On-Device Network Protection via Local Traffic Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Connected mobile devices are vulnerable to network-based attacks such as spyware, botnets, and phishing threats, with existing solutions often relying on remote servers that compromise privacy and network performance.

Innovation Solution

A local, on-device system that intercepts and analyzes all traffic across applications and web browsers, using URL filtering and rule-based policies to block malicious connections, while maintaining user data privacy and minimizing battery consumption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traffic is redirected to outer servers for analysis, then security inspection capability is improved, but network performance deteriorates and privacy is compromised

Engineering Contradiction:
Improvesecurity inspection capabilityVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Instead of redirecting traffic to external servers for analysis, the patent inverts the approach by bringing the security analysis capability directly to the device through a local security application. This local execution eliminates network redirection overhead, preserving network performance while maintaining security inspection capability through on-device URL filtering and rule/policy analysis.

Inventive Principle:
Principle #13The other way round (Inversion)

2Reliability

If traffic is redirected to outer servers for analysis, then security inspection capability is improved, but user privacy deteriorates

Engineering Contradiction:
Improvesecurity inspection capabilityVSAvoiduser privacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent inverts the traditional client-server security model by placing the security analysis function locally on the user's device. This ensures that user traffic data never leaves the device, maintaining privacy while still enabling comprehensive security inspection through local URL filtering and rule/policy evaluation.

Inventive Principle:
Principle #13The other way round (Inversion)

3Reliability

If comprehensive traffic inspection is performed locally, then security protection is improved, but device battery consumption increases

Engineering Contradiction:
Improvesecurity protectionVSAvoiddevice battery consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the essential security analysis functions (URL filtering and rule/policy analysis) to run locally, rather than implementing comprehensive deep packet inspection. This selective approach provides adequate security protection while minimizing the computational overhead and battery consumption on the mobile device.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If comprehensive traffic inspection is performed locally, then security protection is improved, but network performance deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts and implements only the most efficient security checking mechanisms (URL filtering and rule/policy analysis) that can be performed with minimal impact on network traffic flow. This avoids the performance degradation associated with more intensive inspection methods while maintaining effective security protection.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10911487B2On-device network protection
Publication Date: 2021.02.02 CHECK POINT SOFTWARE TECH LTD
  • US10911487B2 patent drawing
  • US10911487B2 patent drawing
  • US10911487B2 patent drawing

AI summary

Methods performed by a system on a computer device, such as a smart phone, i.e., locally, for protecting against network-based attacks. These methods inspect all traffic to every application and web browser on the device.