Enterprise Perimeter Connectivity via Mobile Proxy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in securely accessing enterprise resources from computational devices, particularly in establishing and managing connectivity between devices with different security perimeters, such as personal and enterprise perimeters, while maintaining secure separation of resources.

Innovation Solution

The system enables a computing device to access enterprise proxy resources through a mobile communications device with a secure connection, using tethering techniques and bridge management to create separate sockets and virtual interfaces, allowing controlled access to enterprise networks while maintaining security policies across different perimeters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If tethering techniques are used to connect computing device to mobile communications device for enterprise network access, then connectivity to enterprise resources is enabled, but security separation between personal and enterprise perimeters may be compromised

Engineering Contradiction:
Improveconnectivity to enterprise resourcesVSAvoidsecurity separation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments network connectivity into separate perimeters (personal and enterprise) with distinct security policies. The mobile communications device and computing device each maintain separate perimeter contexts, allowing simultaneous personal and enterprise network access without compromising security separation. Socket connections are routed through appropriate perimeter proxies based on the security context required.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Proxy servers act as intermediaries between the computing device and enterprise network resources. The enterprise perimeter proxy specifically mediates enterprise-related traffic, ensuring that enterprise resources are accessed through a controlled security boundary while personal traffic remains isolated. This intermediary layer enforces security policies without blocking legitimate enterprise access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate sockets and virtual interfaces are created for different perimeters, then security policies are enforced, but device complexity increases

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidsocket and interface management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The perimeter manager implements a universal control mechanism that handles multiple perimeter contexts through a single management interface. Rather than requiring separate complex management systems for each perimeter, the perimeter manager provides unified control over socket creation, proxy selection, and security policy enforcement across both personal and enterprise perimeters, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system automatically determines the appropriate perimeter context and proxy selection based on the security requirements of each connection attempt. The perimeter manager self-manages socket routing and proxy configuration without requiring manual intervention or complex user configuration, reducing the operational complexity of managing multiple virtual interfaces while maintaining strict security enforcement.

Inventive Principle:
Principle #25Self-service

3Reliability

If enterprise validation is performed through network connection attempts, then secure access is ensured, but connection establishment time increases

Engineering Contradiction:
Improvesecure access validationVSAvoidconnection establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary perimeter validation by attempting to establish enterprise network connections before full application-layer authentication. The perimeter manager proactively tests enterprise proxy accessibility and validates the enterprise perimeter context in advance, so that when actual enterprise resources are accessed, the validation is already complete and secure access can be immediately established without time-consuming delays.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2629557B1Establishing connectivity between an enterprise security perimeter of a device and an enterprise
Publication Date: 2019.10.23 BLACKBERRY LTD
  • EP2629557B1 patent drawingFigure 1
  • EP2629557B1 patent drawingFigure 2A
  • EP2629557B1 patent drawingFigure 2B

AI summary

A first device establishes a connection with a second device and attempts access, via the connection to an enterprise server of an enterprise. The first device may have a number of security perimeters, ones of which are allowed to use various communications proxies provided by the second device. If the first device and the second device are associated with a same common enterprise, an enterprise perimeter of the first device may be enabled to access the enterprise using an enterprise proxy of the second device..