Secure Remote Worker Hypervisor for Selective Traffic Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions for remote workers to securely connect to corporate networks from personal devices are limited, as they often rely on unsecured home Wi-Fi networks and can overload remote access systems, while also lacking centralized management and malware inspection capabilities.
Innovation Solution
A secure remote worker (SRW) application executes in a hypervisor of a personal computing device to analyze network data traffic, perform security analyses, and route data securely without the need for a VPN or traditional SDWAN solution, while being remotely monitored and managed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If VPN software is installed to create a secure tunnel, then network security is improved, but the remote access system becomes overloaded due to all data being communicated through it
Solution Approach 1:
The patent segments network traffic into different categories (work-related vs. non-work-related) and routes them through different paths. Work-related traffic is routed through the remote access system for security, while non-work traffic is routed directly to the internet, preventing the remote access system from being overloaded by all data.
Solution Approach 2:
The patent applies different security policies and routing rules to different types of traffic based on their destination and purpose. Corporate applications and work-related websites receive full security inspection, while other traffic receives minimal handling, optimizing the balance between security and system performance.
2Reliability
If VPN is used to secure data transmission, then data security is improved, but malware inspection and security analysis capabilities are lost
Solution Approach 1:
The patent performs preliminary security analysis and malware inspection on work-related traffic before it is routed to the remote access system. This includes inspecting URLs, analyzing application behavior, and checking for malicious content in advance, so that only verified safe traffic is allowed through the secure tunnel.
Solution Approach 2:
The patent introduces an intermediary security appliance that sits between the user device and the remote access system. This intermediary performs deep packet inspection, malware analysis, and security filtering, providing both security inspection capabilities and secure access without requiring the remote access system to handle all security functions.
3Ease of operation
If SDWAN solution is implemented for secure remote access, then network management is improved, but device complexity and cost increase due to requiring separate hardware
Solution Approach 1:
The patent makes the user's existing personal computing device perform multiple functions: it acts as both the work device and the SDWAN edge device. By installing virtualization software and security appliances on the existing device, it provides routing, security, and network management capabilities without requiring separate dedicated hardware.
Solution Approach 2:
The patent enables the user's personal device to self-configure and self-manage network functions. The device automatically routes traffic, manages security policies, and provides remote access capabilities without requiring additional specialized hardware or complex manual configuration of separate devices.
4Reliability
If all data traffic is routed through the remote access system, then security monitoring is improved, but system overload and performance degradation occur
Solution Approach 1:
The patent segments traffic into work-related and non-work-related categories, applying different routing policies. Only work-related traffic requiring security monitoring is routed through the remote access system, while other traffic is routed directly, maintaining security monitoring for critical traffic without overloading the system.
Solution Approach 2:
The patent applies partial routing through the remote access system rather than routing all traffic. It selectively routes only the necessary work-related traffic through the secure channel while allowing other traffic to bypass the system, providing adequate security monitoring without excessive system load.
Data Source
AI summary
A secure remote worker (SRW) application that executes in a hypervisor of a user's personal computing device to analyze data and determine if the data is destined for a corporate remote access system or other location. The SRW may perform a security analysis of the data to determine if the data itself or a location associated with the data is known malware. The SRW may be remotely managed to enable and configured.


