On-Premise Gateway Redirecting Data to Cloud Scanning Service

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Private computer networks with a large number of users face challenges in managing the volume of traffic for on-premise scanning devices, which require frequent upgrades to maintain security checks effectively.

Innovation Solution

An on-premise gateway system that determines whether data needs to be scanned by a cloud scanning service, redirecting it accordingly to alleviate the burden on on-premise devices and utilize cloud resources for more thorough security checks when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is scanned by an on-premise scanning device, then security checks are performed, but the device requires frequent upgrades to accommodate additional users and handles large volumes of traffic

Engineering Contradiction:
Improvesecurity checksVSAvoidaccommodate additional users
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the scanning function by redirecting data traffic to a cloud-based scanning service instead of processing all data locally on the on-premise device. This divides the scanning workload between the on-premise gateway (which handles traffic direction) and the cloud scanner (which performs actual security analysis), allowing the on-premise device to scale without upgrading its scanning capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a cloud scanning service as an intermediary between the on-premise gateway and the destination server. The on-premise gateway receives data, determines whether to redirect it to the cloud scanner, and then forwards the data accordingly. This intermediary cloud service handles the complex scanning tasks, freeing the on-premise device from the burden of processing all data locally.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all data is scanned by an on-premise device, then security coverage is complete, but network traffic volume overwhelms the device

Engineering Contradiction:
Improvesecurity coverageVSAvoidnetwork traffic handling
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the data scanning function from the on-premise device and relocates it to a cloud-based service. The on-premise gateway continues to handle network traffic and make redirection decisions, but the actual security scanning is performed by the cloud scanner, which has the computational resources to handle large volumes of traffic without overwhelming the on-premise infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

3Loss of time

If the on-premise scanning device processes all data locally, then latency is minimized, but the device lacks the resources for thorough security checks

Engineering Contradiction:
Improvedata processing latencyVSAvoidsecurity check thoroughness
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent transitions from local two-dimensional processing (on-premise gateway handling both traffic direction and scanning) to a three-dimensional architecture where the on-premise gateway handles traffic direction and the cloud scanner handles security analysis. This dimensional shift allows the system to leverage the cloud's computational resources for thorough scanning while maintaining acceptable latency through optimized data redirection.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9203851B1Redirection of data from an on-premise computer to a cloud scanning service
Publication Date: 2015.12.01 TREND MICRO INC
  • US9203851B1 patent drawing
  • US9203851B1 patent drawing
  • US9203851B1 patent drawing

AI summary

An on-premise computer in the form of an on-premise gateway receives data transmitted by a client to an intended destination server. The on-premise gateway and the client are on-premise within the same private computer network. The on-premise gateway determines whether or not the data is to be scanned for security checks by a cloud scanning service provided by a cloud scanner on the Internet. The on-premise gateway redirects the data to the cloud scanner when the data is to be scanned in the cloud. Otherwise, when the data is not to be scanned in the cloud, the on-premise gateway forwards the data to the destination server without having the data scanned by the cloud scanner.