Perimeter Access Policy Manager for Cross-Resource Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems lack effective methods for managing cross-perimeter access to resources on a device, where multiple logical perimeters isolate computer resources, preventing access between them, and existing solutions do not provide seamless control over data and network access across perimeters.
Innovation Solution
A system that enables cross-perimeter access by defining and applying policies to each perimeter, allowing specific resources to be accessed by internal or external applications, with conflict resolution mechanisms that default to the strictest policy, ensuring controlled access and seamless user experience.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple logical perimeters isolate computer resources to maintain security, then security control is improved, but access control flexibility deteriorates
Solution Approach 1:
The patent introduces a perimeter access policy manager as an intermediary component that mediates between isolated perimeters. This manager evaluates access requests against defined policies and grants controlled access between perimeters, thereby maintaining security isolation while enabling flexible access when authorized. The intermediary resolves the contradiction by allowing cross-perimeter access without compromising the fundamental security boundaries.
2Reliability
If strict perimeter isolation is enforced to protect resources, then security is improved, but user experience deteriorates
Solution Approach 1:
The patent implements dynamic access control where perimeter isolation is not rigid but adaptable based on policy evaluation. The system dynamically determines whether to grant or deny access requests by evaluating policies in real-time, allowing strict isolation when security requires it while permitting seamless access when user needs arise. This dynamic approach resolves the contradiction by making security enforcement flexible rather than static.
Solution Approach 2:
The system performs preliminary policy evaluation and conflict resolution before actual access requests occur. By pre-defining access policies and establishing conflict resolution rules (such as defaulting to the strictest policy), the system prepares access decisions in advance, enabling fast, seamless user experience when access is permitted while maintaining security when isolation is required.
3Adaptability or versatility
If cross-perimeter access is enabled for resource sharing, then access flexibility is improved, but security control deteriorates
Solution Approach 1:
The patent applies local quality by allowing different access policies for different perimeters and resources. Each perimeter can have customized access rules defined in its policy, enabling flexible access where needed while maintaining strict control where security requires it. This localized policy application resolves the contradiction by making security control granular rather than uniform across all perimeters.
Solution Approach 2:
The perimeter access policy manager implements feedback by continuously evaluating access requests against defined policies and adjusting access decisions based on policy compliance. The system monitors cross-perimeter access attempts and enforces security rules dynamically, providing feedback control that maintains security while enabling flexibility. This feedback mechanism ensures that access flexibility does not compromise security control.
4Manufacturing precision
If multiple policies are applied to different perimeters for fine-grained control, then policy precision is improved, but system complexity deteriorates
Solution Approach 1:
The patent extracts the complexity of policy management by separating policy definition from policy enforcement. The perimeter access policy manager handles the complex task of policy evaluation and conflict resolution, while individual perimeters simply implement their specific access policies. This extraction of management complexity resolves the contradiction by allowing precise policies without proportionally increasing overall system complexity.
Data Source
AI summary
In some implementations, a method of managing access to resources in a single device including receiving, from a first resource assigned to a first perimeter, a request to access a second resource assigned to a second perimeter different from the first perimeter. The single device includes the first perimeter and the second perimeter. Whether access to the second resource is prohibited is determined based on a management policy for the first perimeter. The management policy defining one or more rules for accessing resources assigned to the second perimeter including the second resource.


