Multipath Traffic Coordination via Cloud Security Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current multipath communication protocols, such as Multipath TCP, face challenges in correlating and securing data flows across different networks, leading to incomplete security analysis and potential malicious content transmission, as security servers for different network paths do not coordinate effectively.
Innovation Solution
A method involving a mobile device that connects to a primary network, identifies a cloud connector, and directs subflows to a cloud security server through multiple interfaces, enabling correlation and security analysis of data packets across multiple communication paths, using a secure mobility client to enforce security policies and detect malicious software.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If multipath communication protocols are used to transmit data through multiple networks, then data transmission capacity and bandwidth are improved, but security analysis completeness deteriorates because security servers for different network paths do not coordinate effectively
Solution Approach 1:
The patent merges multiple unconnected security servers into a coordinated system by introducing a flow identifier that links subflows across different networks to a single parent TCP flow. This allows security analysis to be consolidated and correlated across multiple network paths, transforming independent security servers into a unified security analysis system that can comprehensively inspect data regardless of which network path it takes.
Solution Approach 2:
The patent introduces a flow identifier as an intermediary element that mediates between multiple network paths and the security server. This flow identifier acts as a common reference that allows the security server to correlate packets from different subflows (Wi-Fi, cellular, etc.) with the same parent flow, enabling comprehensive security analysis without requiring direct coordination between multiple independent security servers.
2Productivity
If multiple TCP connections are established to provide parallel paths between hosts, then bandwidth and data availability are improved, but connection management complexity increases
Solution Approach 1:
The patent segments the connection management problem by separating the parent TCP connection from its subflows. Each subflow (on different networks like Wi-Fi or cellular) is independently managed but linked to the parent flow through a flow identifier. This segmentation allows parallel paths to operate independently while maintaining centralized coordination through the parent flow concept, reducing the complexity of managing multiple independent TCP connections.
Solution Approach 2:
The patent creates a universal parent flow concept that can accommodate multiple subflows across different networks and protocols. This parent flow structure serves multiple functions: it provides a common identification mechanism, enables centralized security analysis, and allows dynamic addition or removal of subflows without restructuring the entire connection management system.
3Adaptability or versatility
If security servers for different network paths operate independently, then network path autonomy is maintained, but malicious content detection capability deteriorates due to incomplete security analysis
Solution Approach 1:
The patent implements feedback by having the security server analyze packets from multiple subflows and use the flow identifier to correlate findings across different network paths. The security server receives feedback from each subflow's packet inspection and uses the parent flow identification to aggregate this information, enabling comprehensive malicious content detection that leverages observations from all network paths while maintaining their operational autonomy.
Data Source
AI summary
In one implementation, traffic in a mobile network is directed across multiple paths to a single cloud server or security server (e.g., a security as a service). The mobile device detects a cloud connector through a primary connection based on an attachment or connection via a first interface of a mobile device. The mobile device sends a request to the cloud connector for an identification of a cloud security server associated with the cloud connector. After receiving the identification of the cloud security server, the mobile device directs one or more subsequent data flows or subflows for a second interface or another interface of the mobile device to the cloud server or security server. The second data flow and the second interface are associated with another network that is external to the enterprise network and trusted network connection or not associated with the enterprise network and the trusted network connection.


