Cloud PoD Broker for Secure Web App Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional perimeter-based network security approaches become burdensome for users in cloud-oriented architectures, where organizations move corporate resources outside traditional network perimeters, making it difficult to achieve 'anytime, anywhere access' without installing VPN software on devices.

Innovation Solution

A computer-implemented method for secure access to corporate web applications involves a secure access cloud Point of Delivery (PoD) that brokers authentication and authorization, translating between internal and external addresses of corporate web applications without requiring a corresponding agent on the client device, enabling secure communication sessions transparently across cloud environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional perimeter-based network security with VPN software is used, then network security is maintained, but user accessibility and ease of operation deteriorate in cloud-oriented architectures

Engineering Contradiction:
Improvenetwork securityVSAvoiduser accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a cloud-based intermediary service that mediates between users and corporate resources. This service handles authentication, authorization, and secure connection establishment without requiring users to install VPN software. The intermediary translates external access requests into internal network communications, maintaining security while enabling cloud-oriented accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the VPN functionality from the client device and relocates it to a cloud-based service. By removing the VPN client software requirement from user devices, the system maintains security protocols while eliminating the operational burden of installation, configuration, and maintenance of VPN clients on each device.

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If corporate resources are moved outside traditional network perimeters to the cloud, then adaptability and versatility improve, but network security and control worsen

Engineering Contradiction:
Improvecloud resource accessibilityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The cloud-based access service acts as a security intermediary that enables cloud resource accessibility while maintaining organizational control. It implements authentication, authorization, and encryption protocols to secure communications between users and cloud-hosted resources, allowing adaptability without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically adapts security protocols and connection methods based on the cloud environment. It establishes secure tunnels to cloud resources, dynamically manages authentication credentials, and adjusts security policies according to the specific cloud infrastructure being accessed, enabling versatile cloud access while maintaining security.

Inventive Principle:
Principle #15Dynamics

3Reliability

If VPN software is installed on client devices for secure access, then network security is maintained, but device complexity and installation burden increase

Engineering Contradiction:
Improvesecure connectionVSAvoidsoftware installation requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts VPN functionality from client devices and consolidates it into a cloud-based service. Users access corporate resources through a web browser or simple clientless interface, eliminating the need to install, configure, or maintain VPN software on personal devices while maintaining secure connections.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The cloud-based access service provides universal access to corporate resources across multiple devices and platforms without requiring device-specific software installations. A single cloud service handles authentication and secure connection establishment for all users regardless of their device type, simplifying the user experience while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11665171B2Secure access to a corporate web application with translation between an internal address and an external address
Publication Date: 2023.05.30 CA TECH INC
  • US11665171B2 patent drawing
  • US11665171B2 patent drawing
  • US11665171B2 patent drawing

AI summary

Secure access to a corporate application with translation between an internal address and an external address. In some embodiments, a method may include receiving, at a secure access cloud point of delivery (PoD), from a client application on a client device, a request to access a corporate web application that is deployed in a corporate datacenter. The method may also include forwarding, from the secure access cloud PoD, to a connector that is also deployed in the corporate datacenter, the request to access the corporate web application. The method may further include brokering, by the connector and the secure access cloud PoD, authentication of a user, authorization of access by the user, and a secure communication session between the client application and the corporate web application by translating between an internal address of the corporate web application and an external address of the corporate web application.