Zero Trust Security Edge Devices Quality of Service

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Implementing proactive security architectures in modern computing environments is challenging due to the complexity of maintaining quality of service (QOS) and the dynamic nature of network configurations, leading to difficulties in fully realizing Zero Trust strategies and effectively securing against network-borne threats from within traditional security perimeters.

Innovation Solution

A system and method that utilize edge devices with communication management operations at the API command, device/network, and IP payload levels, enabling selective and reversible security measures through automated monitoring and provisioning, full authentication, and authorization of endpoints, to phase in proactive security architectures with minimal impact on QOS.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If proactive security architectures (Zero Trust) are implemented with complete system description and continual reconfiguring, then security reliability is improved, but device complexity and difficulty of operation increase significantly

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs self-identification and self-authentication through automated processes. Edge devices automatically generate and manage their own security credentials, and the system continuously monitors and reconfigures security parameters without requiring manual intervention, thereby maintaining high security reliability while reducing operational complexity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security credentials and authorization parameters are pre-established and cached before actual communication occurs. The system performs preliminary authentication and generates security configurations in advance, allowing rapid deployment of Zero Trust architecture without the need for complex real-time configuration management

Inventive Principle:
Principle #10Preliminary action

2Reliability

If complete authentication and authorization of all endpoints is performed, then security reliability is improved, but quality of service deteriorates due to processing overhead

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidquality of service
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies authentication and authorization selectively rather than uniformly to all communications. Low-risk, established connections receive minimal verification (partial action), while new or suspicious connections undergo full authentication. This differentiated approach maintains security reliability while reducing the overall processing overhead that would otherwise degrade quality of service

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

Authentication credentials and authorization decisions are pre-computed and cached before actual data transmission begins. The system performs authentication in advance and stores the results, allowing subsequent communications to proceed with minimal verification overhead, thereby maintaining both security reliability and quality of service

Inventive Principle:
Principle #10Preliminary action

3Reliability

If continual configuring, updating, and patching of security components is performed, then security reliability is improved, but loss of time and productivity increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidmaintenance time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security updates, configuration changes, and patching operations are performed continuously in the background without interrupting normal system operations. The security system maintains continual monitoring and incremental updates while data communication proceeds uninterrupted, eliminating the need for scheduled maintenance downtime and reducing total maintenance time

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system automatically detects security vulnerabilities, retrieves appropriate patches and configuration updates, and applies them without human intervention. Automated dependency resolution and conflict detection mechanisms handle update management, freeing operators from time-consuming manual maintenance tasks while maintaining security reliability

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11558423B2Methods for zero trust security with high quality of service
Publication Date: 2023.01.17 STEALTHPATH IP INC
  • US11558423B2 patent drawing
  • US11558423B2 patent drawing
  • US11558423B2 patent drawing

AI summary

The present disclosure relates to network security software cooperatively configured on plural nodes to monitor, alert, authenticate, and authorize devices, applications, users, and data protocol in network communications by exchanging nonpublic identification codes, application identifiers, and data type identifiers via pre-established communication pathways and comparing against pre-established values to provide authorized communication and prevent compromised nodes from spreading malware to other nodes.