Secure Application Delivery via Dynamic Path Pooling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional multi-layer security infrastructures for hosted applications pose challenges in configuration and management, often resulting in a tradeoff between security level and operational expertise, leading to suboptimal user experiences and increased operational and capital expenditures, especially in hybrid environments with applications deployed across multiple locations.

Innovation Solution

A dynamically scalable secure application delivery system that includes a frontend traffic delivery layer, backend traffic delivery layer, and traffic processing layer, with an application agent creating a pool of communication paths to validate user requests and ensure secure access to hosted applications, while dynamically adjusting resources based on demand and performance metrics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a traditional multi-layer security infrastructure is deployed to protect hosted applications, then security level is improved, but device complexity and ease of operation deteriorate due to configuration and management challenges

Engineering Contradiction:
Improvesecurity levelVSAvoidconfiguration and management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an application delivery controller as an intermediary component that manages security policies and traffic flow between users and hosted applications. This controller abstracts the complex multi-layer security infrastructure into a single point of management, reducing configuration and management complexity while maintaining high security levels through centralized policy enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The application delivery controller performs multiple functions including security validation, load balancing, and application delivery management within a single system. This multi-functional approach consolidates what would otherwise require separate security appliances and management systems, reducing overall device complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple security features are deployed to enhance security, then security level is improved, but operational expertise requirements increase

Engineering Contradiction:
Improvesecurity levelVSAvoidoperational expertise required
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service security validation by automatically verifying user credentials and device compliance against security policies without requiring manual intervention from security administrators. The application delivery controller autonomously makes access decisions based on pre-configured policies, reducing the operational expertise needed for day-to-day security management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The application delivery controller acts as an intermediary that automates security policy enforcement and validation processes. It handles complex security checks including authentication, authorization, and device compliance verification automatically, eliminating the need for operators to manually manage multiple security features and reducing expertise requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If applications are housed in a single location to simplify security, then device complexity is reduced, but adaptability deteriorates due to business requirements for multiple locations

Engineering Contradiction:
Improvesecurity infrastructure complexityVSAvoidmulti-location deployment flexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The application delivery controller provides a universal platform that can be deployed in single or multi-location environments while maintaining consistent security management. It handles application delivery and security validation regardless of physical location, enabling enterprises to house applications in multiple locations (data centers, cloud, edge) without increasing security infrastructure complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent shifts the security management model from a physical location-based approach to a logical, policy-based approach. Instead of managing security at each physical location, the system implements centralized security policies that apply across all locations, transforming security management from a spatial dimension to a logical dimension and enabling flexible multi-location deployment.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Device complexity

If a port of entry approach is used to route traffic through a single location, then security management is simplified, but speed deteriorates due to increased end-to-end round-trip times

Engineering Contradiction:
Improvesecurity management complexityVSAvoidend-to-end round-trip time
Core Design Contradiction:
Device complexityVSSpeed

Solution Approach 1:

The system performs security validation and authentication in advance before application traffic needs to flow. User credentials and device compliance are verified beforehand, and security contexts are cached, allowing subsequent traffic to flow directly without repeated validation delays. This preliminary security check reduces end-to-end round-trip time while maintaining simplified security management.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent separates security validation functions from application traffic flow. Security checks are performed in a distinct phase before traffic routing, allowing traffic to flow through optimized paths once validated. This segmentation enables security management to be simplified without forcing all traffic through single bottleneck locations, thereby reducing end-to-end latency.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10554622B2Secure application delivery system with dial out and associated method
Publication Date: 2020.02.04 AKAMAI TECHNOLOGIES INC
  • US10554622B2 patent drawing
  • US10554622B2 patent drawing
  • US10554622B2 patent drawing

AI summary

A system is provided to deliver an application, hosted by a private application provider system, over a network to a user device, comprising: an application delivery system that includes a first network interface, a network security interface and a second network interface; wherein the network security interface is configured to determine whether a user or device request for access to an application is valid, and in response to determining that the user or device request for access to the first application is valid, to send the user or device request to the application agent.