Network Intermediary for Remote Access Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In remote access environments, it is challenging for administrators to control access to resources hosted on external servers, as they lack control over external hosts and cannot ensure that all client devices have restricted access to application features.
Innovation Solution
A network device, such as an application delivery controller, is used to intercept and modify ICA protocol communications between clients and servers, applying policies to control access by disabling specific features or channels, thereby ensuring secure and managed access to remote applications or desktops.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a network device intercepts and modifies ICA protocol communications to control access, then access control and security are improved, but device complexity increases
Solution Approach 1:
The patent introduces a network device (such as an application delivery controller) as an intermediary between clients and external servers. This device intercepts ICA protocol communications, applies access control policies, and modifies the protocol streams accordingly. By placing the control logic in this intermediate device rather than requiring modifications to client or server endpoints, the system achieves reliable access control while keeping individual components relatively simple.
2Ease of operation
If access control policies are applied at a centralized network device, then manageability is improved, but the network path becomes more complex
Solution Approach 1:
The network device serves as a centralized intermediary that handles all access control decisions. Policies are defined and applied at this single point in the network path, allowing administrators to manage access centrally without needing to configure multiple distributed systems. The device inspects ICA protocol streams, evaluates policies based on client characteristics, and modifies connections accordingly.
Solution Approach 2:
The system performs preliminary actions by evaluating access control policies during the connection establishment phase or early in the ICA protocol stream. The network device can disable specific channels or features before they are fully utilized, preventing unauthorized access without requiring ongoing complex management throughout the entire session.
3Manufacturing precision
If the network device inspects and modifies ICA protocol streams, then access control precision is improved, but processing time increases
Solution Approach 1:
The network device performs access control decisions during the connection setup phase or at the beginning of the ICA protocol stream, before significant data transfer occurs. By making access control determinations early (such as disabling specific channels during capability negotiation), the system achieves precise access control without requiring extensive processing time during the actual application execution phase.
Solution Approach 2:
The system applies access control by selectively modifying only the necessary portions of the ICA protocol stream rather than processing every detail thoroughly. The network device can disable specific channels or features based on policy without needing to inspect or modify every individual packet, achieving sufficient precision for access control with reduced processing overhead.
Data Source
AI summary
The present disclosure is directed to systems and methods for controlling delivery of a resource. An intermediary device may establish a connection to deliver a resource hosted on at least one server to a client using a remoting protocol. The remoting protocol may define one or more channels in the connection for delivering or enabling one or more features of the resource to the client. The device may identify the one or more channels, and may identify the one or more features of the resource. The device may determine a policy for controlling access of the client to at least a first feature of the resource. The device may control access of the client to the first feature by modifying a first channel of the one or more channels according to the determined policy.


