Multiple-Point SASE Access Control Through Device Arbitration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security solutions involving multiple SASE processing capable devices are inefficient and wasteful due to redundant processing by multiple devices, leading to increased costs and time consumption.

Innovation Solution

Implement mechanisms for arbitration between SASE capable network devices to select a single device for SASE processing, allowing direct connection to a SASE service without relying on intermediary devices like DSL or cable modems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple SASE processing capable devices are deployed in a secure network, then network security coverage is improved, but redundant processing occurs leading to increased costs and time consumption

Engineering Contradiction:
Improvenetwork security coverageVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges multiple SASE processing capabilities into a single operational processing point through arbitration. The system combines the SASE capabilities of multiple devices but activates only one at a time for actual processing, eliminating redundant operations while maintaining comprehensive security coverage across the network.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements dynamic selection of SASE processing devices through arbitration mechanisms. The system can dynamically determine which device performs SASE processing based on current network conditions, traffic patterns, and device availability, allowing the security architecture to adapt rather than statically assigning processing to all devices.

Inventive Principle:
Principle #15Dynamics

2Reliability

If multiple SASE processing capable devices perform SASE processing on network traffic, then security redundancy is improved, but processing time and resource consumption increase

Engineering Contradiction:
Improvesecurity redundancyVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines the security capabilities of multiple devices into a unified processing operation. Through arbitration, the system merges the potential processing power of multiple devices into a single coordinated action, ensuring that only one device performs the actual SASE processing at any given time, thus maintaining security redundancy without the overhead of simultaneous processing.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements feedback mechanisms where devices communicate their processing status and capabilities to the arbitration system. This feedback allows the system to make informed decisions about which device should perform SASE processing, optimizing processing time by selecting the most appropriate device based on real-time conditions rather than using fixed or random selection.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If intermediary devices like DSL or cable modems are used for SASE processing, then network compatibility is improved, but direct access to SASE services is blocked

Engineering Contradiction:
Improvenetwork compatibilityVSAvoiddirect SASE service access
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent extracts the SASE processing function from intermediary devices and assigns it directly to capable network devices. By taking out the SASE processing capability from the traditional intermediary device role, the system allows endpoints to access SASE services directly without being forced through DSL or cable modems, while still maintaining compatibility with these intermediary devices in the network path.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent redefines the role of intermediary devices in the SASE architecture. Rather than requiring all traffic to pass through traditional intermediary devices for SASE processing, the system uses arbitration to determine which device acts as the intermediary for SASE access. This allows flexible mediation where capable devices can directly access SASE services while still working within existing network infrastructure that includes DSL or cable modems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12464356B2Systems and methods for multiple point SASE access control
Publication Date: 2025.11.04 FORTINET INC
  • US12464356B2 patent drawing
  • US12464356B2 patent drawing
  • US12464356B2 patent drawing

AI summary

Various systems, devices, storage media, and methods are discussed for performing secured access service edge (SASE) processing in a network potentially having multiple SASE processing capable devices.