Local Cache for Low Latency Cloud Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud-based security solutions for network traffic analysis often introduce significant latency due to the need for remote server authorization, which negatively impacts user experience in home or small business settings with limited computational resources.
Innovation Solution
Implementing a network security device that caches locally applicable rules for network connections, allowing or denying requests based on cached rules while forwarding uncertain requests to a cloud security service, and selectively forwarding responses only after cloud approval, thereby reducing latency by maintaining a persistent connection with the cloud security server and using locally cached rules for frequently visited destinations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cloud-based security service is used for network traffic analysis, then security analysis capability is improved, but latency increases due to remote server authorization requirements
Solution Approach 1:
The patent implements a local cache that stores security rules and threat intelligence data in advance. When network traffic needs security analysis, the system first checks the local cache for applicable rules before contacting the cloud server. This preliminary action of pre-caching security data eliminates the need for real-time cloud authorization for every connection, significantly reducing latency while maintaining security analysis capability.
2Reliability
If remote server authorization is required for each network connection, then security control is improved, but user experience deteriorates due to connection delays
Solution Approach 1:
The patent implements a hierarchical security control architecture where the local network security device has autonomous decision-making capability through cached security rules. Common local network connections can be authorized locally without cloud intervention, while unusual or high-risk connections still require cloud verification. This local quality differentiation maintains strong security control for critical decisions while providing responsive user experience for routine operations.
3Reliability
If cloud server is used for all security decisions, then centralized security management is improved, but network bandwidth consumption increases due to constant cloud communication
Solution Approach 1:
The patent segments security decision-making into two levels: common security rules and threat intelligence are cached locally at the network security device, while centralized cloud servers handle updates and exceptional cases. This segmentation allows the majority of security decisions to be made locally without cloud communication, dramatically reducing network bandwidth consumption while maintaining centralized security management for rule updates and anomaly detection.
Data Source
AI summary
Latency in a cloud security service provided via a network security device is reduced by receiving in the network security device a new network connection request for a connection between a local network device and a remote server. If a locally cached rule is applicable to the new network connection request, the applicable locally cached rule is applied to selectively allow the new network connection based on the rule. If no locally cached rule is applicable to the new network connection request, the new network connection request is forwarded to the remote server and to a cloud security service, and a response from the remote server is selectively forwarded to the local network device only upon receiving a determination by the cloud security device as to whether the new network connection is a security risk.


