End-to-End TCP Traffic Scanning During Application Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

During data migration between computing devices, there is a risk of inappropriate actions by bad actors due to insufficient security measures, particularly at the Transmission Control Protocol (TCP) layer, which can lead to vulnerabilities such as distributed denial-of-service (DDoS) attacks.

Innovation Solution

Implementing a method that includes initiating an application migration operation with a secure data path establishment using coordinated universal time (UTC)-based system time, generating and encrypting a secure string, and appending it to migration notifications, along with active scanning to detect and reject suspicious network traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data migration is performed between computing devices, then data transfer capability is improved, but security vulnerabilities increase due to insufficient security measures at the TCP layer

Engineering Contradiction:
Improvedata transfer capabilityVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary security actions by establishing a secure data path before actual data migration begins. This includes pre-migration security assessments, establishing encrypted communication channels, and configuring security policies in advance to prevent vulnerabilities during the migration process

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security layer between the source and target computing devices during data migration. This intermediary mechanism validates and secures TCP-level communications, acting as a mediator that enhances security without blocking legitimate data transfer operations

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If active scanning is performed to detect suspicious traffic, then security detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service security scanning where the migration system automatically performs active scans to detect suspicious traffic patterns. The system serves its own security needs by integrating scanning capabilities directly into the migration workflow, eliminating the need for separate complex security infrastructure

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a multi-functional security scanning mechanism that handles multiple detection tasks simultaneously. The active scanning system detects various types of suspicious traffic including DDoS attacks, data exfiltration attempts, and unauthorized access patterns using a unified scanning framework that reduces overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If encrypted secure strings are generated and appended to migration notifications, then data security is improved, but processing time increases

Engineering Contradiction:
Improvedata securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary generation and encryption of secure strings before the actual data migration process begins. By preparing these security credentials in advance and caching them for the duration of the migration operation, the system minimizes processing time overhead during the critical data transfer phase

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent optimizes the encryption parameters and secure string generation algorithms to reduce processing time. By adjusting encryption key lengths, algorithm selections, and caching strategies, the system achieves an optimal balance between enhanced data security and acceptable processing time requirements

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12363162B2End-to-end TCP monitoring during application migration
Publication Date: 2025.07.15 DELL PROD LP
  • US12363162B2 patent drawing
  • US12363162B2 patent drawing
  • US12363162B2 patent drawing

AI summary

A method for performing an application migration operation includes initiating the application migration operation to migrate an application from a source device to a target device, where the source device includes a source data migration agent and the target device comprises a target data migration agent. The method also includes initiating an active scan of network traffic at a transmission control protocol layer. The method further includes establishing a secure data path between the source device and the target device. In addition, the method includes beginning migration of the application from the source device to the target device using the secure data path. Moreover, the method includes making a first determination, using the active scan, that a data packet is associated with suspicious activity and rejecting the data packet based on the first determination.