Network Security Gateway Micro-Segmentation Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional approaches to restricting access in large organizations with many employees and resources are inefficient, as they cannot scale to manage permissions for numerous documents and resources, leading to exposure of sensitive information.

Innovation Solution

Implementing a network security model that uses micro-segmentation and device management attributes to condition access to network resources, allowing specific applications to access designated security groups based on factors like location, user identity, and device status, with a gateway enforcing rules through VPN tunnels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional permission management approaches are used (administrator setting permissions for every user on every document), then access control can be established, but the system cannot scale to organizations with many employees and large numbers of documents and resources

Engineering Contradiction:
Improvescalability of permission managementVSAvoidcomplexity of permission configuration
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the network into multiple virtual network segments (micro-segments), each representing a distinct security zone. Instead of managing permissions individually for each user-document pair, the system creates granular network segments that automatically enforce access policies based on device management attributes, thereby scaling permission management to large organizations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a gateway as an intermediary component that sits between users and network resources. The gateway automatically evaluates device management attributes and enforces access policies without requiring administrators to manually configure permissions for each user-resource interaction, enabling scalable security management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If all employees receive access to all resources on the network, then ease of access is improved, but sensitive corporation information is exposed throughout the organization

Engineering Contradiction:
Improveease of resource accessVSAvoidinformation exposure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by assigning different security attributes and access policies to different virtual network segments. Each segment can have customized access controls based on specific device management attributes, allowing employees to easily access resources in segments where they have legitimate needs while automatically blocking access to segments containing sensitive information they should not view.

Inventive Principle:
Principle #3Local quality

3Reliability

If micro-segmentation is implemented with gateway enforcement, then granular control over network resources is achieved, but device complexity and configuration requirements increase

Engineering Contradiction:
Improvesecurity control precisionVSAvoidgateway configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the gateway a multi-functional component that simultaneously performs multiple security functions: evaluating device management attributes, determining appropriate virtual network segments, enforcing access policies, and managing session state. This consolidation of functions into a single intelligent gateway reduces overall system complexity despite the granular security controls provided by micro-segmentation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12126596B2Configuring network security based on device management characteristics
Publication Date: 2024.10.22 OMNISSA LLC
  • US12126596B2 patent drawing
  • US12126596B2 patent drawing
  • US12126596B2 patent drawing

AI summary

Disclosed are various examples for configuring network security based on device management characteristics. In one example, a specification of a set of network resources on an internal network is received from an administrator client. The set of network resources are those network resources that a particular application executed in client devices on an external network should be authorized to access. A gateway from the external network to the internal network is then configured to permit the particular application to have access to the set of network resources.