Compliance Profile-Based Virtual Session Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing zero-trust security policies in virtual environments often deny access to virtual sessions due to minor non-compliance issues, leading to productivity losses and unnecessary employee downtime, as they do not differentiate between critical and non-critical security threats.
Innovation Solution
Implementing a compliance profile-based system that assesses the operational state of user devices to grant selective virtual session capabilities, allowing access with a minimum set of capabilities while ensuring security, thereby reducing downtime and maintaining productivity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If zero-trust security policies are implemented to verify all device compliance rules, then security is improved, but access to virtual sessions is denied for minor non-compliance issues, leading to productivity loss
Solution Approach 1:
The patent segments the virtual session access into multiple capability levels based on compliance profile scores. Instead of treating all access requests uniformly, the system divides access rights into different tiers (full access, partial access, restricted access) corresponding to different compliance levels, allowing employees to access appropriate functionalities without complete denial
Solution Approach 2:
The patent changes the parameter of access decision from binary (compliant/non-compliant) to continuous (compliance profile score). By calculating a numerical score based on multiple compliance factors and mapping it to different access levels, the system enables graduated access decisions that balance security requirements with productivity needs
2Object-affected harmful factors
If all compliance rules must be satisfied for virtual session access, then security threats are prevented, but employee downtime increases due to inability to access sessions with minor non-compliance
Solution Approach 1:
The patent applies partial action by granting partial access to virtual sessions when compliance is partial. Instead of requiring 100% compliance for any access, the system provides sufficient access level based on the compliance score, allowing employees to perform essential tasks while maintaining security boundaries
Solution Approach 2:
The patent introduces a compliance profile scoring system as an intermediary between security policies and access decisions. This mediator evaluates the degree of compliance and translates it into appropriate access levels, preventing complete access denial while maintaining security thresholds
3Reliability
If zero-trust policies deny access for any non-compliance rule, then security perimeters are protected, but critical productivity activities are blocked unnecessarily
Solution Approach 1:
The patent applies local quality by restricting specific capabilities rather than entire virtual session access. Employees with partial compliance receive access to non-sensitive functionalities while sensitive operations remain restricted, allowing critical productivity activities to continue without compromising security perimeter
Data Source
AI summary
Systems and methods can enable select virtual session capabilities on a user device configured to access a virtual session, which is an instance of a virtual machine. The user device can receive and forward to a gateway sever, a request to launch a virtual session. Based on the virtual session launch request, the gateway server can obtain a compliance profile determined from operational data for the user device and compare it to a minimum access policy (“MAP”). The MAP can include threshold or binary values for states of a group of user device operational aspects. Where the compliance profile satisfies the MAP, the gateway can permit user device access a virtual session hosted on a virtual machine (“VM”) server. The virtual session can be configured at the VM server based on the compliance profile so as to allow access to a portion of a full virtual session capability scheme.


