Network Intermediary for Remote Access Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In remote access environments, it is challenging for administrators to control access to resources hosted on external servers, as they lack control over external hosts and cannot ensure that all client devices have restricted access to application features.

Innovation Solution

A network device, such as an application delivery controller, is used to intercept and modify ICA protocol communications between clients and servers, applying policies to control access by disabling specific features or channels, thereby ensuring secure and managed access to remote applications or desktops.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a network device intercepts and modifies ICA protocol communications to control access, then access control and security are improved, but device complexity increases

Engineering Contradiction:
Improveaccess controlVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network device (such as an application delivery controller) as an intermediary between clients and external servers. This device intercepts ICA protocol communications, applies access control policies, and modifies the protocol streams accordingly. By placing the control logic in this intermediate device rather than requiring modifications to client or server endpoints, the system achieves reliable access control while keeping individual components relatively simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If access control policies are applied at a centralized network device, then manageability is improved, but the network path becomes more complex

Engineering Contradiction:
ImprovemanageabilityVSAvoidnetwork path complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The network device serves as a centralized intermediary that handles all access control decisions. Policies are defined and applied at this single point in the network path, allowing administrators to manage access centrally without needing to configure multiple distributed systems. The device inspects ICA protocol streams, evaluates policies based on client characteristics, and modifies connections accordingly.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by evaluating access control policies during the connection establishment phase or early in the ICA protocol stream. The network device can disable specific channels or features before they are fully utilized, preventing unauthorized access without requiring ongoing complex management throughout the entire session.

Inventive Principle:
Principle #10Preliminary action

3Manufacturing precision

If the network device inspects and modifies ICA protocol streams, then access control precision is improved, but processing time increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidprocessing time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The network device performs access control decisions during the connection setup phase or at the beginning of the ICA protocol stream, before significant data transfer occurs. By making access control determinations early (such as disabling specific channels during capability negotiation), the system achieves precise access control without requiring extensive processing time during the actual application execution phase.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies access control by selectively modifying only the necessary portions of the ICA protocol stream rather than processing every detail thoroughly. The network device can disable specific channels or features based on policy without needing to inspect or modify every individual packet, achieving sufficient precision for access control with reduced processing overhead.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10476969B2Systems and methods for network controlled access of resources
Publication Date: 2019.11.12 CITRIX SYSTEMS INC
  • US10476969B2 patent drawing
  • US10476969B2 patent drawing
  • US10476969B2 patent drawing

AI summary

The present disclosure is directed to systems and methods for controlling delivery of a resource. An intermediary device may establish a connection to deliver a resource hosted on at least one server to a client using a remoting protocol. The remoting protocol may define one or more channels in the connection for delivering or enabling one or more features of the resource to the client. The device may identify the one or more channels, and may identify the one or more features of the resource. The device may determine a policy for controlling access of the client to at least a first feature of the resource. The device may control access of the client to the first feature by modifying a first channel of the one or more channels according to the determined policy.