Intermediary Device Caching for Cloud Security Data Transfer Cost Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security practices are inadequate in distributed enterprise environments, where remote users and cloud-based applications pose challenges for scalable and cost-effective security infrastructure, leading to vulnerabilities due to inadequate updates and high data transfer costs.

Innovation Solution

Implementing a cloud-based security service with an intermediary computing device that caches and forwards data, leveraging docker containers to reduce the number of virtual machines and optimize data transfer costs by sending confirmation rather than full data, thereby reducing expenses and enhancing scalability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is sent from the cloud data center to the specified destination, then security analysis is performed, but data transfer costs are substantially higher

Engineering Contradiction:
Improvesecurity analysisVSAvoiddata transfer costs
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

An intermediary computing device is introduced between the cloud data center and the specified destination. This intermediary receives data from the cloud data center, performs security analysis, and then forwards only approved data to the destination. This mediator role allows the system to maintain security requirements while optimizing data transfer paths to reduce costs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Security analysis is performed in advance before data is forwarded to the specified destination. The cloud data center analyzes data upfront, and only approved data is subsequently transferred to the destination through the intermediary. This preliminary security check prevents the need for costly re-transfers or corrections later.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the number of virtual machines is increased to provide security services, then security capabilities are improved, but financial cost increases

Engineering Contradiction:
Improvesecurity capabilitiesVSAvoidnumber of virtual machines
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple security service functions are merged into a single cloud data center infrastructure. Instead of deploying separate virtual machines at each remote location, the patent consolidates security analysis capabilities in the cloud, where multiple security services can operate sharelessly on pooled hardware resources.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The cloud data center is designed to provide universal security services that can be accessed by multiple remote locations and intermediary devices. A single cloud infrastructure performs multiple security functions (analysis, approval, forwarding) for various clients, eliminating the need for location-specific security infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If traditional security practices are used at each remote location, then local security control is maintained, but scalability and cost-effectiveness deteriorate

Engineering Contradiction:
Improvelocal security controlVSAvoidscalability
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The intermediary computing device serves as a local presence that maintains security control at remote locations while connecting to the centralized cloud data center. This intermediary role allows local security enforcement without requiring full security infrastructure at each site, enabling scalability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security system is segmented into two functional parts: security analysis and approval (centralized in the cloud data center) and data forwarding (distributed at intermediary locations). This segmentation allows each component to be optimized independently, with the cloud handling complex analysis and local intermediaries handling simple forwarding operations.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10608995B2Optimizing data transfer costs for cloud-based security services
Publication Date: 2020.03.31 NETSKOPE INC
  • US10608995B2 patent drawing
  • US10608995B2 patent drawing
  • US10608995B2 patent drawing

AI summary

The disclosed embodiments disclose techniques for optimizing data transfer costs for cloud-based security services. During operation, an intermediary computing device receives a network request from a client located in a remote enterprise location that is sending the network request to a distinct, untrusted remote site (e.g., a site separate from the distinct locations of the remote enterprise, the cloud data center, and the intermediary computing device). The intermediary computing device caches a set of data associated with the network request while forwarding the set of data to the cloud-based security service for analysis. Upon receiving a confirmation from the cloud-based security service that the set of data has been analyzed and is permitted to be transmitted to the specified destination, the intermediary computing device forwards the cached set of data to the specified destination.