Local-Agent REST API for Selective Network Path Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The traditional enterprise network perimeter is no longer sufficient with the shift to cloud-based applications and remote users, leading to increased security risks and scalability issues, as well as the need for applications to know network paths for proxy settings and network path detection for optimized cloud interactions.

Innovation Solution

A REST API provided by a local agent on user devices to detect and manage network paths, enabling service-driven split tunneling and unified service discovery, allowing applications to determine network paths, cache them, and send requests with additional information for optimized cloud interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all traffic is routed through the well-defined perimeter for security, then security protection is improved, but scalability and performance deteriorate due to increased latency and bottleneck effects

Engineering Contradiction:
Improvesecurity protectionVSAvoidscalability and performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments network traffic into different categories (enterprise traffic requiring security inspection vs. non-enterprise traffic) and routes them through different paths. The local agent on user devices determines the network path for each request, allowing selective routing through the security perimeter only when necessary, thereby maintaining security for critical traffic while improving overall scalability and performance.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If remote users are allowed direct access to the network, then scalability and ease of operation are improved, but security risks increase due to unsecured devices and unauthorized access

Engineering Contradiction:
Improvescalability and remote accessVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a local agent as an intermediary component on user devices that acts as a security gateway. This agent intercepts requests, determines the appropriate network path, and enforces security policies locally. This allows remote users to access the network directly without traditional VPNs while maintaining security through the intermediary agent that can identify and route enterprise traffic appropriately.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If applications need to determine network paths for proxy settings, then request accuracy is improved, but computational overhead and device complexity increase

Engineering Contradiction:
Improverequest accuracyVSAvoidcomputational overhead
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by having the local agent determine and cache network paths before actual requests are made. The agent proactively identifies the network path for a destination and stores this information for future use. This eliminates the need for applications to perform complex real-time path determination, reducing computational overhead while maintaining accurate routing information.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12445439B2Rest API provided by a local agent to detect network path of a request
Publication Date: 2025.10.14 ZSCALER INC
  • US12445439B2 patent drawing
  • US12445439B2 patent drawing
  • US12445439B2 patent drawing

AI summary

Systems and methods implemented by a user device include receiving a request, from an application executed on the user device, to identify a network path for a destination; determining the network path to the destination including ports, addresses, and inline proxies; and providing details of the network path to the application.