Mid-link server IP assignment for localized content delivery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IP address assignment systems struggle to identify and isolate malicious users among multiple users sharing a single IP address, leading to blacklisting and penalization of all users. Additionally, locations without data centers face challenges in receiving localized content.

Innovation Solution

A cloud network system that includes a client device, a mid-link server, and a cloud provider. The mid-link server creates buckets for users, assigns IP addresses to buckets, and narrows them down to assign unique IP addresses based on policies. User behavior analysis is conducted to identify threats, and a score is assigned to IP addresses. Requests are routed to a sub-data center with an IP address specific to the user location, enabling localized content delivery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a single IP address is shared by multiple users, then resource utilization is improved, but security and abuse mitigation deteriorate because the entire IP address gets blacklisted when one user commits malicious activity

Engineering Contradiction:
ImproveIP address utilization efficiencyVSAvoidAbuse mitigation capability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the single shared IP address into multiple virtual IP addresses (vIPs), where each user or user group is assigned a unique vIP. This segmentation allows the system to maintain high IP address utilization (one physical IP serving multiple users) while preventing abuse propagation (compromise of one user's vIP doesn't blacklist the entire shared IP or other users' vIPs). The mid-link server manages this segmentation by creating buckets of users and assigning vIPs dynamically.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If data centers are deployed in all locations, then localized content delivery is improved, but infrastructure complexity and cost worsen

Engineering Contradiction:
ImproveLocalized content delivery capabilityVSAvoidData center distribution infrastructure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a mid-link server as an intermediary component that enables localized content delivery without requiring data centers in every location. The mid-link server acts as a mediator between users and remote data centers, handling IP address assignment, user behavior analysis, and request routing. This allows users in locations without data centers to receive localized content through the intermediary's coordination with nearest available data centers.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If user behavior analysis is performed to identify threats, then security is improved, but system complexity and processing time worsen

Engineering Contradiction:
ImproveThreat identification accuracyVSAvoidUser behavior analysis system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies partial action by performing user behavior analysis selectively rather than uniformly on all users. The system creates buckets of users and focuses analysis on specific buckets or users showing suspicious patterns, rather than continuously analyzing every user's behavior. This reduces system complexity and processing overhead while maintaining effective threat identification for problematic users.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250097247A1Conditional egress IP address assignment and scoring for delivery of localized content
Publication Date: 2025.03.20 NETSKOPE INC
  • US20250097247A1 patent drawing
  • US20250097247A1 patent drawing
  • US20250097247A1 patent drawing

AI summary

A cloud network for delivering local content to a user at a user location. The cloud network includes a client device comprising a local application, a mid link server and a cloud provider. The mid link server receives from the client device a request for local data from the user at the user location. The user has provided the request for the local data from the user location without a data center. A sub data center for the user location is identified and assigned an Internet Protocol (IP) address for the user location. The sub-data center is a data center nearest to the user location. Each data center has IP addresses for different locations to deliver the local content to the respective IP address for the location. The request is routed to the sub data center which is used to provide the local data to the user by the cloud provider. A cloud network for delivering local content to user locations. The cloud network includes a client device, a mid-link server, and a cloud provider. The mid-link server receives requests using a local application of the client device for local data from the user at a user location. The mid link server creates multiple buckets for the users and assigns IP addresses to buckets. The buckets are further narrowed to assign a unique IP address to the user based on the policies. User behavior is analyzed to identify a threat and a score is assigned to the IP address of user. A sub-data center is routed the request. Each data center has IP addresses for different locations to deliver the local content to the respective IP address. The request is routed to the sub-data center which is used to provide the local data to the user by the cloud provider.