Network Resource Access Portal Isolating Users from Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network architectures face issues with unchecked and unmanaged user requests and responses, leading to data leakages, attacks, and security risks due to direct access to network applications, which can result in business losses and vulnerabilities.

Innovation Solution

A network resource access system comprising a user portal and a resource portal that isolate users from network resources by processing and filtering access requests and responses through multiple stages, ensuring only valid and secure information is transmitted, thereby reducing unnecessary information disclosure and security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users directly access network applications, then ease of operation is improved, but security reliability deteriorates due to unmanaged requests and information leakage

Engineering Contradiction:
Improveuser access convenienceVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a portal system as an intermediary between users and network applications. The portal receives user requests, performs security checks, manages access permissions, and filters information before forwarding to network applications. This mediator architecture maintains user access convenience while ensuring security through centralized request management and information filtering.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the access architecture into distinct layers: user terminal, portal system, and network application. By dividing the monolithic access path into separate functional segments, the patent enables independent security management at the portal layer without affecting user convenience or application functionality.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If network applications expose detailed information to users, then adaptability is improved, but harmful factors increase due to information collection for malicious purposes

Engineering Contradiction:
Improveinformation accessibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The portal acts as an information intermediary that selectively filters and manages data flow between network applications and users. It provides necessary information for user operations while blocking sensitive data that could be misused, thus balancing information accessibility with security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies different information disclosure policies to different types of information. Sensitive information is restricted or anonymized, while non-sensitive operational information is freely provided. This local quality differentiation allows the system to maintain adaptability for legitimate operations while reducing harmful factors through selective information control.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11632376B2Network resource access system and method, user portal and resource portal
Publication Date: 2023.04.18 HANGZHOU JINDOUTENGYUN TECH CO LTD
  • US11632376B2 patent drawing
  • US11632376B2 patent drawing
  • US11632376B2 patent drawing

AI summary

The invention relates to the technical field of network security, in particular to a network resource access system and method, a user portal, and a resource portal to isolate users from network resources to reduce unnecessary information disclosure, thus reducing security risks. According to the technical solution, the resource portal acquires resource information associated with the resource portal according to a configuration from an administrator or from a third party, as well as a list of user portals capable of communicating with the resource portal, receives a second access request sent from a user portal in the list of user portals, generates a third access request according to the second access request, and then sends the third access request to a target network resource server.