Secure Networking Engine Using Local Protocol Server Forwarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional secure networking systems lack comprehensive computing logic and infrastructure to efficiently provide secure network communications that are SASE compatible, leading to computing-resource inefficiencies and security risks, particularly in cloud server-based implementations.

Innovation Solution

A local protocol server associated with a secure networking engine on a client device performs client-side forwarding operations, including IP assignment, OS routing, and destination network address translation to support secure network communications, intercepting and processing data traffic at the client level.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud server-based secure networking implementations are used, then centralized security management is achieved, but CPU computation and memory requirements increase significantly

Engineering Contradiction:
Improvesecurity managementVSAvoidCPU computation
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the secure networking functionality from the cloud server and implements it locally on the client device. The local protocol server performs IP assignment, OS routing, destination network address translation, and packet interception directly on the client, eliminating the need for resource-intensive cloud server processing while maintaining security management capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If cloud server-based secure networking implementations are used, then centralized security management is achieved, but memory requirements increase significantly

Engineering Contradiction:
Improvesecurity managementVSAvoidmemory requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts the secure networking functionality from the cloud server and implements it locally on the client device. The local protocol server performs IP assignment, OS routing, destination network address translation, and packet interception directly on the client, eliminating the need for resource-intensive cloud server processing while maintaining security management capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If conventional IP-based network processing is used, then basic network communication is achieved, but secure network communications functionality is insufficient

Engineering Contradiction:
Improvenetwork communicationVSAvoidsecurity functionality
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements a universal local protocol server that handles multiple functions including IP assignment, operating system routing, destination network address translation, packet interception, and secure communication processing. This multi-functional approach provides comprehensive secure network communications functionality while maintaining ease of operation through a unified local system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12381847B2Secure networking engine for a secure networking system
Publication Date: 2025.08.05 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12381847B2 patent drawing
  • US12381847B2 patent drawing
  • US12381847B2 patent drawing

AI summary

Methods, systems, and computer storage media for providing a local protocol server associated with a secure networking engine that provides client-side forwarding in a secure networking system. The local protocol server (e.g., local TCP/UDP server)—on a client device—operates based on client-side forwarding operations that include: IP assignment, operating system (OS) routing, destination network address translation, and original destination retrieval to support accessing a network resource (e.g., socket connection) on the client device and support communications between client applications on the client device and the local protocol server on the same client device. In this way, the local protocol server supports communications of a diverse set of data traffic or network traffic (e.g., different types of cross-platform communications), where the diverse set of network traffic is initially communicated from a client application and processed for network security operations at the local protocol sever of within the same client device.