Gateway Load Balancing and Failover for Cryptographic Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing gateway devices face challenges in load balancing and failover, leading to inefficiencies in data/resource availability and increased complexity due to the need for redundant systems and point-to-point data protection, which complicates the management of communication and security across trusted and untrusted networks.

Innovation Solution

A method and system for load balancing and failover across gateway devices that support communication of cryptographically split data, involving a control gateway that assigns communication requests using a load balancing algorithm and automatically designates a new control gateway in case of failure, ensuring continuous operation and secure data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If redundant gateway devices are implemented to ensure data availability and prevent downtime, then reliability is improved, but device complexity increases substantially

Engineering Contradiction:
Improvedata availabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the gateway functionality into two distinct roles: control gateway devices that manage licensing and coordination, and worker gateway devices that handle actual data processing. This segmentation allows redundancy to be implemented more efficiently by distributing control functions centrally while allowing worker nodes to be replaced or added without proportionally increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Multiple worker gateway devices are merged into a coordinated group that shares a single control gateway. This merging allows the system to achieve redundancy and load distribution benefits while minimizing the complexity increase that would result from each gateway being fully independent. The control gateway consolidates management functions for multiple workers.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If redundant gateway devices are implemented to ensure data availability, then reliability is improved, but the number of data vulnerability locations increases

Engineering Contradiction:
Improvedata availabilityVSAvoiddata vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The control gateway acts as an intermediary between worker gateways and external systems. All licensing, authentication, and coordination traffic flows through the control gateway, which mediates access and enforces security policies. This intermediary role allows worker gateways to be redundant without proportionally increasing vulnerability points, as the control gateway centralizes security management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The control gateway provides universal security functions for the entire worker gateway group, including centralized licensing, authentication, and coordination. This multi-functionality means that security management is consolidated rather than distributed across each worker node, reducing the number of independent vulnerability locations while maintaining reliability through worker redundancy.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If point-to-point data protection schemes are employed for secure data transmission, then security is improved, but adaptability to redundant systems deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidsystem scalability
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent segments data protection into two layers: point-to-point encryption between individual worker gateways and the control gateway for secure communication, and cryptographic splitting of data across multiple worker gateways. This segmentation allows secure point-to-point channels to coexist with a redundant multi-node architecture, as each worker maintains secure individual channels while the system as a whole achieves redundancy through distributed storage and processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security architecture combines multiple protection mechanisms: point-to-point encryption for channel security, cryptographic splitting for data redundancy and security, and centralized licensing for access control. This composite approach integrates traditionally conflicting security models, allowing both point-to-point protection and redundant system architecture to work together synergistically.

Inventive Principle:
Principle #40Composite materials

4Object-affected harmful factors

If gateway devices coordinate responses to untrusted networks, then security is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity coordinationVSAvoidcoordination complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The control gateway serves as an intermediary that centralizes coordination of security responses. When security events occur on worker gateways, the control gateway mediates the response coordination, licensing decisions, and policy enforcement. This intermediary role consolidates coordination complexity in a single node rather than requiring complex peer-to-peer coordination among all gateway devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback loops where worker gateways report status and security events to the control gateway, which then coordinates appropriate responses. This feedback mechanism allows security coordination to be managed centrally through standardized communication protocols, reducing the complexity that would arise from distributed autonomous decision-making among multiple gateways.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8341722B2Load balancing and failover of gateway devices
Publication Date: 2012.12.25 UNISYS CORP
  • US8341722B2 patent drawing
  • US8341722B2 patent drawing
  • US8341722B2 patent drawing

AI summary

Methods and systems for load balancing and failover among gateway devices are disclosed. One method provides for assigning communication transaction handling to a gateway. The method includes receiving a request for a license from a computing device at a control gateway within a group of gateway devices including a plurality of gateway devices configured to support communication of cryptographically split data. The method also includes assigning communications from the computing device to one of the plurality of gateway devices based on a load balancing algorithm, and routing the communication request to the assigned gateway device.