Decentralized Web Filtering via User Device Smart Agents

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional centralized proxy server systems for web filtering face challenges such as complexity in management, security vulnerabilities, and latency, especially with the increasing use of encrypted communications, which hinder effective access management and user experience.

Innovation Solution

Implementing web-filtering operations on user devices using smart agents that configure and manage local proxies, issuing trust certificates, and providing proxy access configuration, thereby eliminating the need for centralized decryption and reducing security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized proxy servers are used for web filtering, then web filtering capability is achieved, but system complexity and security vulnerabilities increase

Engineering Contradiction:
Improveweb filtering capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the centralized proxy server system into distributed components on individual user devices. Each device runs its own filtering software locally, segmenting the filtering function from the centralized architecture. This reduces system complexity by eliminating the need for centralized server management while maintaining filtering capability through distributed execution.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The filtering software on each user device performs self-configuration and self-management without requiring centralized proxy server intervention. The software automatically installs, configures itself, and executes filtering operations locally, enabling each device to serve its own filtering needs independently rather than relying on external centralized infrastructure.

Inventive Principle:
Principle #25Self-service

2Reliability

If centralized proxy servers are used for web filtering, then web filtering capability is achieved, but security vulnerabilities increase

Engineering Contradiction:
Improveweb filtering capabilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

By distributing filtering operations across multiple independent user devices rather than concentrating them on centralized proxy servers, the patent segments the security risk. A compromise on one device does not affect other devices or a centralized server that would expose all users' data, thereby reducing overall security vulnerabilities while maintaining filtering capability.

Inventive Principle:
Principle #1Segmentation

3Reliability

If all internet traffic is routed through centralized proxy servers, then web filtering is enabled, but latency increases

Engineering Contradiction:
Improveweb filtering capabilityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the filtering operation from the centralized proxy server architecture and places it directly on user devices. This removes the additional network hop and processing delay associated with routing all traffic through external proxy servers, reducing latency while maintaining filtering capability through local execution.

Inventive Principle:
Principle #2Taking out (Extraction)

4Adaptability or versatility

If proxy configuration and trust certificates are deployed to multiple devices, then web filtering is enabled across the organization, but IT management complexity increases

Engineering Contradiction:
Improveorganization-wide filtering coverageVSAvoidIT management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The filtering software automatically configures itself on each user device without requiring manual IT intervention for proxy settings or certificate installation. This self-configuration capability enables organization-wide filtering coverage while eliminating the repetitive manual deployment tasks that create IT management complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11711343B2User device-based enterprise web filtering
Publication Date: 2023.07.25 LIGHTSPEED SOLUTIONS LLC
  • US11711343B2 patent drawing
  • US11711343B2 patent drawing
  • US11711343B2 patent drawing

AI summary

Web-filtering operations may be implemented on the user device, rather than on a centralized proxy server, to improve reliability, performance, and/or security of the web-filtering operations. Some or all of the necessary functions related to web-filtering may be performed on the end user device to remove the complexity and security issues inherent with the current methodology. One technique for allowing operation of proxy servers on user devices is to install smart agents on the user device. The smart agents, under control of a management server, may configure the proxy server, issue trust certificates to applications on the device, and/or provide proxy access configuration (PAC) files to applications on the device.