Network Access Client for Seamless Location-Aware Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Employees face complexity in accessing corporate networks from various locations due to different access methods and authentication requirements, which can vary based on location, device health, and security state, making seamless connectivity challenging.

Innovation Solution

A technology that automatically detects the user's need for network access, determines location-specific connection methods, and attempts to establish a connection using available methods, with credentials being stored and retrieved for seamless authentication, reverting to less secure methods if necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple access methods are provided for different locations, then network security and location-specific access control are improved, but user operation complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoiduser operation complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically determines the user's current location, selects the appropriate access method, and configures connection parameters without user intervention. The client device self-services by autonomously navigating through different access methods (IPSec VPN, SSL VPN, Web Publishing, etc.) based on location context, eliminating the need for users to manually select or remember multiple access procedures while maintaining security policies.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically changes connection parameters including access method selection, authentication credentials, and network configuration based on the determined user location. When location changes from corporate premises to remote location, the system automatically adjusts the access method and associated parameters to match the appropriate security and connectivity requirements for that location.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If automatic connection attempts are made across multiple methods, then connectivity reliability is improved, but system complexity increases

Engineering Contradiction:
Improveconnectivity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system pre-configures multiple access methods and their associated parameters in a predetermined hierarchy before connection is needed. The client device stores and organizes multiple access methods (IPSec VPN, SSL VPN, Web Publishing, Terminal Service Gateway) with their respective credentials and configuration parameters, ready for automatic selection and execution without requiring complex real-time decision-making logic during the connection attempt.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If location-based access control is implemented, then network security is improved, but ease of access deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidease of access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The client device automatically performs location determination and access method selection without requiring user awareness or manual configuration. The system self-services by autonomously querying location information, comparing it against stored location profiles, and selecting the appropriate access method according to security policies, thereby maintaining strict location-based access control while providing seamless user experience.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements a universal access client that can handle multiple access methods (IPSec VPN, SSL VPN, Web Publishing, Terminal Service Gateway) through a single unified interface. This multi-functional client eliminates the need for separate access tools for different locations, allowing users to access the network from any location using a single application that automatically adapts to the appropriate access method based on location context.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2294868B1Seamless location aware network connectivity
Publication Date: 2019.11.06 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP2294868B1 patent drawingFigure 1
  • EP2294868B1 patent drawingFigure 2
  • EP2294868B1 patent drawingFigure 3

AI summary

Described is a technology by which a seamless automatic connection to an (e.g., corporate) network is made for a client device. Upon detecting a need for a connection to a network, such as by intercepting a communication directed towards a network destination, a list of available connection methods is automatically obtained based on the device's current location data (e.g., LAN or remote) and policy information. An available connection method from the list is selected, e.g., in order, and an attempt is made to establish a connection via that connection method. If the attempt fails, another attempt is made with a different connection method, and so on, until a connection method succeeds. Additional seamlessness from the user's perspective is provided via a credentials vault, by which stored credentials may be retrieved and used in association with the access method being attempted.