Remote Access Connection Manager for Compliance Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a remote access environment, it is challenging for a remote application server to enforce compliance rules across client devices with varying operating systems, as some systems require specific software updates or security settings, and the process of updating client configurations to comply with server requirements can be complex.

Innovation Solution

The remote access connection manager on client devices receives compliance requirements from the server, checks the device's configuration, and either automatically or manually updates it to meet these requirements before establishing a connection, thereby enforcing compliance and restricting access to published resources based on compliance status.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the remote application server enforces compliance rules on client devices with varying operating systems, then security and policy compliance are improved, but the complexity of the enforcement process increases due to different system requirements and update procedures

Engineering Contradiction:
Improvecompliance enforcementVSAvoidenforcement process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A compliance intermediary component is introduced on the client device that acts as a mediator between the remote application server and the operating system. This intermediary receives compliance requirements from the server, translates them into OS-specific commands, and executes the necessary updates or configuration changes. This resolves the contradiction by providing a unified enforcement mechanism that adapts to different operating systems without increasing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The compliance enforcement mechanism dynamically adjusts its behavior based on the detected operating system type and version. The system changes parameters such as update commands, configuration file locations, and security policy implementation methods to match the specific OS environment. This allows consistent compliance enforcement across diverse platforms without requiring separate complex enforcement processes for each OS.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If the client device configuration is updated to comply with server requirements, then compliance status is improved, but the time required for compliance checking and remediation increases

Engineering Contradiction:
Improvecompliance statusVSAvoidcompliance check and remediation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The compliance intermediary component continuously monitors and pre-configures the client device to meet compliance requirements before actual connection attempts to the remote application server. By performing compliance checks and remediation actions in advance, the system ensures compliance status is already established when needed, eliminating time delays during critical connection moments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The compliance enforcement system is designed to automatically detect compliance gaps and execute remediation actions without requiring user intervention. The intermediary component self-manages the entire compliance process including checking current status, applying necessary updates or configuration changes, and verifying compliance achievement. This automation significantly reduces the time required for compliance remediation compared to manual processes.

Inventive Principle:
Principle #25Self-service

3Reliability

If compliance requirements are strictly enforced before connection, then security and policy adherence are improved, but user convenience deteriorates due to required user involvement in configuration updates

Engineering Contradiction:
Improvepolicy adherenceVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The compliance intermediary component is designed to autonomously handle all compliance-related tasks including detecting non-compliance conditions, executing updates, and applying configuration changes without requiring user action. The system performs self-service compliance remediation in the background, ensuring policy adherence while completely eliminating the need for user involvement in the compliance enforcement process.

Inventive Principle:
Principle #25Self-service

4Measurement precision

If the remote application server performs comprehensive compliance checks, then compliance accuracy is improved, but server load increases

Engineering Contradiction:
Improvecompliance check accuracyVSAvoidserver load
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The compliance checking function is segmented and distributed between the client device and the remote application server. The compliance intermediary component on the client device performs local compliance assessments and prepares compliance status information, then transmits only the results to the server. This segmentation maintains comprehensive compliance check accuracy while significantly reducing the processing load and energy consumption on the server compared to performing all compliance checks centrally.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10887390B1Remote access to published resources
Publication Date: 2021.01.05 PARALLELS INT GMBH
  • US10887390B1 patent drawing
  • US10887390B1 patent drawing
  • US10887390B1 patent drawing

AI summary

A remote application connection manager, executed by a processing device, transmits a remote application connection request from the processing device to a remote application server. The remote application connection manager further receives one or more access compliance conditions for the processing device from the remote application server. Also, the remote application connection manager determines whether the processing device satisfies the one or more access compliance conditions and if the processing device does not satisfy the one or more access compliance conditions, the remote application connection manager determines whether the processing device has a configuration control right to update a configuration of the processing device to satisfy the one or more access compliance conditions. If the processing device has the configuration control right, the remote application connection manager updates the configuration of the processing device. In addition, the remote application connection manager establishes a connection to the remote application server.