Multiple-Point SASE Access Control Through Device Arbitration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security solutions involving multiple SASE processing capable devices are inefficient and wasteful due to redundant processing by multiple devices, leading to increased costs and time consumption.
Innovation Solution
Implement mechanisms for arbitration between SASE capable network devices to select a single device for SASE processing, allowing direct connection to a SASE service without relying on intermediary devices like DSL or cable modems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple SASE processing capable devices are deployed in a secure network, then network security coverage is improved, but redundant processing occurs leading to increased costs and time consumption
Solution Approach 1:
The patent merges multiple SASE processing capabilities into a single operational processing point through arbitration. The system combines the SASE capabilities of multiple devices but activates only one at a time for actual processing, eliminating redundant operations while maintaining comprehensive security coverage across the network.
Solution Approach 2:
The patent implements dynamic selection of SASE processing devices through arbitration mechanisms. The system can dynamically determine which device performs SASE processing based on current network conditions, traffic patterns, and device availability, allowing the security architecture to adapt rather than statically assigning processing to all devices.
2Reliability
If multiple SASE processing capable devices perform SASE processing on network traffic, then security redundancy is improved, but processing time and resource consumption increase
Solution Approach 1:
The patent combines the security capabilities of multiple devices into a unified processing operation. Through arbitration, the system merges the potential processing power of multiple devices into a single coordinated action, ensuring that only one device performs the actual SASE processing at any given time, thus maintaining security redundancy without the overhead of simultaneous processing.
Solution Approach 2:
The patent implements feedback mechanisms where devices communicate their processing status and capabilities to the arbitration system. This feedback allows the system to make informed decisions about which device should perform SASE processing, optimizing processing time by selecting the most appropriate device based on real-time conditions rather than using fixed or random selection.
3Adaptability or versatility
If intermediary devices like DSL or cable modems are used for SASE processing, then network compatibility is improved, but direct access to SASE services is blocked
Solution Approach 1:
The patent extracts the SASE processing function from intermediary devices and assigns it directly to capable network devices. By taking out the SASE processing capability from the traditional intermediary device role, the system allows endpoints to access SASE services directly without being forced through DSL or cable modems, while still maintaining compatibility with these intermediary devices in the network path.
Solution Approach 2:
The patent redefines the role of intermediary devices in the SASE architecture. Rather than requiring all traffic to pass through traditional intermediary devices for SASE processing, the system uses arbitration to determine which device acts as the intermediary for SASE access. This allows flexible mediation where capable devices can directly access SASE services while still working within existing network infrastructure that includes DSL or cable modems.
Data Source
AI summary
Various systems, devices, storage media, and methods are discussed for performing secured access service edge (SASE) processing in a network potentially having multiple SASE processing capable devices.


