Enterprise Perimeter Connectivity via Mobile Proxy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in securely accessing enterprise resources from computational devices, particularly in establishing and managing connectivity between devices with different security perimeters, such as personal and enterprise perimeters, while maintaining secure separation of resources.
Innovation Solution
The system enables a computing device to access enterprise proxy resources through a mobile communications device with a secure connection, using tethering techniques and bridge management to create separate sockets and virtual interfaces, allowing controlled access to enterprise networks while maintaining security policies across different perimeters.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If tethering techniques are used to connect computing device to mobile communications device for enterprise network access, then connectivity to enterprise resources is enabled, but security separation between personal and enterprise perimeters may be compromised
Solution Approach 1:
The system segments network connectivity into separate perimeters (personal and enterprise) with distinct security policies. The mobile communications device and computing device each maintain separate perimeter contexts, allowing simultaneous personal and enterprise network access without compromising security separation. Socket connections are routed through appropriate perimeter proxies based on the security context required.
Solution Approach 2:
Proxy servers act as intermediaries between the computing device and enterprise network resources. The enterprise perimeter proxy specifically mediates enterprise-related traffic, ensuring that enterprise resources are accessed through a controlled security boundary while personal traffic remains isolated. This intermediary layer enforces security policies without blocking legitimate enterprise access.
2Reliability
If separate sockets and virtual interfaces are created for different perimeters, then security policies are enforced, but device complexity increases
Solution Approach 1:
The perimeter manager implements a universal control mechanism that handles multiple perimeter contexts through a single management interface. Rather than requiring separate complex management systems for each perimeter, the perimeter manager provides unified control over socket creation, proxy selection, and security policy enforcement across both personal and enterprise perimeters, reducing overall system complexity.
Solution Approach 2:
The system automatically determines the appropriate perimeter context and proxy selection based on the security requirements of each connection attempt. The perimeter manager self-manages socket routing and proxy configuration without requiring manual intervention or complex user configuration, reducing the operational complexity of managing multiple virtual interfaces while maintaining strict security enforcement.
3Reliability
If enterprise validation is performed through network connection attempts, then secure access is ensured, but connection establishment time increases
Solution Approach 1:
The system performs preliminary perimeter validation by attempting to establish enterprise network connections before full application-layer authentication. The perimeter manager proactively tests enterprise proxy accessibility and validates the enterprise perimeter context in advance, so that when actual enterprise resources are accessed, the validation is already complete and secure access can be immediately established without time-consuming delays.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
A first device establishes a connection with a second device and attempts access, via the connection to an enterprise server of an enterprise. The first device may have a number of security perimeters, ones of which are allowed to use various communications proxies provided by the second device. If the first device and the second device are associated with a same common enterprise, an enterprise perimeter of the first device may be enabled to access the enterprise using an enterprise proxy of the second device..