Network Security Appliance Injecting Sensitive Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for managing sensitive data, such as usernames and passwords, are vulnerable to attacks from malware and keyloggers since the data must be stored or input on local computers before transmission to remote servers, exposing it to security risks.

Innovation Solution

A network security appliance intercepts outgoing traffic, stores sensitive data, and injects it into the traffic flow on behalf of the user, ensuring it is not present on the local device, thereby maintaining security and transparency to the remote server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If sensitive data is stored or input on local computers before transmission to remote servers, then the data can be accessed and submitted to servers, but the data becomes vulnerable to malware and keylogger attacks

Engineering Contradiction:
Improvedata securityVSAvoidmalware access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive data from the local computer environment and stores it remotely on secure servers. The data is only temporarily cached in memory during transmission, never written to disk. This removes the data from the vulnerable local storage environment where malware and keyloggers operate, while still enabling access and submission to remote servers.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a secure data management system as an intermediary between the user's local computer and remote servers. This intermediary handles data storage, retrieval, and transmission securely, preventing direct exposure of sensitive data to the local computer environment where malware threats exist. The intermediary uses encrypted communication and temporary memory storage to protect data during the transmission process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If password management software is installed on local computers to manage usernames and passwords, then password management is facilitated, but sensitive data remains vulnerable to keyloggers and injected code

Engineering Contradiction:
Improvepassword managementVSAvoidkeylogger attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Instead of storing passwords locally on the computer (traditional approach), the patent inverts the storage location by keeping passwords remotely on secure servers and only temporarily caching them in memory during transmission. This inversion removes passwords from the vulnerable local environment where keyloggers and injected code operate, while still providing automatic fill functionality through the secure data management system.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent moves password management from the traditional two-dimensional local storage model to a three-dimensional architecture involving local temporary caching, secure remote storage, and encrypted transmission channels. This dimensional change allows passwords to be managed conveniently while being protected from local threats by relocating the primary storage to a secure remote dimension.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If sensitive data is transmitted from local clients to remote servers through computer networks, then online services can be accessed, but security risks increase due to data presence on local computers

Engineering Contradiction:
Improveonline service accessVSAvoidsecurity protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent performs preliminary secure storage of sensitive data on remote servers before transmission is needed. When online services require data submission, the system retrieves data temporarily and transmits it through encrypted channels. This preliminary remote storage arrangement enables online service access while maintaining security, as data never resides permanently on vulnerable local computers.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the storage parameter from permanent local disk storage to temporary in-memory caching with remote server storage. This parameter change reduces the security risk by eliminating persistent local data storage, while still enabling online service access through temporary data availability during transmission windows. The data existence duration and location parameters are optimized for both security and functionality.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10382525B2Managing transmission and storage of sensitive data
Publication Date: 2019.08.13 FORTINET INC
  • US10382525B2 patent drawing
  • US10382525B2 patent drawing
  • US10382525B2 patent drawing

AI summary

Systems and methods for injecting sensitive data into outgoing traffic on behalf of a user of a private network are provided. According to one embodiment, a network security appliance maintains a database of sensitive data. Secure submission of sensitive data of a user is facilitated by the security appliance in connection with interactions between a client and a server by: (i) intercepting outgoing traffic from the client to the server; (ii) determining whether the outgoing traffic matches a policy configured by an administrator of the private network that causes the sensitive data to be injected into the outgoing traffic by the network security device on behalf of the user; and (iii) when the determining is affirmative: (a) retrieving the sensitive data from the database; (b) modifying the outgoing traffic by injecting the sensitive data into the outgoing traffic; and (c) sending the modified outgoing traffic to the server.