Local Device Proxy for Secure Low-Latency Traffic Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The exponential growth of mobile users bypassing conventional network security devices like corporate firewalls and secure web gateways leads to increased security risks and performance bottlenecks due to latency and network bottlenecks caused by external proxy servers.

Innovation Solution

A device proxy is installed on user computing devices to decrypt and inspect traffic, eliminating latency and performance issues by managing SSL traffic and encryption keys locally, ensuring secure data access and storage while preventing interception by unauthorized devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traffic is routed through external hosted proxy servers for security inspection, then security inspection capability is improved, but network latency increases substantially (10-100 ms)

Engineering Contradiction:
Improvesecurity inspection capabilityVSAvoidnetwork latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces a local proxy server as an intermediary component installed on the user's computing device. This local proxy acts as a mediator between the application and the external network, enabling security inspection functions to be performed locally rather than requiring all traffic to travel to external hosted proxies. The local proxy maintains security inspection capabilities while eliminating the substantial latency (10-100 ms) associated with WAN-based proxy servers by keeping the inspection process on the same LAN as the end device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all network traffic is routed through external proxy servers for inspection, then security monitoring is improved, but network performance degrades due to bottlenecks at peak loads

Engineering Contradiction:
Improvesecurity monitoringVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the proxy functionality by distributing it across multiple locations - a local proxy server on each user device and a remote proxy server for centralized management. This segmentation allows security monitoring to be performed locally without consolidating all traffic through a single external proxy bottleneck. The local proxy handles inspection independently for each device, eliminating the network bottleneck that occurs when peak loads concentrate traffic through external hosted proxies.

Inventive Principle:
Principle #1Segmentation

3Reliability

If proxy servers are geographically distributed at multiple locations, then security coverage is improved, but device complexity and deployment difficulty increase

Engineering Contradiction:
Improvesecurity coverageVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The local proxy server is designed to be self-installing and self-configuring on user devices, eliminating the need for complex manual deployment configurations. The system automatically manages the distribution and configuration of local proxies across the organization's network. This self-service approach maintains comprehensive security coverage through geographically distributed local proxies while dramatically reducing deployment complexity compared to traditional centralized proxy solutions.

Inventive Principle:
Principle #25Self-service

4Reliability

If encryption keys are managed centrally on external servers, then key management security is improved, but access latency and performance overhead increase

Engineering Contradiction:
Improvekey management securityVSAvoidkey access latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a nested key management structure where local proxy servers on user devices hold cached encryption keys locally, while maintaining a secure connection to the remote proxy server for key updates and management. This nested approach allows frequent key access operations to be performed locally without external server round trips, eliminating access latency. Meanwhile, the remote server maintains centralized control for key generation, distribution, and rotation, preserving key management security. The local cache acts as a nested layer between the application and the external key management infrastructure.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS11784980B2Secure low-latency trapdoor proxy
Publication Date: 2023.10.10 BITGLASS LLC
  • US11784980B2 patent drawing
  • US11784980B2 patent drawing
  • US11784980B2 patent drawing

AI summary

A proxy system is installed on a computing device that is in the network path between the device and the Internet. The proxy system, residing on the computing device, decrypts and inspects all traffic going in and out of the computing device.