Client-Side Security String Evaluation for VPN Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for accessing a virtual private network connection are burdensome due to the need for explicit user credential authentication and evaluation, which increases administrative workload and introduces delays, especially when components are remotely located.

Innovation Solution

A method where an appliance transmits a security string to a client for evaluation based on client-side attributes, allowing the client to assess and respond, thereby reducing the number of components involved in access control decisions and minimizing administrative burdens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional credential authentication methods are used, then access control security is maintained, but administrative burden increases and access delays occur

Engineering Contradiction:
Improveaccess control processVSAvoidaccess decision delay
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by having the client evaluate security clauses and gather attribute information before the formal access decision is made. This pre-evaluation reduces the time required for the actual access decision by the policy engine, as much of the credential verification work is completed in advance by the client device itself.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary approach where the client device acts as a partial mediator in the authentication process. Instead of direct credential verification between the user and policy engine, the client device intermediates by locally evaluating security clauses and preparing attribute data, thereby reducing the burden on remote policy engines and minimizing access delays.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple components are involved in credential evaluation, then security checks are thorough, but system complexity increases

Engineering Contradiction:
Improvesecurity verificationVSAvoidaccess control system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the access control system into distinct functional components: the client device handles credential gathering and security clause evaluation, while the policy engine focuses on making the final access decision. This segmentation distributes the security verification burden across multiple specialized components, maintaining thorough security checks while reducing overall system complexity through clear division of responsibilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the credential evaluation function from the central policy engine and places it on the client device. By taking out the security clause evaluation and attribute gathering tasks from the main access control system, the patent reduces the complexity of the policy engine while maintaining comprehensive security verification through the distributed evaluation process.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If credential requests are translated into user-friendly formats, then ease of use improves, but processing time increases

Engineering Contradiction:
Improvecredential request interfaceVSAvoidaccess decision speed
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent implements self-service by enabling the client device to autonomously evaluate security clauses and gather required attribute information without requiring manual user intervention for credential translation. The client device automatically retrieves and evaluates the necessary credentials locally, eliminating the time-consuming translation and manual processing steps while maintaining user-friendly access.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8904475B2Method and system for authorizing a level of access of a client to a virtual private network connection, based on a client-side attribute
Publication Date: 2014.12.02 CITRIX SYSTEMS INC
  • US8904475B2 patent drawing
  • US8904475B2 patent drawing
  • US8904475B2 patent drawing

AI summary

An appliance and method for authorizing a level of access of a client to a virtual private network connection, based on a client-side attribute includes the step of establishing, by an appliance, a control connection with a client upon receiving a client request to establish a virtual private network connection with a network. The appliance transmits, via the control connection, a request to the client to evaluate at least one clause of a security string, the at least one clause including an expression associated with a client-side attribute. The client transmits, via the control connection, a response to the appliance comprising a result of evaluating the at least one clause by the client. The appliance assigns the client to an authorization group based on the result of evaluation of the at least one clause.