Remote Security Gateway Rendering Web Content

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional anti-virus modules are ineffective against sophisticated hacks that evade protection by operating at low levels of computer architecture, and inline devices are vulnerable to denial-of-service attacks, while current malware protection methods rely on detection and signature-based systems that are not foolproof.

Innovation Solution

A remote security module that renders and recontainerizes incoming web page code into a secure, pixelated image format, eliminating malware by converting browser readable code into a secure browser readable code set, and periodically flipping virtual machines during normal network operations to prevent malicious activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional anti-virus software and malware scanners are used to protect computers, then basic malware detection capability is provided, but sophisticated hacks operating at low levels of computer architecture can evade detection

Engineering Contradiction:
Improvemalware protection effectivenessVSAvoidsophisticated hack evasion capability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a gateway device as an intermediary between the internet and the user's computer. This gateway intercepts and filters web traffic before it reaches the protected system, converting HTML code into rendered images. The intermediary approach allows security filtering to occur at network level rather than relying solely on endpoint anti-virus software, effectively blocking sophisticated malware that would otherwise evade traditional detection mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the web browsing function into two separate components: a gateway device that handles code rendering and filtering, and a protected computer that only receives rendered images. This segmentation isolates the vulnerable code-processing functions from the protected system, preventing malware from executing on the user's computer while maintaining browsing capability.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If robust browser software is used to handle many different types of data and executable code, then user experience is enriched, but the risk of malicious code infection increases

Engineering Contradiction:
Improvebrowser functionalityVSAvoidmalware infection risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The gateway device serves as an intermediary that handles all code processing and rendering operations. The robust browser functionality is maintained at the gateway level where malware risks are isolated, while the protected computer only receives rendered images without executable code. This preserves full browser adaptability while eliminating the infection risk on the user's system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the code-processing and rendering functions from the user's computer and relocates them to a separate gateway device. By taking out the vulnerable HTML parsing and code execution capabilities from the protected system, the invention maintains browser versatility at the gateway while preventing malware from reaching the user's computer.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If inline devices are used for malware filtering, then real-time protection is provided, but the devices are vulnerable to denial-of-service attacks

Engineering Contradiction:
Improvereal-time malware filteringVSAvoidresistance to denial-of-service attacks
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The gateway device acts as an inline intermediary that performs real-time rendering and filtering of web content. By positioning the gateway between the internet and the protected computer, it provides real-time malware filtering while isolating the protected system from denial-of-service attacks. The gateway absorbs attack impacts that would otherwise directly affect the user's computer availability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The gateway device provides beforehand cushioning by absorbing and mitigating denial-of-service attacks before they can reach the protected computer. The gateway's rendering and filtering functions serve as a buffer that protects the user's system from direct exposure to malicious traffic and resource exhaustion attacks.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

4Speed

If browser readable code is transmitted directly from server to user computer, then communication efficiency is maintained, but malware can be transmitted along with the code

Engineering Contradiction:
Improveweb communication speedVSAvoidmalware transmission
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The gateway device serves as an intermediary that receives HTML code from servers, renders it into images, and transmits only the rendered images to user computers. This intermediary process removes malware from the transmission stream while maintaining efficient communication by using standard web protocols and optimizing image delivery.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The gateway creates a copy of the web content in a safe format (rendered images) before transmitting it to the user's computer. Instead of transmitting the original HTML code that may contain malware, the system copies the visual representation of the content in an immutable image format that cannot execute malicious code, thereby preserving communication efficiency while eliminating malware transmission risks.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9118712B2Network communication system with improved security
Publication Date: 2015.08.25 TOUCHPOINT PROJECTION INNOVATIONS LLC
  • US9118712B2 patent drawing
  • US9118712B2 patent drawing
  • US9118712B2 patent drawing

AI summary

A computer network communication method and system wherein software rendering software is interposed in the data communication path between a browser running on a user computer and the internet data sources (for example, internet-accessible server computers) that the user browser wants to receive information from. The software rendering application gets data from internet data sources, but this data may contain malware. To provide enhanced security, the software rendering application renders this data to form a new browser readable code set (for example, an xml page with CSS layers), and this new and safe browser readable code set is sent along to the browser on the user computer for appropriate presentation to the user. As part of the rendering process, dedicated and distinct virtual machines may be used to render certain portion of the data, such as executable code. These virtual machines may be watched, and quickly destroyed if it is detected that they have encountered some type of malware.