Proxy Server Device-Level Access Control for Cloud Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based network environments lack the configurability and customization necessary to effectively control access to enterprise resources at a device level, often allowing unqualified devices to access sensitive information despite proper user-level access controls.

Innovation Solution

A system comprising a proxy server and a compliance server that authenticate and authorize devices based on device identifiers and access credentials, ensuring compliance with defined hardware, software, and device management restrictions, thereby controlling access to enterprise resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud-based network environments are used to host enterprise resources, then accessibility and scalability are improved, but device-level access control capability deteriorates

Engineering Contradiction:
ImproveaccessibilityVSAvoiddevice-level access control
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway device as an intermediary between cloud-based enterprise resources and user devices. This gateway maintains device-level access control capabilities by authenticating devices and managing access policies, while the actual enterprise resources remain hosted in the cloud. The gateway acts as a mediator that preserves security control without requiring enterprises to manage complex cloud infrastructure themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If device-level access control is implemented, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway device serves as a specialized intermediary that handles all device-level authentication and access control logic centrally. This concentrates the complexity in a single managed component rather than distributing it across multiple cloud services or client devices. The gateway maintains device identifiers, authentication credentials, and access policies, simplifying the overall system architecture while ensuring security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the access control function into distinct layers: device-level authentication handled by the gateway, user-level authentication handled separately, and resource access policies enforced at the gateway. This segmentation allows each component to focus on specific security tasks, reducing overall system complexity while maintaining comprehensive security control.

Inventive Principle:
Principle #1Segmentation

3Ease of manufacture

If cloud-based data services are used, then ease of deployment is improved, but configurability for access control deteriorates

Engineering Contradiction:
Improveease of deploymentVSAvoidconfigurability
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The gateway device provides a configurable interface between cloud services and enterprise security requirements. It can be configured with custom device identifiers, authentication methods, and access policies tailored to specific enterprise needs. The gateway maintains configurability for access control while allowing cloud-based services to be deployed easily, as the gateway handles the customization layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9769266B2Controlling access to resources on a network
Publication Date: 2017.09.19 OMNISSA LLC
  • US9769266B2 patent drawing
  • US9769266B2 patent drawing
  • US9769266B2 patent drawing

AI summary

Control of access to resources on a network may be provided. A request to access enterprise resource(s), the request comprising a set of user access credentials and a device identifier, may be generated. The request to access the at least one enterprise resource and an updated device profile may be provided to an authorization service. A set of enterprise access credentials may be received from the authorization service and used to generate a second request to access the enterprise resource(s).