Redisplay Computing Data Filtering Pipeline

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Remote access technologies lack the ability to provide inline, integrated inspection, validation, and transformation of data streams, failing to prevent unauthorized and malicious data infiltration or exfiltration, with security measures primarily applied to network transport rather than the content itself.

Innovation Solution

A method and system for secure remote network access that integrates data filtering and processing within a redisplay mechanism, utilizing a data processing pipeline with validation, transformation, and auditing modules to inspect, verify, and transform data streams, preventing unauthorized data transfer and providing a secure infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If remote access technology is used to provide network access to computing applications, then user accessibility and ease of use are improved, but the ability to inspect, validate, and transform data streams is lost

Engineering Contradiction:
Improveuser accessibilityVSAvoiddata stream security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a data processing pipeline as an intermediary component between the remote access system and the data streams. This pipeline includes filtering modules that inspect, validate, and transform data before it reaches the computing applications, thereby maintaining both user accessibility and data security without compromising the remote access functionality

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security measures are applied around network transport, then data transmission protection is improved, but the ability to prevent unauthorized data infiltration and exfiltration is worsened

Engineering Contradiction:
Improvedata transmission protectionVSAvoidunauthorized data infiltration
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the security function into multiple independent filtering modules within the data processing pipeline. Each module can inspect specific aspects of data streams (e.g., content validation, format verification, transformation) separately, allowing comprehensive security coverage without creating a single point of failure or overwhelming the system

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If integrated data filtering is implemented within the redisplay mechanism, then unauthorized data transfer prevention is improved, but device complexity increases

Engineering Contradiction:
Improveunauthorized data transferVSAvoidsystem structure
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements multi-functional filtering modules that can perform multiple operations (inspection, validation, transformation) within a single integrated pipeline. This universal approach allows the system to handle various security threats and data processing tasks through a unified structure, reducing overall system complexity compared to multiple separate security systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11297099B2Redisplay computing with integrated data filtering
Publication Date: 2022.04.05 FORCEPOINT LLC
  • US11297099B2 patent drawing
  • US11297099B2 patent drawing
  • US11297099B2 patent drawing

AI summary

A method, system and computer-usable medium for redisplaying data at a remote access client system from a secure computing environment. The redisplaying data includes receiving a request form the remote access client system for data, inspecting the request for potential unauthorized or malicious retransmission. Modifying the data, by filtering audio data or transforming graphical data prior to sending the requested data is performed to prevent the unauthorized or malicious retransmission.