Dynamic Policy Access Control for Virtual Private Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote access systems over virtual private networks (VPNs) face security risks due to inadequately configured non-enterprise computing devices, which are often impractical and costly to manage, necessitating a solution for secure access to enterprise resources.

Innovation Solution

A dynamic policy management system that assesses client device configurations and environments, applying granular access controls and using virtual sandboxes to restrict operations, ensuring secure access while allowing flexible device usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If employees are required to use only organization-maintained computing devices, then security risk is reduced, but device complexity and operational cost increase

Engineering Contradiction:
Improvesecurity riskVSAvoiddevice management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a policy management server as an intermediary between the computing device and enterprise resources. This server acts as a mediator that assesses device trust levels and dynamically applies access policies, allowing unmanaged devices to access resources without requiring the device itself to be managed by the organization, thus resolving the contradiction between security and device management complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical approach of physically managing and controlling each device with a virtual/software-based policy enforcement mechanism. Instead of requiring organizational control over the physical device, the system uses software policies and trust assessments to secure access, reducing the need for physical device management infrastructure

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If employees are required to use only organization-maintained computing devices, then security configuration is ensured, but operational cost increases

Engineering Contradiction:
Improvesecurity configurationVSAvoidoperational cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The policy management server serves as an intermediary that provides centralized security policy enforcement without requiring each device to be individually managed. This allows the organization to maintain security configurations through software policies rather than through costly device provisioning and management infrastructure

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically changes access parameters (policy enforcement level) based on device trust assessment results. Devices that pass trust assessment receive appropriate access permissions without requiring full organizational management, allowing cost-effective access while maintaining security through parameter-based control rather than universal device management

Inventive Principle:
Principle #35Parameter changes

3Reliability

If dynamic policy assessment is implemented, then access security is improved, but system complexity increases

Engineering Contradiction:
Improveaccess securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the access control system into distinct functional components: a trust assessment module that evaluates device characteristics, a policy management server that stores and retrieves policies, and an enforcement mechanism that applies policies. This segmentation allows complex security functionality to be implemented through modular, manageable components rather than a monolithic complex system

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements feedback loops where device characteristics are assessed, policy decisions are made based on that assessment, and the results are enforced. This feedback mechanism allows the system to automatically adjust access decisions based on real-time device evaluation, improving security while maintaining manageable system complexity through automated decision-making

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8560709B1System and method for dynamic policy based access over a virtual private network
Publication Date: 2013.10.15 F5 NETWORKS INC
  • US8560709B1 patent drawing
  • US8560709B1 patent drawing
  • US8560709B1 patent drawing

AI summary

An apparatus and method are directed to managing access to an enterprise resource over a virtual private network by employing a dynamic policy. A client device is configured to log into a network device. The network device receives information about the client device, including information about its configuration and environment. Based, in part, on received information a policy for access is applied to the client device. For example, in one embodiment, the policy may allow only email access from a public kiosk client device, but full intranet access from an enterprise configured client device. The policy may further enable a restriction for the client device that may restrict, for example, what documents may be saved by the client device. In one embodiment, the restriction is enabled using a virtual sandbox.