating localized quality variations in security enforcement that optimize both security effectiveness and processing cost.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial security processing by applying intensive security measures only to identified high-risk traffic portions rather than all traffic. This partial action approach maintains security effectiveness for critical traffic while reducing overall processing complexity and cost.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If intensive security processing is applied to all network traffic, then security effectiveness is improved, but WAN bandwidth usage increases

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidWAN bandwidth usage
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent selectively applies security processing to local high-risk traffic portions identified through risk assessment, allowing low-risk traffic to bypass intensive processing. This local quality approach reduces WAN bandwidth consumption while maintaining security effectiveness for critical traffic segments.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent extracts and identifies high-risk traffic portions from the overall network traffic flow, separating them for intensive security processing while allowing the remaining low-risk traffic to flow with reduced processing requirements, thereby reducing WAN bandwidth usage.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If security review is performed on all network traffic sessions, then security effectiveness is improved, but throughput decreases

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidthroughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements local quality by applying full security review only to identified high-risk traffic sessions while reducing or suspending security review for low-risk sessions. This creates varying levels of security processing across different traffic portions, maintaining security effectiveness for critical traffic while improving overall throughput.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent applies partial security review action to network traffic by suspending security processing for portions of traffic sessions deemed low-risk after initial assessment. This partial action maintains security for high-risk traffic while eliminating unnecessary processing overhead for low-risk traffic, thereby improving throughput.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20240414210A1Systems and methods for edge processing using selectively suspended network security
Publication Date: 2024.12.12 FORTINET INC
  • US20240414210A1 patent drawing
  • US20240414210A1 patent drawing
  • US20240414210A1 patent drawing

AI summary

Various embodiments provide embodiments provide systems and methods for performing edge processing using selectively suspended network security processing.