Remote Access System with Mid-Link Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As employees work remotely, maintaining security and control over diverse devices and software environments becomes challenging, especially with bring your own device policies in place, where unique systems and software builds introduce numerous risk factors that IT staff struggle to manage.

Innovation Solution

A remote access system that enforces policy-controlled computing by using a client device connected to a remote software environment. This system includes a local application with first policies, a mid-link server with second policies updated for each client device, and a mirror function that emulates sensor input as if it is happening inside the remote software environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If employees work remotely with bring your own device policies allowing diverse platforms and operating systems, then employee flexibility and work-from-home capability are improved, but security control and risk management deteriorate

Engineering Contradiction:
Improvedevice compatibilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a remote access server as an intermediary between employees and enterprise resources. This server provides a standardized, secure interface that all diverse devices must connect through, thereby maintaining security control while allowing device flexibility. The intermediary abstracts the underlying device diversity from the enterprise network, presenting a uniform access point for all users regardless of their platform or operating system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the access control into multiple layers: device-level policies, user-level policies, and resource-level policies. This segmentation allows the enterprise to apply different security rules to different devices, users, and resources independently. By dividing the monolithic security control into manageable segments, the system can accommodate diverse devices while maintaining granular security oversight through policy enforcement at each segment.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple unique systems and software builds are supported to enable device diversity, then adaptability is improved, but IT staff ability to keep ahead of threats deteriorates

Engineering Contradiction:
Improvesoftware compatibilityVSAvoidsystem management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The remote access server provides universal functionality by supporting multiple platforms, operating systems, and software builds through a single unified interface. Rather than requiring separate management systems for each platform, the server implements a universal policy enforcement mechanism that works across all device types. This multi-functional approach allows the enterprise to support diverse software environments while managing security through a single centralized system, reducing the burden on IT staff.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system creates virtual copies of the enterprise environment within the remote access server. Instead of managing security on each unique device, the server maintains a standardized virtual representation of enterprise resources and policies. This copying approach allows IT staff to manage security against a single set of standardized images or virtual environments, rather than attempting to secure each unique device configuration individually.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20250126099A1Policy-based remote access system with periodic authentication
Publication Date: 2025.04.17 NETSKOPE INC
  • US20250126099A1 patent drawing
  • US20250126099A1 patent drawing
  • US20250126099A1 patent drawing

AI summary

A remote access system for policy-controlled computing with a client device connected to a remote software environment is disclosed. The client device communicates with the remote software environment that securely runs applications. Restrictions for a local application that runs on the client device are enforced using a first plurality of policies. A mid-link server enforces restrictions on the remote software environment using a second plurality of policies. An authentication function that perform periodic authentication of the client device for continued authorization to access a remote instance associated with the remote software environment. A mirror function that emulates sensor input from the client device as if it is happening inside the remote software environment.