Proxy Server Navigation Security Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital workspace solutions face challenges in enforcing access policies across all electronic resources, particularly when users access insecure resources using unmanaged applications or browsers, as organizations are unable to apply security controls effectively outside their managed environments.
Innovation Solution
A method and system that monitor navigation attempts on client devices, determine if they are insecure based on predefined policies, and modify the navigation to prevent access to insecure resources by replacing the address with a safe one or launching a managed application, ensuring security policies are enforced.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If organizations provide managed applications to enforce access policies, then security control is improved, but user convenience deteriorates because users cannot access insecure resources using native browsers even within the organization's network
Solution Approach 1:
The patent introduces a proxy server as an intermediary component that sits between users and electronic resources. This proxy server intercepts navigation attempts, applies security policies, and mediates the access decision. When a user attempts to access a resource through a native browser, the proxy server checks whether the resource is allowed and whether the user should be redirected to a managed application, thus resolving the contradiction between security control and user convenience
Solution Approach 2:
The system implements feedback mechanisms where the proxy server monitors navigation attempts and provides feedback to users through error notifications or redirections. This feedback loop allows the organization to maintain security control while informing users of policy violations, enabling users to understand why certain access attempts were blocked and guiding them to appropriate managed applications
2Reliability
If organizations use proxies to monitor and manage navigation, then access policy enforcement is improved, but user privacy and security concerns worsen because personal network traffic must go through monitored proxies
Solution Approach 1:
The patent applies local quality by differentiating between types of traffic handling. The proxy server applies strict monitoring and policy enforcement to organizational resources while maintaining different behaviors for personal resource access. This allows selective enforcement where security policies are applied where needed without unnecessarily monitoring all personal traffic, thus addressing privacy concerns while maintaining access policy enforcement
3Reliability
If organizations block navigation to insecure resources using access policies, then security is improved, but user productivity deteriorates because legitimate access attempts are also blocked causing inconvenience
Solution Approach 1:
The system implements dynamic access control where the proxy server continuously evaluates navigation attempts based on current security policies, resource types, and user contexts. This dynamic evaluation allows the system to adaptively block only truly insecure resources while permitting legitimate access attempts, thus maintaining security while minimizing impact on user productivity through overly restrictive policies
Data Source
AI summary
In one aspect, an illustrative methodology implementing the disclosed techniques includes, by a computing device, receiving input via an application of the computing device, the input to initiate navigation to an electronic resource, and determining that navigation to the electronic resource via the application is insecure. The method also includes, by the computing device, responsive to the determination that the navigation is insecure, modifying the navigation to the electronic resource so as to prevent navigation to the electronic resource via the application.


