Transparent Network Bridge for Bi-directional Security Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Individual users face challenges in affording and managing network security due to the complexity and cost of existing security solutions, which often require multiple, conflicting software applications for different security threats, lacking comprehensive and affordable protection.

Innovation Solution

A method and system for transparent bridging and bi-directional management of network data, utilizing a security device that detects and decodes network activity, establishes a transparent networking bridge between local and wide area networks, and evaluates TCP SYN packets to determine necessary security measures, integrating with a three-layer protection architecture for comprehensive security services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple separate client security applications are installed on each PC to protect against different security threats, then comprehensive security coverage is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsoftware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network-based security server as an intermediary that centralizes security management. Instead of installing multiple security applications on each client PC, a single lightweight client connects to the security server which handles threat detection, analysis, and response. This mediator approach consolidates complex security functions on the server while keeping client software simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security server provides universal security protection against multiple threat types (viruses, worms, spyware, hackers) through a single platform. The server performs multiple security functions including threat detection, classification, filtering, and remediation, replacing the need for separate specialized security applications on each client device.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple separate client security applications are installed on each PC, then comprehensive security coverage is improved, but cost increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsoftware resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges multiple security functions and resources into a single centralized security server. Instead of each client PC running separate security applications, the system combines virus scanning, firewall management, intrusion detection, and other security services on one server that serves multiple clients, reducing overall software resource consumption.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security server provides self-service capabilities by automatically detecting, classifying, and responding to security threats without requiring individual client software to perform complex analysis. The server autonomously manages security policies, updates threat databases, and coordinates responses across the network.

Inventive Principle:
Principle #25Self-service

3Reliability

If extensive-client security technology is installed on each PC, then security protection is improved, but ease of operation deteriorates due to conflicting applications

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security server acts as an intermediary that manages all security operations centrally, eliminating the need for users to configure and manage multiple conflicting security applications on their PCs. The lightweight client software requires minimal user interaction while the server handles complex security decisions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent inverts the traditional security model by moving complex security processing from the client side to the server side. Instead of each PC running extensive security software that conflicts with other applications, the client runs minimal software that communicates with the central security server which performs the heavy lifting.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS7716472B2Method and system for transparent bridging and bi-directional management of network data
Publication Date: 2010.05.11 GEN DIGITAL INC
  • US7716472B2 patent drawing
  • US7716472B2 patent drawing
  • US7716472B2 patent drawing

AI summary

A network-communication method includes detecting network activity between a local area network and a wide area network, decoding the network activity, responsive to the decoding step, obtaining at least a source network address, and using the source network address to establish a transparent networking bridge between the local area network and the wide area network.