Transparent Heartbeat Processing in Network Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Securing endpoints in heterogeneous enterprise networks is challenging due to the complexity and diversity of networked devices, which often leads to difficulties in bringing devices into compliance with network policies and managing secure communications across different vendors and configurations.

Innovation Solution

Implementing a threat management system that configures network devices to pass security information such as heartbeats and notifications between logical or physical network partitions, facilitating integrated endpoint management and secure communication across boundaries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network devices are configured to pass security information between network partitions, then integrated endpoint management is improved, but device complexity increases

Engineering Contradiction:
Improveintegrated endpoint managementVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces network devices (firewalls, gateways, routers) as intermediary components that transparently pass security information between network partitions. These intermediaries enable integrated endpoint management across boundaries without requiring complex configuration on endpoint devices themselves, as the network devices handle the security information forwarding automatically

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent makes network devices universal by enabling them to perform multiple functions: traditional network routing/forwarding plus transparent security information passing. By configuring existing network devices to handle both data traffic and security information (heartbeats, notifications, device ID) simultaneously, the system achieves integrated management without adding dedicated security appliances to each endpoint

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If security information is passed between logical or physical network partitions, then secure communication across boundaries is improved, but administrator resources increase

Engineering Contradiction:
Improvesecure communicationVSAvoidadministrator resources
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The patent implements self-service by enabling network devices to automatically pass security information between partitions without requiring administrator intervention for each transmission. Once configured, the network devices autonomously forward heartbeats, compromise notifications, and device identification information across partition boundaries, reducing ongoing administrative overhead while maintaining secure communication

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent establishes feedback loops where endpoints send security status information (heartbeats, compromise notifications) to network devices, which then automatically relay this information across partitions. This automated feedback mechanism ensures continuous secure communication monitoring without requiring administrators to manually check or relay security status between partitions

Inventive Principle:
Principle #23Feedback

3Difficulty of detecting and measuring

If network devices transparently process security information, then threat detection capability is improved, but information loss increases

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidinformation loss
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of information

Solution Approach 1:

The patent uses network devices as intermediaries that transparently process security information, allowing threat detection enhancement without information loss. The intermediaries forward complete security information (heartbeats, notifications, device ID) between partitions without filtering or modifying the data, enabling comprehensive threat detection while maintaining information integrity through transparent processing

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10862864B2Network device with transparent heartbeat processing
Publication Date: 2020.12.08 SOPHOS LTD
  • US10862864B2 patent drawing
  • US10862864B2 patent drawing
  • US10862864B2 patent drawing

AI summary

Network devices within an enterprise are configured to pass out-of-band security information such as heartbeats, notifications of compromise, device identification information, and so forth between logical or physical network partitions such as subnets, routing domains, access points, and so forth. This technique can advantageously facilitate integrated management of endpoints across network boundaries that might otherwise interfere with the identification and management of specific devices.