Application Signature Authorization for Granular Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Companies face challenges in securely managing access to corporate networks from personal devices owned by employees, known as 'unmanaged devices' or 'BYOD,' due to concerns about vulnerabilities from nefarious applications and data leakage, as existing VPN solutions provide all-or-nothing data sharing and lack granular application control.

Innovation Solution

An appliance works in conjunction with an agent on a remote device to control application access to a corporate network through an SSL tunnel and policy, allowing users to determine which applications can access the network, with analysis to identify secure configurations and denials, and using code signatures to verify authorized applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If all data is shared with corporate intranet through VPN, then network accessibility is improved, but security risk increases due to potential data leakage and unauthorized access

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments network traffic by application, creating separate virtual interfaces for different applications. This allows the system to control and restrict traffic on a per-application basis rather than allowing all-or-nothing access, thereby maintaining security while enabling necessary network connectivity for authorized applications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements different security policies for different applications by assigning unique identifiers and characteristics to each application's network traffic. This enables granular control where each application receives appropriate network access based on its specific requirements and security clearance, rather than applying a uniform policy to all applications.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If no data is shared with corporate intranet, then security risk is reduced, but network accessibility deteriorates preventing employees from performing work tasks

Engineering Contradiction:
Improvesecurity riskVSAvoidnetwork accessibility
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

By segmenting network access into application-specific channels, the system enables selective data sharing where only authorized applications can communicate with the corporate intranet. This resolves the contradiction by allowing necessary work-related applications to access the network while blocking unauthorized applications, thus maintaining both security and accessibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a network controller as an intermediary that sits between the device applications and the corporate intranet. This controller monitors and manages application traffic, enabling authorized communication while preventing unauthorized access, thus mediating between security requirements and accessibility needs.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If MDM control is implemented on employee devices, then security control is improved, but device autonomy deteriorates as users lose control over their personal devices

Engineering Contradiction:
Improvesecurity controlVSAvoiddevice autonomy
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent applies security controls at the application level rather than device level, allowing each application to have its own security policy and network interface. This enables security management without requiring full MDM control, as users retain autonomy over their devices while the system enforces security policies for specific applications accessing the corporate network.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

By segmenting the device into application-specific network zones with unique identifiers, the system enables granular security control for corporate-related applications without imposing device-wide MDM restrictions. This allows users to maintain full control of their personal devices while enabling secure access for authorized applications.

Inventive Principle:
Principle #1Segmentation

4Object-affected harmful factors

If per-application VPN control is implemented, then application-level security is improved, but system complexity increases due to multiple VPN clients and configurations

Engineering Contradiction:
Improveapplication-level securityVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent merges multiple application-specific network interfaces and security policies into a single unified network controller that manages all applications through one system. This eliminates the need for multiple separate VPN clients and configurations, reducing system complexity while maintaining application-level security control through centralized management.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11140131B2Application signature authorization
Publication Date: 2021.10.05 SONICWALL US HOLDINGS INC
  • US11140131B2 patent drawing
  • US11140131B2 patent drawing
  • US11140131B2 patent drawing

AI summary

An appliance works in conjunction with an agent on a remote device to control application access to a corporate network. In conjunction with an SSL tunnel and policy operating at the appliance, granular application control may be implemented. In particular, a device user may determine what applications from a set of applications may access the corporate network and which applications do not access the network. The applications may be analyzed to determine whether the application is good or bad, as what security configurations, approvals and denials are associated with the application.