Integrity Plug-in Proxy for Endpoint Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network access control methods primarily rely on user authentication and authorization, failing to effectively assess endpoint integrity before granting access, which can lead to untrustworthy devices connecting to internal networks.

Innovation Solution

A method involving the distribution of user data and integrity policies to remote integrity servers, where integrity results are collated to provide an access recommendation or single integrity result, allowing network access authorities to grant or deny access based on endpoint trustworthiness without needing direct knowledge of remote integrity plug-ins.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional user authentication and authorization methods are used for network access control, then the access control process is simple and fast, but the system cannot effectively assess endpoint integrity and trustworthiness

Engineering Contradiction:
Improveendpoint integrity assessmentVSAvoidaccess control system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access control system is segmented into multiple independent components: local integrity plug-ins on user devices, remote integrity servers for verification, and an access control authority. This segmentation allows the system to perform comprehensive integrity assessment without centralizing all complexity in one location, thereby improving reliability while managing device complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components (integrity plug-ins and remote integrity servers) that mediate between the user device and the access control authority. These intermediaries handle the complex integrity verification tasks, allowing the access control system to assess endpoint trustworthiness without requiring the entire system to be complex.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive integrity checks are performed on endpoints before network access, then network security is improved, but the access control process becomes more complex and time-consuming

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess control process time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The integrity plug-ins continuously perform preliminary integrity checks and maintain readiness status on user devices before access requests are made. This preliminary action ensures that when access is requested, the verification process is already partially complete or can be quickly validated, reducing the time loss while maintaining comprehensive security checks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The integrity plug-ins on user devices perform self-service integrity monitoring and self-assessment, automatically checking their own compliance status without requiring real-time intervention from the access control system. This self-service approach maintains high network security through continuous monitoring while minimizing the time required for access verification.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If third party integrity plug-ins are loaded on remote integrity servers separate from the network, then the network server can maintain security and control, but the network access authority cannot directly manage or know about the remote integrity plug-ins

Engineering Contradiction:
Improveintegrity verification capabilityVSAvoidintegrity management system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The access control authority is designed with universal functionality that allows it to manage multiple types of integrity plug-ins from different third-party vendors without requiring specific knowledge of each plug-in's internal workings. The authority interacts with all plug-ins through a standardized interface, enabling versatile integrity verification while simplifying the management system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses an intermediary standardized interface layer between the access control authority and remote integrity plug-ins. This intermediary allows the authority to manage and coordinate multiple third-party plug-ins without needing direct knowledge of their specific implementations, thereby increasing adaptability while managing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8667555B1Integrity plug-in-proxy
Publication Date: 2014.03.04 PULSE SECURE LLC
  • US8667555B1 patent drawing
  • US8667555B1 patent drawing
  • US8667555B1 patent drawing

AI summary

A system receives user data associated with a user device and integrity policies associated with the user data, and distributes the user data and the integrity policies to one or more remote integrity servers. The system further receives integrity results from the one or more remote integrity servers based on the user data and the integrity policies, and collates the integrity results to formulate an access recommendation or a single integrity result for the user device.