Cloud Workspace System for Secure Law Enforcement Database Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems fail to provide reliable and cost-effective access to secure law enforcement databases in the field, particularly due to connectivity issues and security concerns when using mobile devices, leading to inefficiencies and increased labor costs.

Innovation Solution

A system that enables secure access to a cloud-based database using smartcard pass-through authentication, supporting both common access card (CAC) and personal identity verification (PIV), allowing users to connect via thin clients or mobile devices without requiring a VPN, ensuring data security and reducing endpoint risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a VPN connection is used to access secure database from mobile device, then security is maintained, but connectivity reliability deteriorates due to packet loss and session termination

Engineering Contradiction:
Improveconnectivity reliabilityVSAvoidsecurity risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

A cloud-based session-hosted desktop environment acts as an intermediary between the mobile device and the secure database. The desktop session is hosted on secure infrastructure in the cloud, allowing users to access the database through a web browser without establishing direct VPN connections from mobile devices. This intermediary approach maintains security while eliminating mobile connectivity issues.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the traditional VPN-based mechanical connection system with a web-based access system. Instead of requiring VPN protocols and network layer connections, users access the secure database through standard web browsers using HTTPS connections, substituting the complex VPN mechanism with a simpler, more reliable web interface that works over any internet connection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If Windows client workstation is used for database access, then security and functionality are maintained, but cost increases due to frequent updates and maintenance

Engineering Contradiction:
ImprovesecurityVSAvoidmaintenance cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent uses session-hosted desktop environments that are created on-demand and can be discarded after use. Each user session is a temporary, isolated instance that provides the necessary Windows environment and security credentials only for the duration of the work session, eliminating the need for permanent, expensive Windows client workstations that require ongoing maintenance and updates.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The cloud-hosted desktop session provides universal access to the secure database from any device with a web browser. The same secure environment and database access capabilities are made available across different devices and locations without requiring device-specific software installations or maintenance, making the system universally accessible and reducing overall maintenance costs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If data is transmitted to mobile device for access, then accessibility is improved, but security deteriorates as data becomes available in unencrypted form on endpoint

Engineering Contradiction:
ImproveaccessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the sensitive data from the mobile device environment and keeps it exclusively on the secure server. Only the user's interaction interface (web browser) is hosted on the mobile device, while all data processing and storage occur on the secure server. This extraction approach allows mobile accessibility without exposing data to the unsecured mobile device environment.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the dimension of data access by moving from direct data transmission to the device to remote access through a web interface. Instead of bringing data to the mobile device (one dimension), the system creates a new dimension of access where the user interacts with the data through a browser-based interface that streams graphical representations without transferring the actual data to the device.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Reliability

If VPN connection is required for database access, then security is maintained, but productivity deteriorates due to reconnection requirements and data loss

Engineering Contradiction:
ImprovesecurityVSAvoidwork efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables continuous access to the secure database through the session-hosted desktop environment. The desktop session maintains persistent connections to the database, and users can reconnect to their same session from any device without losing their work context. This continuity eliminates the need to re-establish VPN connections and recover from connection interruptions, maintaining both security and productivity.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11611549B2System and method of securing access to a secure remote server and database on a mobile device
Publication Date: 2023.03.21 FSET INC
  • US11611549B2 patent drawing
  • US11611549B2 patent drawing

AI summary

A new and novel system and method for reliably, securely, and affordably isolating and securing remote access to a secure cloud-based server and database, specifically, a NicheRMS police database, through a secured application, such as the NicheRMS application, over a secure network connection, such as a Citrix Independent Computing Architecture (ICA) connection, wherein the data in the sensitive database is accessed, and only present in a secured workspace and never transmitted locally to the endpoint devices.