Network Gateway Session Routing for Security and Latency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Companies face challenges in managing data transfers across networks due to vulnerabilities from malicious code, unauthorized access, and bandwidth issues caused by frivolous communication, which require additional resources and can lead to data transfer delays.

Innovation Solution

A method and apparatus for managing data transfers in a data network by identifying communication sessions, processing data packets, and applying criteria such as IP and TCP compliance, signature analysis, and bandwidth management to permit or restrict data transfers, using a gateway with a session identifier, controller, and signature analyzer to label and route packets accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If monitoring and controlling of data transfers is implemented to protect against malicious code and unauthorized access, then network security is improved, but network operation overhead increases and data transfer delays occur

Engineering Contradiction:
Improvenetwork securityVSAvoiddata transfer delays
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-classifying communication sessions into trusted and untrusted categories based on initial criteria (such as whether the session initiated from inside or outside the network). This pre-classification allows the system to prepare appropriate processing paths in advance, so that when actual data packets arrive, they can be routed efficiently without requiring comprehensive real-time analysis of every packet, thus maintaining security while reducing transfer delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the data transfer process into two distinct paths: a fast path for trusted sessions and a slow path for untrusted sessions. This segmentation allows most legitimate traffic to flow quickly through the optimized fast path while only suspicious traffic undergoes the more resource-intensive monitoring and controlling processes in the slow path, thereby resolving the contradiction between security and transfer speed.

Inventive Principle:
Principle #1Segmentation

2Reliability

If comprehensive monitoring and controlling of data transfers is implemented, then network security is improved, but additional computer resources are required

Engineering Contradiction:
Improvenetwork securityVSAvoidcomputer resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies partial action by implementing monitoring and controlling measures selectively rather than comprehensively. Instead of applying full security scrutiny to all data transfers, the system applies enhanced monitoring only to untrusted sessions (those that meet specific criteria), while trusted sessions receive minimal or no monitoring. This partial application of security measures maintains adequate network security while significantly reducing the computer resources required compared to comprehensive monitoring of all traffic.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If policy rules completely block access to certain applications, then network security is improved, but network functionality and productivity are reduced

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork functionality
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by implementing different levels of security control for different communication sessions based on their specific characteristics. Instead of applying a uniform blocking policy to all applications, the system identifies specific untrusted sessions (using local criteria such as origin location or protocol type) and applies monitoring and controlling measures only to those specific sessions. This localized approach maintains network security for problematic sessions while preserving full functionality and productivity for legitimate applications and sessions.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8166547B2Method, apparatus, signals, and medium for managing a transfer of data in a data network
Publication Date: 2012.04.24 FORTINET INC
  • US8166547B2 patent drawing
  • US8166547B2 patent drawing
  • US8166547B2 patent drawing

AI summary

A method and apparatus for managing a transfer of data in a data network identifies data associated with a communication session between a first node and a second node in the data network. Further processing of the communication session occurs when a portion of the communication session meets a criterion and the communication session is permitted to continue when the portion of the communication session does not meet the criterion.