Enterprise Perimeter Access via Identifier Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in securely managing access to resources across different perimeters, such as personal and enterprise networks, especially when devices connect to networks through wireless connections, as they struggle to effectively control and separate resources using traditional security protocols.

Innovation Solution

A system and method that utilize enterprise identifiers to grant access to resources within an enterprise perimeter by comparing identifiers between devices, allowing secure access when matching and creating a separate unknown user perimeter when identifiers do not match, thereby ensuring secure separation of resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security protocols are used to control access to resources, then security control is maintained, but the ability to effectively separate and manage resources across different perimeters deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoidresource separation capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments resources into different perimeters (personal perimeter and enterprise perimeter) with distinct security policies. Each perimeter is independently managed with its own access control rules, allowing simultaneous maintenance of security control and effective resource separation across multiple organizational contexts.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If devices connect to networks through wireless connections, then network accessibility is improved, but the complexity of controlling and separating resources across different perimeters increases

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidperimeter control complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system introduces perimeter identifiers as an intermediary mechanism that automatically identifies and assigns devices to appropriate perimeters based on their enterprise associations. This mediator simplifies the control complexity by automating perimeter assignment, allowing wireless devices to access networks while maintaining clear resource separation without manual configuration.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If enterprise identifiers are used to grant access to enterprise perimeter resources, then secure access control is achieved, but the system complexity for managing identifiers and comparisons increases

Engineering Contradiction:
Improveaccess control securityVSAvoididentifier management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service functionality where devices automatically perform identifier comparisons and self-assign to appropriate perimeters without requiring manual intervention. The device compares its own enterprise identifier against perimeter identifiers and autonomously determines its perimeter membership, reducing the complexity of identifier management while maintaining secure access control.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10735964B2Associating services to perimeters
Publication Date: 2020.08.04 MALIKIE INNOVATIONS LTD
  • US10735964B2 patent drawing
  • US10735964B2 patent drawing
  • US10735964B2 patent drawing

AI summary

In some implementations, a method includes receiving, from a user of a first device, a request to enable access, through a second device, to a server resource account of an enterprise. The first device includes a first enterprise perimeter including an internal resource and a first enterprise identifier and configured to prevent external resources from accessing the internal resource. A request is wirelessly transmit, to the second device, to the second device for a second enterprise identifier assigned to a second enterprise perimeter included in the second device. Whether to grant access to the internal resource is determined based on a first enterprise identifier assigned to the first device and a second enterprise identifier assigned to the second device.