Mobile Access Control Layer for Secure Enterprise Resource Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems do not provide an appropriate interface for managing secure access to enterprise resources via smartphones or other wireless mobile devices, limiting mobile users' ability to access network resources and bypassing security policies, which poses security risks.
Innovation Solution
A client-server system with a mobile access control layer that authenticates users, determines group membership, and generates a list of accessible resources and operations based on access rules, allowing secure management of mobile user access to network resources, including read, write, execute, modify, delete, email, download, and synchronize operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If mobile users are permitted to access enterprise network resources, then user productivity and convenience are improved, but security risks and policy violations increase
Solution Approach 1:
The patent introduces a mobile access control layer as an intermediary component between mobile users and enterprise network resources. This layer includes mobile access control server, client, and interface that mediate all access requests, enabling productivity improvements while maintaining security through controlled intermediation rather than direct access.
Solution Approach 2:
The access control system is segmented into distinct functional components: mobile access control server for policy management, mobile access control client for local authentication, and mobile access control interface for resource coordination. This segmentation allows security policies to be enforced at multiple levels without blocking legitimate productivity-enhancing access.
2Reliability
If a conventional VPN is used for secure access, then security is improved, but system complexity and setup requirements increase
Solution Approach 1:
The patent extracts the essential security function from the complex VPN infrastructure and implements it directly within the mobile device through the mobile access control client. This extracts security enforcement from the network layer and places it at the endpoint, eliminating the need for complex VPN setup while maintaining security through local authentication and policy enforcement.
Solution Approach 2:
The mobile access control client enables users to authenticate and access resources independently without requiring manual VPN configuration. The system performs self-service authentication and policy enforcement locally on the mobile device, eliminating complex setup requirements while maintaining security through automated control.
3Reliability
If access controls are strictly enforced, then security policy compliance is improved, but user convenience and accessibility deteriorate
Solution Approach 1:
The system performs preliminary authentication and policy evaluation through the mobile access control client before actual resource access occurs. User credentials and access policies are verified in advance, and authorized resources are pre-configured through the administrative interface, enabling convenient access without compromising policy compliance.
Solution Approach 2:
The mobile access control interface provides real-time feedback to users about their access rights and available resources based on enforced policies. This feedback mechanism allows users to understand and work within policy constraints without feeling restricted, improving convenience while maintaining compliance through transparent policy communication.
Data Source
AI summary
A client-server system and method is provided for secure management of mobile user access to network resources from a wireless mobile device, such as a smart phone. A mobile access control layer resides between a wireless service provider network and host network, allowing for management of mobile access without overriding internal access policies. Access rules determining accessible resources and permitted operations are determined based on a user's group memberships, and optionally on other information received from the system, or from the mobile device, e.g. time or location. Each group is associated with a set of permitted accessible resources and operations, e.g. read or write access to a resource such as a file, list, shared calendar, et al. A list of accessible resources and permitted operations is generated, and the list is made available for subsequent processes, e.g. presented to the user for selection of an accessible resource and permitted operation.


