In-Channel Event Processing for Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The growth of endpoint mobile devices and cloud services in enterprises leads to complexity in managing multiple applications for secure access, with existing solutions failing to provide unified service discovery and secure availability, resulting in user frustration and productivity losses due to network constraints and lack of real-time notifications for network issues.

Innovation Solution

A method for in-channel event processing in cloud-based security systems that intercepts and monitors network transactions from network-agnostic mobile applications, using a secure tunneling protocol to adapt to enterprise network constraints and provide real-time notifications and remediation actions to users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple separate applications are deployed for different enterprise services (VPN, web security, resource access), then each service can be secured independently, but device complexity and ease of operation deteriorate due to the need to manage and configure multiple applications

Engineering Contradiction:
Improveservice securityVSAvoidapplication management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple separate enterprise service applications (VPN client, web security filter, resource access application) into a single unified application that provides all these functions through a common interface and shared configuration management, thereby reducing device complexity while maintaining service security

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified application is designed to perform multiple functions simultaneously - providing VPN connectivity, web security filtering, and corporate resource access - allowing a single application to replace multiple specialized applications and simplify the overall system architecture

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple separate applications are deployed for different enterprise services, then each service can be secured independently, but ease of operation deteriorates due to the need for users to manually configure and reconfigure each application for network changes

Engineering Contradiction:
Improveservice securityVSAvoidconfiguration simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

By merging configuration management across all enterprise services into a single unified application, the system automatically detects network changes and applies appropriate configuration updates to all services simultaneously, eliminating the need for users to manually reconfigure each application

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified application incorporates automatic network condition detection and self-configuration capabilities, where the application monitors network changes and automatically adjusts its settings and service configurations without requiring user intervention, thereby improving ease of operation

Inventive Principle:
Principle #25Self-service

3Ease of manufacture

If applications are designed to communicate with dedicated servers making them agnostic of network path, then application development is simplified, but reliability deteriorates in enterprise environments with firewalls, packet filters, and network access controls

Engineering Contradiction:
Improveapplication development simplicityVSAvoidnetwork connectivity reliability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The unified application acts as an intermediary between network-agnostic mobile applications and enterprise network infrastructure, providing intelligence about network conditions, firewalls, and access controls to enable applications to adapt their communication patterns while maintaining development simplicity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically changes communication parameters such as protocol selection, port usage, and transmission methods based on detected network conditions and enterprise security requirements, allowing applications to maintain reliability across different network environments without requiring complex built-in adaptation logic

Inventive Principle:
Principle #35Parameter changes

4Reliability

If users manually reconfigure each application for network changes, then network security control is maintained, but productivity deteriorates due to user frustration and time loss

Engineering Contradiction:
Improvenetwork security controlVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The unified application automatically detects network changes and performs self-configuration across all enterprise services, eliminating the need for user intervention while maintaining security policies, thereby preventing productivity losses associated with manual reconfiguration

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors network conditions and provides real-time feedback to automatically adjust service configurations, ensuring security requirements are met while eliminating user frustration and time loss associated with manual intervention

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10432673B2In-channel event processing for network agnostic mobile applications in cloud based security systems
Publication Date: 2019.10.01 ZSCALER INC
  • US10432673B2 patent drawing
  • US10432673B2 patent drawing
  • US10432673B2 patent drawing

AI summary

Systems and methods in a mobile device communicatively coupled to a cloud based security system, the method for detecting and processing in-channel events associated with a network agnostic mobile application, the method includes intercepting outgoing data from the network agnostic mobile application at a tunnel interface on the mobile device; monitoring the outgoing data for network transactions from the network agnostic mobile application to maintain a context of the network transactions and intended responses for every request; transmitting the outgoing data from the tunnel interface to the cloud based security system; and receiving a response from the cloud based security system responsive to the outgoing data and processing any deviation from the intended responses.