Mobile Access Server Mediator for Enterprise Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems fail to provide secure and efficient access to enterprise network resources for mobile users, limiting their ability to access documents and files from wireless devices, and existing solutions often compromise security or override internal access policies.

Innovation Solution

A method and system that determine user access rights based on group membership, generating a list of accessible resources and operations, which are then presented to the user on their mobile device, ensuring secure and controlled access to enterprise network resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If mobile users are granted access to enterprise network resources, then user productivity and accessibility are improved, but security risks and policy violation risks increase

Engineering Contradiction:
Improveuser productivityVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a mobile access server as an intermediary component between mobile devices and enterprise network resources. This server acts as a mediator that receives requests from mobile devices, evaluates them against security policies, and grants or denies access accordingly. The intermediary architecture allows mobile users to access network resources while maintaining security control, as the server enforces policy-based access rules without requiring direct connections to internal network resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the access control function into separate components: mobile devices, mobile access server, and enterprise network resources. The mobile access server is further segmented into policy evaluation modules that independently assess each request. This segmentation allows security policies to be applied at the gateway level without affecting the internal structure of enterprise resources, enabling controlled access while maintaining security boundaries.

Inventive Principle:
Principle #1Segmentation

2Reliability

If conventional VPN technology is used for secure access, then security is improved, but device compatibility and ease of operation deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The mobile access server is designed to support multiple device types and operating systems simultaneously. It provides a universal access mechanism that works with various mobile devices (smartphones, tablets, PDAs) without requiring device-specific VPN client software. The server handles authentication and encryption centrally, making the security system universally applicable across different platforms while simplifying user operations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The mobile access server serves as an intermediary that abstracts the complexity of VPN technology from end users. Instead of requiring users to manually configure VPN connections, certificates, and encryption settings, the server provides a simplified interface that automatically handles security protocols. This intermediary layer maintains strong security while dramatically improving ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If access policies are strictly enforced, then security control is improved, but user flexibility and adaptability worsen

Engineering Contradiction:
Improvesecurity controlVSAvoiduser flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The access control system implements dynamic policy evaluation that can adapt to different contexts. Policies are not static but can be adjusted based on user identity, device type, location, time of access, and resource sensitivity. The mobile access server evaluates multiple policy rules dynamically and makes real-time decisions about access permissions, allowing flexible adaptation to various scenarios while maintaining security control.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Different security policies are applied to different resources and user contexts. Rather than enforcing a single uniform policy, the system applies localized policy rules specific to each resource type, user group, and access scenario. This allows high-security policies for sensitive resources while permitting more flexible access for less critical resources, thereby balancing security control with user flexibility.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUSRE46916E1System and method for secure management of mobile user access to enterprise network resources
Publication Date: 2018.06.26 XE2
  • USRE46916E1 patent drawing
  • USRE46916E1 patent drawing
  • USRE46916E1 patent drawing

AI summary

A system and method are provided for managing mobile user access to enterprise network resources from a wireless mobile device, such as a smart phone or mobile computer, with improved security and access control. Access rules determining accessible resources and associated permitted operations are determined based on membership of an authenticated user to each of one or more groups, each group being associated with a set of permitted accessible resources and operations. For each user, based on membership of a group, or a Boolean evaluation of memberships of two or more groups, a list of accessible resources and permitted operations is generated, and the list is made available for subsequent processes, e.g. presentation to the user on an interface of the mobile device. Access rules may also be defined dependent on other information received from the system, or from the mobile device, such as time or location. Requests for an operation such as read access or write access to a network resource, such as a file, lists, shared calendars et al., may thus be readily controlled by an IT manager for multiple users of an enterprise network. Since the application resides in an application layer between the mobile device and existing security infrastructure, mobile access may be set without overriding internal access policies.