Secure Remote Worker Hypervisor for Selective Traffic Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for remote workers to securely connect to corporate networks from personal devices are limited, as they often rely on unsecured home Wi-Fi networks and can overload remote access systems, while also lacking centralized management and malware inspection capabilities.

Innovation Solution

A secure remote worker (SRW) application executes in a hypervisor of a personal computing device to analyze network data traffic, perform security analyses, and route data securely without the need for a VPN or traditional SDWAN solution, while being remotely monitored and managed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VPN software is installed to create a secure tunnel, then network security is improved, but the remote access system becomes overloaded due to all data being communicated through it

Engineering Contradiction:
Improvenetwork securityVSAvoidremote access system performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments network traffic into different categories (work-related vs. non-work-related) and routes them through different paths. Work-related traffic is routed through the remote access system for security, while non-work traffic is routed directly to the internet, preventing the remote access system from being overloaded by all data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security policies and routing rules to different types of traffic based on their destination and purpose. Corporate applications and work-related websites receive full security inspection, while other traffic receives minimal handling, optimizing the balance between security and system performance.

Inventive Principle:
Principle #3Local quality

2Reliability

If VPN is used to secure data transmission, then data security is improved, but malware inspection and security analysis capabilities are lost

Engineering Contradiction:
Improvedata securityVSAvoidmalware protection
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary security analysis and malware inspection on work-related traffic before it is routed to the remote access system. This includes inspecting URLs, analyzing application behavior, and checking for malicious content in advance, so that only verified safe traffic is allowed through the secure tunnel.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security appliance that sits between the user device and the remote access system. This intermediary performs deep packet inspection, malware analysis, and security filtering, providing both security inspection capabilities and secure access without requiring the remote access system to handle all security functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If SDWAN solution is implemented for secure remote access, then network management is improved, but device complexity and cost increase due to requiring separate hardware

Engineering Contradiction:
Improvenetwork managementVSAvoidhardware requirements
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent makes the user's existing personal computing device perform multiple functions: it acts as both the work device and the SDWAN edge device. By installing virtualization software and security appliances on the existing device, it provides routing, security, and network management capabilities without requiring separate dedicated hardware.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent enables the user's personal device to self-configure and self-manage network functions. The device automatically routes traffic, manages security policies, and provides remote access capabilities without requiring additional specialized hardware or complex manual configuration of separate devices.

Inventive Principle:
Principle #25Self-service

4Reliability

If all data traffic is routed through the remote access system, then security monitoring is improved, but system overload and performance degradation occur

Engineering Contradiction:
Improvesecurity monitoringVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments traffic into work-related and non-work-related categories, applying different routing policies. Only work-related traffic requiring security monitoring is routed through the remote access system, while other traffic is routed directly, maintaining security monitoring for critical traffic without overloading the system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial routing through the remote access system rather than routing all traffic. It selectively routes only the necessary work-related traffic through the secure channel while allowing other traffic to bypass the system, providing adequate security monitoring without excessive system load.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12348530B2Secure remote worker device and management system
Publication Date: 2025.07.01 AMZETTA TECH LLC
  • US12348530B2 patent drawing
  • US12348530B2 patent drawing
  • US12348530B2 patent drawing

AI summary

A secure remote worker (SRW) application that executes in a hypervisor of a user's personal computing device to analyze data and determine if the data is destined for a corporate remote access system or other location. The SRW may perform a security analysis of the data to determine if the data itself or a location associated with the data is known malware. The SRW may be remotely managed to enable and configured.