Application Signature Authorization for Granular Network Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Companies face challenges in securely managing access to corporate networks from personal devices owned by employees, known as 'unmanaged devices' or 'BYOD,' due to concerns about vulnerabilities from nefarious applications and data leakage, as existing VPN solutions provide all-or-nothing data sharing and lack granular application control.
Innovation Solution
An appliance works in conjunction with an agent on a remote device to control application access to a corporate network through an SSL tunnel and policy, allowing users to determine which applications can access the network, with analysis to identify secure configurations and denials, and using code signatures to verify authorized applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If all data is shared with corporate intranet through VPN, then network accessibility is improved, but security risk increases due to potential data leakage and unauthorized access
Solution Approach 1:
The patent segments network traffic by application, creating separate virtual interfaces for different applications. This allows the system to control and restrict traffic on a per-application basis rather than allowing all-or-nothing access, thereby maintaining security while enabling necessary network connectivity for authorized applications.
Solution Approach 2:
The patent implements different security policies for different applications by assigning unique identifiers and characteristics to each application's network traffic. This enables granular control where each application receives appropriate network access based on its specific requirements and security clearance, rather than applying a uniform policy to all applications.
2Object-affected harmful factors
If no data is shared with corporate intranet, then security risk is reduced, but network accessibility deteriorates preventing employees from performing work tasks
Solution Approach 1:
By segmenting network access into application-specific channels, the system enables selective data sharing where only authorized applications can communicate with the corporate intranet. This resolves the contradiction by allowing necessary work-related applications to access the network while blocking unauthorized applications, thus maintaining both security and accessibility.
Solution Approach 2:
The patent introduces a network controller as an intermediary that sits between the device applications and the corporate intranet. This controller monitors and manages application traffic, enabling authorized communication while preventing unauthorized access, thus mediating between security requirements and accessibility needs.
3Object-affected harmful factors
If MDM control is implemented on employee devices, then security control is improved, but device autonomy deteriorates as users lose control over their personal devices
Solution Approach 1:
The patent applies security controls at the application level rather than device level, allowing each application to have its own security policy and network interface. This enables security management without requiring full MDM control, as users retain autonomy over their devices while the system enforces security policies for specific applications accessing the corporate network.
Solution Approach 2:
By segmenting the device into application-specific network zones with unique identifiers, the system enables granular security control for corporate-related applications without imposing device-wide MDM restrictions. This allows users to maintain full control of their personal devices while enabling secure access for authorized applications.
4Object-affected harmful factors
If per-application VPN control is implemented, then application-level security is improved, but system complexity increases due to multiple VPN clients and configurations
Solution Approach 1:
The patent merges multiple application-specific network interfaces and security policies into a single unified network controller that manages all applications through one system. This eliminates the need for multiple separate VPN clients and configurations, reducing system complexity while maintaining application-level security control through centralized management.
Data Source
AI summary
An appliance works in conjunction with an agent on a remote device to control application access to a corporate network. In conjunction with an SSL tunnel and policy operating at the appliance, granular application control may be implemented. In particular, a device user may determine what applications from a set of applications may access the corporate network and which applications do not access the network. The applications may be analyzed to determine whether the application is good or bad, as what security configurations, approvals and denials are associated with the application.


