Network Appliance External User Identity Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for restricting user access to external resources, such as firewalls, often hinder legitimate activities by not distinguishing between different external user accounts, leading to unnecessary restrictions on employees' access to websites and services.
Innovation Solution
A data appliance that identifies external user accounts and enforces policies based on these identities, allowing for differentiated access rules, such as allowing access through corporate accounts while restricting personal accounts, using a process that involves packet processing, application identification, and policy enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firewalls are used to prevent users from accessing external resources, then security is improved, but legitimate activities are hindered
Solution Approach 1:
The patent segments users into different categories (internal users, external users, authenticated users, anonymous users) and applies different access policies to each segment. This allows the firewall to restrict anonymous access while permitting authenticated users to access external resources legitimately, thus maintaining security without hindering legitimate activities.
Solution Approach 2:
The patent implements local quality by applying different access control policies to different user types and different external resources. Internal users accessing corporate resources receive different treatment than external users accessing public resources, allowing fine-grained control that preserves legitimate access while maintaining security.
2Reliability
If all access to specific websites is prohibited for all users, then security is improved, but employee productivity deteriorates
Solution Approach 1:
The patent implements dynamic access control where permissions are not static but change based on user authentication status and identity. Users can dynamically transition from restricted anonymous access to permitted authenticated access, allowing employees to access necessary external resources for productivity while maintaining security through conditional policies.
Solution Approach 2:
The patent changes the parameter of user identity from unknown to known through authentication. By detecting and identifying user identities, the system changes access parameters from restrictive (anonymous) to permissive (authenticated), enabling employees to access external resources needed for productivity while maintaining security through identity-based controls.
3Adaptability or versatility
If external user accounts are identified and differentiated policies are enforced, then access control flexibility is improved, but device complexity increases
Solution Approach 1:
The patent implements self-service by having the system automatically detect, identify, and authenticate user identities without manual intervention. The firewall automatically determines user categories and applies appropriate policies, reducing the need for complex manual configuration while maintaining high access control flexibility through automated identity-based decisions.
Data Source
AI summary
Techniques for identifying external user names and enforcing policies are disclosed. A request is received from a first client device within a first network to access an external application that is outside of the first network. An identification of an external user account associated with the received request is identified. A determination is made, based at least in part on the identification, of a policy to apply to the request. The policy is applied.


