Dynamic Policy Access Control for Virtual Private Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing remote access systems over virtual private networks (VPNs) face security risks due to inadequately configured non-enterprise computing devices, which are often impractical and costly to manage, necessitating a solution for secure access to enterprise resources.
Innovation Solution
A dynamic policy management system that assesses client device configurations and environments, applying granular access controls and using virtual sandboxes to restrict operations, ensuring secure access while allowing flexible device usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If employees are required to use only organization-maintained computing devices, then security risk is reduced, but device complexity and operational cost increase
Solution Approach 1:
The patent introduces a policy management server as an intermediary between the computing device and enterprise resources. This server acts as a mediator that assesses device trust levels and dynamically applies access policies, allowing unmanaged devices to access resources without requiring the device itself to be managed by the organization, thus resolving the contradiction between security and device management complexity
Solution Approach 2:
The patent replaces the mechanical approach of physically managing and controlling each device with a virtual/software-based policy enforcement mechanism. Instead of requiring organizational control over the physical device, the system uses software policies and trust assessments to secure access, reducing the need for physical device management infrastructure
2Reliability
If employees are required to use only organization-maintained computing devices, then security configuration is ensured, but operational cost increases
Solution Approach 1:
The policy management server serves as an intermediary that provides centralized security policy enforcement without requiring each device to be individually managed. This allows the organization to maintain security configurations through software policies rather than through costly device provisioning and management infrastructure
Solution Approach 2:
The system dynamically changes access parameters (policy enforcement level) based on device trust assessment results. Devices that pass trust assessment receive appropriate access permissions without requiring full organizational management, allowing cost-effective access while maintaining security through parameter-based control rather than universal device management
3Reliability
If dynamic policy assessment is implemented, then access security is improved, but system complexity increases
Solution Approach 1:
The patent segments the access control system into distinct functional components: a trust assessment module that evaluates device characteristics, a policy management server that stores and retrieves policies, and an enforcement mechanism that applies policies. This segmentation allows complex security functionality to be implemented through modular, manageable components rather than a monolithic complex system
Solution Approach 2:
The system implements feedback loops where device characteristics are assessed, policy decisions are made based on that assessment, and the results are enforced. This feedback mechanism allows the system to automatically adjust access decisions based on real-time device evaluation, improving security while maintaining manageable system complexity through automated decision-making
Data Source
AI summary
An apparatus and method are directed to managing access to an enterprise resource over a virtual private network by employing a dynamic policy. A client device is configured to log into a network device. The network device receives information about the client device, including information about its configuration and environment. Based, in part, on received information a policy for access is applied to the client device. For example, in one embodiment, the policy may allow only email access from a public kiosk client device, but full intranet access from an enterprise configured client device. The policy may further enable a restriction for the client device that may restrict, for example, what documents may be saved by the client device. In one embodiment, the restriction is enabled using a virtual sandbox.


