Network Gateway Security Analysis Coordination

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer networks face inefficiencies due to redundant security analyses performed by multiple devices on the same network data packets, consuming valuable resources and hindering optimal performance without compromising security.

Innovation Solution

A system and method that intercepts network data packets, identifies the security systems on target devices, determines if they meet predefined security standards, and performs necessary security analyses at a networking device if the target device's system does not satisfy the standards, using a cloud-based server for authentication and information storage to eliminate redundant analyses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple computing devices perform security analyses on the same network data packets, then security coverage is improved, but network resources are consumed and performance deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent combines security analysis functions across multiple computing devices by implementing a centralized coordination mechanism. The gateway device coordinates with target computing devices to perform security analyses, merging their capabilities into a unified security evaluation process that avoids redundant operations while maintaining comprehensive security coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements feedback mechanisms where the gateway device receives information about security analyses performed by target computing devices and uses this feedback to avoid redundant analyses. The system tracks which security checks have been performed and communicates this information back to coordinate future security evaluations, eliminating wasted resources while maintaining security thoroughness.

Inventive Principle:
Principle #23Feedback

2Reliability

If redundant security analyses are performed on network data packets, then security thoroughness is improved, but network resource consumption increases

Engineering Contradiction:
Improvesecurity thoroughnessVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent performs preliminary security analyses at the gateway device before packets reach target computing devices. By conducting initial security checks in advance and sharing the results with target devices, the system avoids redundant analyses while maintaining thorough security evaluation, thus reducing network resource consumption without compromising security completeness.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent discards redundant security analysis operations by tracking which analyses have already been performed on packets. The system recovers network resources by eliminating duplicate security checks while maintaining a record of performed analyses to ensure thorough security evaluation is preserved through coordinated, non-redundant checks.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentEP2926523B1Systems and methods for eliminating redundant security analyses on network data packets
Publication Date: 2016.09.21 GEN DIGITAL INC
  • EP2926523B1 patent drawingFigure 1
  • EP2926523B1 patent drawingFigure 2
  • EP2926523B1 patent drawingFigure 3

AI summary

A computer-implemented method for eliminating redundant security analyses on network data packets may include (1) intercepting, at a networking device, at least one network data packet destined for a target computing device, (2) identifying a security system installed on the target computing device, (3) determining that the security system installed on the target computing device does not satisfy a predefined security standard, and then (4) performing a security analysis that satisfies the predefined security standard on the network data packet at the networking device based at least in part on determining that the security system installed on the target computing device does not satisfy the predefined security standard. Various other methods, systems, and computer-readable media are also disclosed.