Remote Device Filtering System for Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems struggle to enforce corporate acceptable usage policies (AUP) for remote and mobile employees, as they lack the ability to effectively filter and monitor internet access outside the corporate network, leading to increased legal liabilities and reduced productivity.

Innovation Solution

A device resource access filtering system that uses a thin client on monitored devices to communicate with a remote server for real-time filtering and monitoring, allowing companies to manage internet usage, protect against malicious content, and enforce filtering policies even when devices are offline or on unfiltered ports, with adjustable sensitivity levels and reporting capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a server acts as a gateway to perform filtering operations on incoming and outgoing Internet traffic, then network security and policy enforcement are improved, but device complexity and processing requirements increase

Engineering Contradiction:
Improvenetwork securityVSAvoidserver complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the filtering functionality from the server gateway and implements it locally on individual devices through filtering software. This allows the server to maintain security policies without bearing the full processing burden, as devices perform preliminary filtering before traffic reaches the server gateway.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The filtering system is segmented into multiple components: local filtering software on devices, server-side policy management, and collaborative filtering mechanisms. This segmentation distributes the processing load and complexity across multiple points in the network architecture.

Inventive Principle:
Principle #1Segmentation

2Reliability

If remote devices perform their own filtering, then corporate-wide acceptable usage policy enforcement is improved, but device processing power requirements increase

Engineering Contradiction:
Improvepolicy enforcementVSAvoiddevice processing power
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent implements a universal filtering software solution that can run on various device types (desktops, laptops, mobile devices) with different processing capabilities. The software adapts its filtering intensity and methods based on device resources, providing consistent policy enforcement across diverse hardware platforms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The filtering system allows dynamic adjustment of filtering parameters such as sensitivity levels, processing intensity, and rule sets based on device capabilities. This enables the same filtering software to operate effectively on both high-power servers and low-power mobile devices by modifying its operational parameters.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If filtering sensitivity is increased to block more inappropriate content, then network security is improved, but legitimate resource access may be blocked

Engineering Contradiction:
Improvecontent filtering accuracyVSAvoidresource access efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic filtering that adjusts sensitivity and rule application based on context, user role, time of day, and resource type. This allows the system to maintain high security for critical resources while permitting broader access for routine operations, optimizing both security and productivity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Different filtering sensitivity levels and rule sets are applied to different users, departments, and resource types. This localized approach allows high-security filtering for sensitive corporate resources while using more permissive rules for public or less-critical resources, maintaining productivity while ensuring security.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS7890642B2Device internet resource access filtering system and method
Publication Date: 2011.02.15 FORCEPOINT LLC
  • US7890642B2 patent drawing
  • US7890642B2 patent drawing
  • US7890642B2 patent drawing

AI summary

A remote site filtering and monitoring system and method is described in which the Internet accesses of a remote device are monitored and categorized by a remote server in real-time. The system also provides for offline access logging and subsequent uploading, adjustable filtering sensitivities and particular HTTP port filtering.