Security Gateway for Context-Aware Network Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional network routing solutions lack the intelligence to control data access based on sensitivity and security context, leading to potential unauthorized access of sensitive data over public networks, and require additional costly infrastructure for monitoring and control.

Innovation Solution

An apparatus and method that integrate security context into network routing decisions by identifying the sensitivity level of data and security context of requests, applying policies to determine routing actions, and selecting secure router paths based on network information stored in a data store, which can block or encrypt data access as needed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional routers are used for network routing decisions, then device complexity is reduced and ease of operation is improved, but security control capability deteriorates as routers lack intelligence to control data access based on sensitivity and security context

Engineering Contradiction:
Improvesecurity control capabilityVSAvoidrouter intelligence
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a security gateway as an intermediary component between users and the network. This gateway analyzes security context, determines sensitivity levels of data, and makes routing decisions based on security policies. By placing this intelligent intermediary in the network path, security control capability is enhanced without requiring existing routers to become complex, as the gateway handles the intelligence functions while routers continue their traditional packet forwarding roles.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security agents are deployed on user devices to prevent unauthorized access, then security control capability is improved, but device complexity increases and not all user devices can run security agents

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidsecurity agent deployment
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of requiring security agents on every user device, the patent uses a security gateway as a centralized intermediary that performs security analysis. The gateway intercepts and analyzes requests, determines security context and data sensitivity, and enforces access control policies. This approach provides unauthorized access prevention without requiring complex security agents on user devices, making the solution accessible to all devices regardless of their capability to run additional software.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If additional servers and network devices are deployed for monitoring and controlling data access, then security control capability is improved, but operational cost increases

Engineering Contradiction:
Improvedata access controlVSAvoidoperational cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent designs the security gateway to perform multiple functions: security context analysis, sensitivity level determination, policy evaluation, and routing decision-making. By consolidating these functions into a single multi-functional gateway rather than deploying separate dedicated servers for each function, the solution achieves comprehensive data access control while minimizing the number of additional infrastructure components required, thereby reducing operational costs compared to traditional multi-component architectures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2982091B1Method and apparatus for integrating security context in network routing decisions
Publication Date: 2019.11.27 CA TECH INC
  • EP2982091B1 patent drawingFigure 1
  • EP2982091B1 patent drawingFigure 2
  • EP2982091B1 patent drawingFigure 3

AI summary

An apparatus identifies a request from a user device to access data on a storage server. The apparatus determines a sensitivity level of response data for a response to the request, security context of the response, and a routing action to perform for the response by applying a policy to the sensitivity level of the response data and the security context of the response. The apparatus executes the routing action for the response.