Local Cache for Low Latency Cloud Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based security solutions for network traffic analysis often introduce significant latency due to the need for remote server authorization, which negatively impacts user experience in home or small business settings with limited computational resources.

Innovation Solution

Implementing a network security device that caches locally applicable rules for network connections, allowing or denying requests based on cached rules while forwarding uncertain requests to a cloud security service, and selectively forwarding responses only after cloud approval, thereby reducing latency by maintaining a persistent connection with the cloud security server and using locally cached rules for frequently visited destinations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud-based security service is used for network traffic analysis, then security analysis capability is improved, but latency increases due to remote server authorization requirements

Engineering Contradiction:
Improvesecurity analysis capabilityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a local cache that stores security rules and threat intelligence data in advance. When network traffic needs security analysis, the system first checks the local cache for applicable rules before contacting the cloud server. This preliminary action of pre-caching security data eliminates the need for real-time cloud authorization for every connection, significantly reducing latency while maintaining security analysis capability.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If remote server authorization is required for each network connection, then security control is improved, but user experience deteriorates due to connection delays

Engineering Contradiction:
Improvesecurity controlVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a hierarchical security control architecture where the local network security device has autonomous decision-making capability through cached security rules. Common local network connections can be authorized locally without cloud intervention, while unusual or high-risk connections still require cloud verification. This local quality differentiation maintains strong security control for critical decisions while providing responsive user experience for routine operations.

Inventive Principle:
Principle #3Local quality

3Reliability

If cloud server is used for all security decisions, then centralized security management is improved, but network bandwidth consumption increases due to constant cloud communication

Engineering Contradiction:
Improvecentralized security managementVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments security decision-making into two levels: common security rules and threat intelligence are cached locally at the network security device, while centralized cloud servers handle updates and exceptional cases. This segmentation allows the majority of security decisions to be made locally without cloud communication, dramatically reducing network bandwidth consumption while maintaining centralized security management for rule updates and anomaly detection.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11736528B2Low latency cloud-assisted network security with local cache
Publication Date: 2023.08.22 GEN DIGITAL INC
  • US11736528B2 patent drawing
  • US11736528B2 patent drawing
  • US11736528B2 patent drawing

AI summary

Latency in a cloud security service provided via a network security device is reduced by receiving in the network security device a new network connection request for a connection between a local network device and a remote server. If a locally cached rule is applicable to the new network connection request, the applicable locally cached rule is applied to selectively allow the new network connection based on the rule. If no locally cached rule is applicable to the new network connection request, the new network connection request is forwarded to the remote server and to a cloud security service, and a response from the remote server is selectively forwarded to the local network device only upon receiving a determination by the cloud security device as to whether the new network connection is a security risk.