Extranet Provisioning System for Non-Enterprise Device Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Non-enterprise client devices often unintentionally facilitate breaches in enterprise network security, as they lack awareness of their role in potential security breaches and do not have restricted access to enterprise network systems.

Innovation Solution

A system and method for provisioning non-enterprise client devices with access to an extranet enterprise domain, utilizing a provisioner that generates a unique permanent identification IDINDEX, sends linkage and access messages via different transmission systems, and manages client records to ensure secure access without exposing enterprise client data outside the intranet.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If non-enterprise client devices are granted access to the enterprise network system, then access to network resources is improved, but network security is worsened due to potential breaches

Engineering Contradiction:
Improveaccess to network resourcesVSAvoidnetwork security breaches
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network access by creating separate extranet and intranet zones. Non-enterprise client devices are provisioned with credentials that grant access only to the extranet portion of the enterprise network, physically and logically isolating them from the sensitive intranet resources. This segmentation allows controlled access while maintaining security boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary provisioning system that acts as a mediator between non-enterprise devices and the enterprise network. This intermediary credentials system manages authentication and authorization, controlling what resources non-enterprise devices can access and preventing direct access to sensitive intranet areas, thus resolving the security conflict.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If enterprise client data is stored outside the intranet for extranet access, then access convenience is improved, but data security is worsened

Engineering Contradiction:
Improveaccess convenienceVSAvoiddata exposure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the necessary access credentials and authentication information needed for extranet access, storing them in a secure credentials system outside the intranet. The actual enterprise client data remains protected within the intranet, while only the minimal required authentication data is externalized to enable convenient access control.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements local quality by creating different data storage locations with different security characteristics. Sensitive enterprise client data is kept in the secure intranet environment, while access credentials are stored in a separate extranet credentials system. Each location has appropriate security measures tailored to its specific function and risk profile.

Inventive Principle:
Principle #3Local quality

3Device complexity

If a single transmission system is used for provisioning messages, then system complexity is reduced, but message delivery reliability is worsened

Engineering Contradiction:
Improvetransmission system complexityVSAvoidmessage delivery reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent merges multiple transmission channels (email system and SMS messaging system) into a unified provisioning system that can select appropriate channels based on message type and recipient preferences. This combination maintains low complexity from the user perspective while achieving high reliability through redundant communication paths.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The provisioning system is designed with multi-functionality to send different types of messages (activation links, security codes, notifications) through different transmission systems (email, SMS) based on the specific requirements of each message type, achieving both versatility and reliability without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11436314B2System and method for provisioning non-enterprise client devices with access credentials
Publication Date: 2022.09.06 SAUDI ARABIAN OIL CO
  • US11436314B2 patent drawing
  • US11436314B2 patent drawing
  • US11436314B2 patent drawing

AI summary

A system, a method, or a computer program for provisioning a non-enterprise client device with access to an extranet enterprise domain. The system includes an enterprise client device connected to an intranet, a provisioner that receives an extranet registration request from the enterprise client device, an active directory connected to the intranet, a database that stores a non-enterprise client record populated with the non-enterprise client data, a primary transmission system connected to the intranet that transmits a portion of the non-enterprise client data and a linkage message outside of the intranet, and a secondary transmission system connected to the intranet and configured to transmit to an access message outside of the intranet, wherein the provisioner generates a unique permanent identification IDINDEX for the non-enterprise client record.