Private Network Request Forwarding for Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing public network infrastructure is vulnerable to disruptions and attacks, such as denial of service, which can expose content providers and delivery entities to financial and physical damages by allowing illegitimate requests to reach servers directly.

Innovation Solution

Implementing a system where requests from public networks are analyzed for legitimacy, with a multi-layered risk evaluation process that includes authentication and additional handling for high-risk requests, and forwarding legitimate requests through a private network to limit user access and protect content providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If requests are allowed to reach servers directly through public networks, then service accessibility and response speed are improved, but security vulnerabilities and service disruption risks increase

Engineering Contradiction:
Improveservice response speedVSAvoidservice disruption risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a private network as an intermediary layer between public networks and servers. Delivery nodes route requests through this private network infrastructure, which acts as a mediator that filters and validates traffic before reaching the server. This resolves the contradiction by maintaining fast public network access while protecting against direct exposure to attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the network infrastructure into distinct public and private network layers. The public network handles incoming requests while the private network handles validated traffic to servers. This segmentation allows the system to maintain high-speed public access while isolating servers from direct public network threats.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a private network is introduced to filter and forward requests, then security and service stability are improved, but network complexity and latency increase

Engineering Contradiction:
Improveservice stabilityVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Delivery nodes are designed to perform multiple functions: receiving requests from public networks, evaluating risk levels, authenticating users, and forwarding legitimate requests through private networks. This multi-functionality reduces the need for separate specialized components, thereby managing complexity while maintaining reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary risk evaluation and authentication of requests before they are forwarded through the private network. By pre-validating traffic at delivery nodes, the system ensures that only legitimate requests enter the private network, maintaining service stability without requiring complex continuous monitoring throughout the entire network.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If risk evaluation and authentication are performed for each request, then security is improved, but processing time and system overhead increase

Engineering Contradiction:
Improveillegitimate request filteringVSAvoidrequest processing time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The system dynamically changes the evaluation parameters based on risk levels. Low-risk requests from authenticated users undergo minimal processing, while high-risk requests trigger more stringent evaluation. This parameter adaptation allows the system to maintain strong security filtering while minimizing processing time for legitimate traffic.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system applies partial authentication and risk evaluation to requests based on their assessed risk level. Not every request undergoes the complete authentication sequence - only those that trigger risk thresholds do. This selective approach filters illegitimate requests effectively while avoiding unnecessary processing overhead for legitimate traffic.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11368433B1Private network request forwarding
Publication Date: 2022.06.21 UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
  • US11368433B1 patent drawing
  • US11368433B1 patent drawing
  • US11368433B1 patent drawing

AI summary

Private network request forwarding can include receiving a request from a user for Internet services over a public network. Private network request forwarding can include analyzing the request and determining whether the request is legitimate. Private network request forwarding can include forwarding the request to an entity through a private network when it is determined that the request is legitimate, wherein the user has access to the entity through a proxy.