Packet Security Gateway Segmentation for Proactive Network Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network protection systems are reactive rather than proactive, and scalable proactive solutions are untenable due to the need for high-resolution filtering of enormous network traffic, which is infeasible in large networks.

Innovation Solution

Implementing a system with packet security gateways configured in series, each receiving dynamic security policies from a management server to perform packet transformation functions, including filtering, forwarding, and dropping packets based on rules that can handle large volumes of network traffic efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If high-resolution filtering is implemented to provide proactive network protection, then security reliability is improved, but processing time increases making the solution infeasible for large networks

Engineering Contradiction:
Improvenetwork securityVSAvoidpacket processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent divides the network protection system into multiple distributed packet security gateways that operate independently in parallel. Each gateway handles a portion of the network traffic, allowing high-resolution filtering to be applied without requiring a single centralized system to process all traffic sequentially. This segmentation enables proactive security measures while maintaining feasible processing times across large networks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by pre-configuring security policies and rules at each packet security gateway before traffic arrives. The gateways are pre-positioned throughout the network infrastructure, enabling immediate proactive filtering without requiring real-time decision-making that would increase processing delays.

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If reactive approaches are used to identify attack sources, then system complexity is reduced, but security effectiveness deteriorates because attacks have already succeeded

Engineering Contradiction:
Improvesystem complexityVSAvoidsecurity effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the network into multiple zones with distributed packet security gateways positioned at strategic locations. This segmentation enables the system to maintain relatively simple individual gateway configurations while achieving comprehensive proactive security coverage across the entire network, preventing attacks before they can succeed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces packet security gateways as intermediary devices between untrusted external networks and protected internal networks. These gateways act as mediators that enforce security policies and filter malicious traffic before it can reach critical internal systems, providing effective security without requiring complex changes to existing network infrastructure or applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If packet security gateways perform multiple transformation functions on packets, then security capability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity capabilityVSAvoidgateway complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs packet security gateways as universal multi-functional devices capable of performing various packet transformation functions including filtering, forwarding, dropping, and modifying packets based on security policies. Each gateway is configured to handle multiple security functions simultaneously, reducing the need for separate specialized devices and managing complexity through standardized multi-purpose components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements dynamic security policies that can be updated and reconfigured at each packet security gateway without requiring hardware changes. The gateways can dynamically adjust their transformation functions based on changing threat landscapes and network conditions, providing enhanced security capability while managing complexity through software-based flexibility rather than fixed complex hardware architectures.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3955519B1Methods and systems for protecting a secured network
Publication Date: 2025.09.17 CENTRIPETAL NETWORKS INC
  • EP3955519B1 patent drawingFigure 1
  • EP3955519B1 patent drawingFigure 2
  • EP3955519B1 patent drawingFigure 3

AI summary

Methods and systems for protecting a secured network are presented. For example, one or more packet security gateways may be associated with a security policy management server. At each packet security gateway, a dynamic security policy may be received from the security policy management server, packets associated with a network protected by the packet security gateway may be received, and at least one of multiple packet transformation functions specified by the dynamic security policy may be performed on the packets. Performing the at least one of multiple packet transformation functions specified by the dynamic security policy on the packets may include performing at least one packet transformation function other than forwarding or dropping the packets.