Policy-Controlled Communication System for Secure Session Protocol Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in securing communication sessions due to obsolete encryption protocols, weak links, and the inability to enforce encryption rules on unmanaged devices, leading to compromised content and financial losses.

Innovation Solution

A policy-controlled communication system that customizes encryption protocols based on parameters, using a mid-link server to determine and modify encryption links and select session protocols for secure sessions between client devices and web servers, ensuring compliance with specified policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If group policy is used to enforce encryption rules on managed endpoints, then encryption security is improved, but the ability to enforce rules on unmanaged devices is lost

Engineering Contradiction:
Improveencryption securityVSAvoidcoverage of unmanaged devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a gateway server as an intermediary component that mediates between cloud services and client devices. This gateway enforces encryption policies for connections from unmanaged devices, which cannot be controlled through traditional group policies. The gateway acts as a policy enforcement point that intercepts and secures communications regardless of the client device's management status, thereby extending encryption coverage to unmanaged devices while maintaining security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If default encryption settings are used, then ease of operation is improved, but vulnerability to obsolete protocols increases

Engineering Contradiction:
Improvedefault configurationVSAvoidsecurity against obsolete protocols
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic protocol selection and policy enforcement rather than static default settings. The system dynamically evaluates connection requests, selects appropriate encryption protocols based on current security requirements and protocol availability, and enforces policies in real-time. This dynamic approach allows the system to adapt to evolving security threats and protocol obsolescence while maintaining ease of operation through automated decision-making.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The gateway server incorporates feedback mechanisms that monitor encryption protocol usage, security posture, and connection outcomes. Based on this feedback, the system adjusts policy enforcement and protocol selection to prevent reliance on obsolete protocols. The feedback loop ensures that default settings automatically evolve to maintain security without requiring manual intervention, thus preserving ease of operation while improving reliability.

Inventive Principle:
Principle #23Feedback

3Reliability

If encryption protocols are updated to address security vulnerabilities, then security is improved, but compatibility with legacy systems may deteriorate

Engineering Contradiction:
Improvesecurity against vulnerabilitiesVSAvoidcompatibility with legacy systems
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the encryption protocol enforcement into multiple layers: the gateway server handles policy enforcement and protocol negotiation, while client devices and cloud services maintain their native protocol capabilities. This segmentation allows legacy systems to continue using older protocols where necessary while the gateway enforces modern security requirements for new connections. The segmented architecture enables gradual migration and maintains compatibility without compromising security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes encryption protocol parameters dynamically based on the capabilities of connecting systems. When connecting to legacy systems, the gateway negotiates appropriate protocol versions and security parameters that maintain compatibility while incorporating modern security enhancements where possible. This parameter adaptation allows the system to enforce updated security standards without completely breaking compatibility with legacy infrastructure.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11882125B2Selection of session protocol based on policies
Publication Date: 2024.01.23 NETSKOPE INC
  • US11882125B2 patent drawing
  • US11882125B2 patent drawing
  • US11882125B2 patent drawing

AI summary

A policy-controlled communication system including a plurality of client devices establishing a secure session with remote instances on a web server using a protocol. The system includes a policy component with a set of policies customized based on parameters. The policies specify configuration settings of encryption protocols for content security on a client device. A local application on the client device selects a cloud service. A mid-link server includes a security developer to determine an encryption link to deliver the cloud service to the client device and a linker to select a session protocol for establishing the secure session between the client device and the web server based on the set of policies. The policies are modified when the encryption link does not meet the set of policies. The router establishes via the encryption link the secure session based on the session protocol and the modified policies.