Edge Surrogate Browsing via Proxy Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing surrogate browsing techniques face challenges in providing a satisfactory user experience when the surrogate browser is located on a different network from the user, leading to issues such as delayed responses and incorrect location-based results.

Innovation Solution

The implementation of a scalable and elastic surrogate browsing system that uses a combination of distributed components and edge networks to provide localized content rendering and secure browsing, while maintaining user privacy and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a surrogate browser is used to protect users from malicious content, then user security is improved, but user experience deteriorates due to location-based inaccuracies and latency

Engineering Contradiction:
Improveuser securityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments the browsing function into two parts: a remote surrogate browser that handles security-risky operations and a local client that maintains the user experience. The surrogate browser is further segmented into multiple geographic locations, allowing users to connect to the nearest surrogate, thus maintaining both security and location-accurate results.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system adds a geographic dimension to the surrogate browsing architecture by deploying surrogates in multiple locations. This allows the system to select surrogates based on geographic proximity to the user, improving location-based results while maintaining security through remote execution.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If a remote surrogate browser is deployed to ensure security, then protection against threats is improved, but response time deteriorates due to network latency

Engineering Contradiction:
Improveprotection against threatsVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The system implements local quality by deploying surrogate browsers in multiple geographic locations and allowing users to connect to the nearest surrogate based on their location. This reduces network latency and improves response time while maintaining the security benefits of remote browsing through the surrogate architecture.

Inventive Principle:
Principle #3Local quality

3Reliability

If a surrogate browser is used to prevent browser compromise, then system reliability is improved, but browsing performance deteriorates due to proxy overhead

Engineering Contradiction:
Improvebrowser protectionVSAvoidbrowsing performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments the browsing architecture into a remote surrogate component that handles security and a local client component that handles rendering and user interaction. This segmentation allows the surrogate to provide security protection while the local client maintains responsive performance by performing rendering operations locally rather than through a remote proxy.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12335351B1Edge networks for surrogate browsing and direct traffic via proxy
Publication Date: 2025.06.17 MENLO SECURITY INC
  • US12335351B1 patent drawing
  • US12335351B1 patent drawing
  • US12335351B1 patent drawing

AI summary

Edge networks for surrogate browsing and direct traffic via proxy are disclosed. A first server processes a received first IPv4 packet into an encapsulation. The encapsulation is sent to a second server. The second server determines a third server to which the encapsulation should be routed and transmits it. The third server processes the encapsulation, selects a public IP address, and transmits a second IPv4 packet using the selected public IP address as a source address of the second IPv4 packet.