Router Security Validation and Endpoint Load Balancing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number of Internet of Things (IoT) devices in home networks with weak or no security measures poses a significant security threat, as they are vulnerable to malware and network attacks, and existing endpoint security solutions are not scalable or robust enough to protect all devices within a personal network.

Innovation Solution

A router-level computer security component validates and registers endpoint security components across multiple devices, ensuring they have a consistent anti-malware scanning engine and signature set, and then load balances security processing based on device capabilities to provide robust protection, including for IoT devices lacking endpoint security software.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If endpoint security applications are installed on each device, then security protection is provided for individual devices, but the security system is not scalable and cannot protect IoT devices with limited resources

Engineering Contradiction:
Improvesecurity protectionVSAvoidscalability to IoT devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent merges security processing capabilities from multiple endpoint devices into a centralized security system. The router aggregates security resources from protected endpoints to create a collective security service that can protect all devices including IoT devices, eliminating the need for each device to have independent security software.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The centralized security system provides universal protection across diverse device types. By creating a security service that operates at the network level rather than device level, the system can protect traditional devices, IoT devices with limited resources, and other endpoints uniformly, regardless of their individual capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If security processing is centralized on the router, then protection can be provided for all devices including IoT devices, but the router must validate and manage multiple endpoint security components

Engineering Contradiction:
Improveability to protect all device typesVSAvoidvalidation and management of security components
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The router implements a validation mechanism that receives feedback from endpoint devices about their security component status. The router sends validation requests to endpoints and processes their responses to determine whether to include them in the security service, creating a feedback loop that manages complexity automatically.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Endpoint devices perform self-validation by responding to router requests with information about their security component status. The devices autonomously provide necessary information about their anti-malware engines and signature versions, reducing the burden on the router to manually assess each device.

Inventive Principle:
Principle #25Self-service

3Reliability

If the router validates each endpoint's security components, then the security service can be reliably provided, but the validation process requires transmitting code samples and verifying detection results

Engineering Contradiction:
Improvevalidation of security componentsVSAvoidvalidation processing time
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The router performs validation actions in advance before deploying the security service. By pre-validating endpoint security components and determining their reliability beforehand, the system avoids time-consuming validation processes during active security operations, improving overall productivity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The router transmits code samples to endpoints for validation, creating temporary copies of security-relevant data. These copied code samples are used to test endpoint detection capabilities without affecting the actual security state of the network, enabling efficient validation.

Inventive Principle:
Principle #26Copying

4Productivity

If security resources are distributed across multiple endpoints, then the security system can leverage varied hardware and computing resources, but the ability to provide robust and scalable security services is limited

Engineering Contradiction:
Improveutilization of computing resourcesVSAvoidrobustness of security services
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the security system into endpoint-level components (anti-malware engines, signature databases) and a centralized coordination layer on the router. This segmentation allows individual endpoints to contribute their resources while the router aggregates and orchestrates them into a unified, robust security service with centralized control.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10122737B1Local area network ecosystem of verified computer security resources
Publication Date: 2018.11.06 GEN DIGITAL INC
  • US10122737B1 patent drawing
  • US10122737B1 patent drawing
  • US10122737B1 patent drawing

AI summary

A router-level computer security component validates multiple endpoint computer security components on multiple endpoint devices in a local area network, based on whether given endpoints each have a specific anti-malware scanning engine and set of signatures used by the router-level component. To validate a given endpoint, the router-level component transmits a code sample which will trigger scanning by the specific anti-malware scanning engine in conjunction with a specific signature of the set, resulting in a specific detection result. In response to receiving the specific, expected detection result in return, the router-component validates the endpoint. The router-level component monitors incoming traffic in the local area network, and load balances security processing of the network traffic of each incoming data stream, based on the security capabilities of the corresponding target endpoint, and the security capabilities and available computational bandwidth of the multiple validated endpoint components and the router-level component.