Smart Bits Data Routing via Classification Proxy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computing networks lack the ability to distinguish between different data types being transmitted, leading to inefficient routing that increases latency and costs due to the need for multiple security and inspection pathways for data packets containing various types of data.

Innovation Solution

Implementing a dynamic routing system with a proxy on client devices that scans and classifies data streams, routing them based on applicable policies and security protocols, utilizing libraries for data classification and re-routing sensitive or high-risk data to appropriate infrastructure or honeypot networks for additional authentication and protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data packets are routed through multiple security and inspection pathways to ensure comprehensive security coverage, then security reliability is improved, but network latency increases and operational costs increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidnetwork latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments data packets into different categories based on sensitivity levels (e.g., PII, PCI, PHI) and routes each segment through appropriate security pathways. Sensitive data types are routed through specialized inspection systems while less sensitive data uses standard routing, eliminating the need for all packets to traverse every security checkpoint.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different security inspection qualities are applied to different data types based on their sensitivity. High-sensitivity data receives comprehensive multi-layer inspection, while lower-sensitivity data receives streamlined inspection. This local differentiation of security quality reduces overall latency while maintaining appropriate security standards for each data category.

Inventive Principle:
Principle #3Local quality

2Reliability

If all data streams are transmitted through multiple security and inspection infrastructure components, then security coverage is improved, but infrastructure costs increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidoperational costs
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent divides data traffic into segments based on sensitivity classification and directs each segment through cost-appropriate security infrastructure. This segmentation allows the organization to pay for comprehensive security inspection only for sensitive data types while using more economical routing for less sensitive data, reducing overall operational costs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the security inspection parameter (level of scrutiny) based on data sensitivity classification. By adjusting the inspection depth and type of security measures applied to different data categories, the system optimizes the balance between security coverage and infrastructure costs, avoiding unnecessary expenditure on inspecting all data with the same high level of security measures.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If centralized systems route all data packets without distinguishing data types, then system complexity is reduced, but security effectiveness deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoidsecurity effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent performs preliminary classification of data packets at the source before routing decisions are made. By pre-tagging data with sensitivity information and classification metadata, the system enables automated routing without requiring complex real-time analysis at each routing decision point, thus maintaining manageable system complexity while achieving effective security differentiation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary classification layer that sits between the data source and the routing infrastructure. This intermediary component analyzes data content, assigns sensitivity labels, and directs packets to appropriate security pathways. This intermediary approach maintains relative system simplicity by centralizing the classification logic while enabling sophisticated security routing without requiring complex modifications to the entire network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11611584B2Smart bits
Publication Date: 2023.03.21 CLOUDENTITY INC
  • US11611584B2 patent drawing
  • US11611584B2 patent drawing
  • US11611584B2 patent drawing

AI summary

Systems and methods for intelligent data routing based on data type are provided. A proxy installed on a client device receives a data stream and scans the data stream for classification parameters associated with sensitive data. A data stream may be broken down, for example, to data packets, classified using known libraries containing characteristics of a classification, and routed based on applicable policies governing each classification. The routed data packets are constantly monitored and may be re-routed to a network designed to handle highly sensitive data, a network designed to handle data with high security risk, or to another applicable service infrastructure as needed, before reaching the intended recipient. The classification libraries may be updated based on the monitored data and change in classification of the data packet.