Cloud PoD Broker for Secure Web App Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional perimeter-based network security approaches become burdensome for users in cloud-oriented architectures, where organizations move corporate resources outside traditional network perimeters, making it difficult to achieve 'anytime, anywhere access' without installing VPN software on devices.
Innovation Solution
A computer-implemented method for secure access to corporate web applications involves a secure access cloud Point of Delivery (PoD) that brokers authentication and authorization, translating between internal and external addresses of corporate web applications without requiring a corresponding agent on the client device, enabling secure communication sessions transparently across cloud environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional perimeter-based network security with VPN software is used, then network security is maintained, but user accessibility and ease of operation deteriorate in cloud-oriented architectures
Solution Approach 1:
The patent introduces a cloud-based intermediary service that mediates between users and corporate resources. This service handles authentication, authorization, and secure connection establishment without requiring users to install VPN software. The intermediary translates external access requests into internal network communications, maintaining security while enabling cloud-oriented accessibility.
Solution Approach 2:
The patent extracts the VPN functionality from the client device and relocates it to a cloud-based service. By removing the VPN client software requirement from user devices, the system maintains security protocols while eliminating the operational burden of installation, configuration, and maintenance of VPN clients on each device.
2Adaptability or versatility
If corporate resources are moved outside traditional network perimeters to the cloud, then adaptability and versatility improve, but network security and control worsen
Solution Approach 1:
The cloud-based access service acts as a security intermediary that enables cloud resource accessibility while maintaining organizational control. It implements authentication, authorization, and encryption protocols to secure communications between users and cloud-hosted resources, allowing adaptability without compromising security.
Solution Approach 2:
The system dynamically adapts security protocols and connection methods based on the cloud environment. It establishes secure tunnels to cloud resources, dynamically manages authentication credentials, and adjusts security policies according to the specific cloud infrastructure being accessed, enabling versatile cloud access while maintaining security.
3Reliability
If VPN software is installed on client devices for secure access, then network security is maintained, but device complexity and installation burden increase
Solution Approach 1:
The patent extracts VPN functionality from client devices and consolidates it into a cloud-based service. Users access corporate resources through a web browser or simple clientless interface, eliminating the need to install, configure, or maintain VPN software on personal devices while maintaining secure connections.
Solution Approach 2:
The cloud-based access service provides universal access to corporate resources across multiple devices and platforms without requiring device-specific software installations. A single cloud service handles authentication and secure connection establishment for all users regardless of their device type, simplifying the user experience while maintaining security.
Data Source
AI summary
Secure access to a corporate application with translation between an internal address and an external address. In some embodiments, a method may include receiving, at a secure access cloud point of delivery (PoD), from a client application on a client device, a request to access a corporate web application that is deployed in a corporate datacenter. The method may also include forwarding, from the secure access cloud PoD, to a connector that is also deployed in the corporate datacenter, the request to access the corporate web application. The method may further include brokering, by the connector and the secure access cloud PoD, authentication of a user, authorization of access by the user, and a secure communication session between the client application and the corporate web application by translating between an internal address of the corporate web application and an external address of the corporate web application.


