Application Catalog Network Microsegmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional methods for managing network resource permissions in large organizations are inefficient, as they often grant all users access to all resources, exposing sensitive information and failing to scale with the number of employees and resources, leading to security risks.

Innovation Solution

Implementing an application catalog that allows users to select specific network resources needed for their roles, using network microsegmentation to enforce permissions, creating virtual network segments for each resource grouping, and configuring applications to access only authorized resources, thereby restricting access based on organizational roles.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional permission management methods are used, then ease of operation is improved (simple user access), but security deteriorates (exposure of sensitive information)

Engineering Contradiction:
Improveuser accessVSAvoidexposure of sensitive information
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies network microsegmentation to divide the network into isolated segments, where each segment corresponds to a specific resource or resource group. Users are assigned to specific segments based on their roles, allowing them to access only the resources they need while maintaining ease of operation through role-based access control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by providing different access permissions to different users based on their specific roles and requirements. Instead of uniform access, each user receives tailored permissions that match their functional needs, balancing security with operational ease.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If traditional permission management methods are used, then ease of operation is improved, but device complexity deteriorates (cannot scale with organization size)

Engineering Contradiction:
Improvepermission managementVSAvoidsystem scalability
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent creates a universal permission management system where a single application can be configured to access multiple network resources through virtual network segments. This multi-functional approach allows the system to scale with the organization without requiring separate custom applications for each resource group.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements dynamic permission management where access rights can be automatically adjusted based on user roles, departments, or other organizational attributes. This dynamic configuration enables the system to adapt to changing organizational needs while maintaining ease of operation through automated management.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If all users receive access to all resources, then ease of operation is improved, but reliability deteriorates (security risks)

Engineering Contradiction:
Improveresource accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the network into isolated virtual network segments, where each segment contains specific resources accessible to designated user groups. This segmentation maintains security by limiting access while preserving ease of operation through role-based access control within each segment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces virtual network segments as intermediary structures between users and network resources. These segments act as mediators that control and filter access, ensuring that users can access resources they need while preventing unauthorized access to sensitive information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11812273B2Managing network resource permissions for applications using an application catalog
Publication Date: 2023.11.07 OMNISSA LLC
  • US11812273B2 patent drawing
  • US11812273B2 patent drawing
  • US11812273B2 patent drawing

AI summary

Disclosed are various examples for managing network resource permissions for applications through the use of an application catalog. An identification of a particular application from the application catalog is received from a managed client device. The identification indicates a particular security group of multiple security groups. A network of the organization is configured to provide the particular application on the managed client device with access to a set of resources corresponding to the particular security group.