Gateway Content Filtering Delegation to Client Agents

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Content filtering at gateway computers is CPU-intensive and unsustainable due to rapidly growing pattern sizes, requiring significant resources and additional maintenance, making it difficult to effectively manage network security threats.

Innovation Solution

A system where a gateway computer delegates content filtering services to client computers, utilizing a master entity to determine which services can be reliably performed by each client, with trusted agents coordinating filtering efforts and maintaining up-to-date configurations and policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If content filtering services are performed at the gateway computer, then network security protection is provided, but CPU load and resource consumption increase significantly

Engineering Contradiction:
Improvenetwork security protectionVSAvoidCPU load
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The content filtering service is segmented into multiple distributed filtering instances deployed across different client computers in the network. Each client computer runs a filtering instance that handles filtering for its local traffic, dividing the overall filtering task from a single gateway-based system into multiple distributed components. This segmentation reduces the CPU load on the gateway computer while maintaining network-wide security protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Client computers are empowered to perform their own content filtering operations through locally deployed filtering instances. Each client computer independently executes filtering operations on its own traffic without requiring centralized processing at the gateway, enabling self-service filtering that reduces dependency on gateway resources and lowers overall system CPU consumption.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If content filtering services are performed at the gateway computer, then centralized control is maintained, but device complexity and maintenance difficulty increase

Engineering Contradiction:
Improvecentralized controlVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The gateway computer maintains multi-functionality by serving both as a network gateway and as a coordinator for distributed filtering instances. The filtering service is designed to operate in both centralized (gateway-based) and distributed (client-based) modes, providing universal functionality that adapts to different deployment scenarios. This universality allows centralized control to be maintained through coordination protocols while the actual filtering workload is distributed, reducing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If content filtering patterns are updated frequently, then filtering effectiveness is improved, but the size of patterns and storage requirements grow rapidly

Engineering Contradiction:
Improvefiltering effectivenessVSAvoidpattern size
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

Filtering patterns are segmented and distributed across multiple client computers rather than being centralized in the gateway. Each client computer stores and processes a portion of the overall pattern set, reducing the pattern size burden on any single system. This segmentation allows frequent updates to be distributed incrementally across the network, improving filtering effectiveness without causing rapid growth in centralized storage requirements.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8082583B1Delegation of content filtering services between a gateway and trusted clients in a computer network
Publication Date: 2011.12.20 TREND MICRO INC
  • US8082583B1 patent drawing
  • US8082583B1 patent drawing
  • US8082583B1 patent drawing

AI summary

Method and system for performing content filtering services in a computer network. A gateway computer may be configured to be in the data path of network communications between client computers in a private computer network and computers in a public computer network. A master entity in the gateway computer may be configured to determine content filtering services available in the client computers. The master entity may delegate to the client computers performance of content filtering services that may be reliably performed in the client computers. Each of the client computers may include a trusted agent in communication with the master entity to coordinate content filtering in the private computer network.