Remote Access Policy Engine for Session Reconnection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods fail to provide smooth reconnection of users to authorized application sessions when access control decisions change due to shifts in computing environments, leading to potential loss of work and unauthorized session maintenance.

Innovation Solution

A method and apparatus that utilize a policy engine with a collection agent to gather user information, identify associated application sessions, and reconnect the user only to authorized sessions by applying access control policies and conditions, ensuring secure and seamless access across different environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing remote access methods are used, then users can access application sessions, but users cannot smoothly reconnect to authorized sessions when access control decisions change due to environment shifts

Engineering Contradiction:
Improvesession reconnection reliabilityVSAvoidadaptability to environment changes
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically evaluates access control decisions by detecting shifts in computing environments and recalculating authorization status. The policy engine continuously monitors environmental changes and adapts session accessibility in real-time, transforming static access control into a dynamic system that responds to environmental variations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms where the policy engine receives information about environmental changes and user context, evaluates access control policies, and sends decisions back to the session management system. This closed-loop feedback ensures that session reconnection rights are continuously adjusted based on current conditions.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If users are automatically reconnected to previous sessions, then reconnection is seamless, but unauthorized sessions may be maintained

Engineering Contradiction:
Improvereconnection easeVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary evaluation of access control decisions before granting session reconnection rights. The policy engine assesses user context, environmental factors, and session authorization status in advance of the reconnection attempt, ensuring that only authorized sessions are restored while maintaining operational simplicity for legitimate users.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If access control policies are strictly enforced, then security is improved, but smooth reconnection to authorized sessions is prevented

Engineering Contradiction:
Improveaccess control securityVSAvoidsession restoration efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system changes parameters of access control evaluation by considering multiple contextual factors including user role, environmental trust level, session importance, and time-based policies. These parameter variations enable flexible security enforcement that can permit smooth reconnection for authorized users while maintaining strict security controls where needed.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8613048B2Method and apparatus for providing authorized remote access to application sessions
Publication Date: 2013.12.17 CITRIX SYSTEMS INC
  • US8613048B2 patent drawing
  • US8613048B2 patent drawing
  • US8613048B2 patent drawing

AI summary

A method and apparatus for providing authorized remote access to one or more application sessions includes a client node, a collection agent, a policy engine, and a session server. The client node requests access to a resource. The collection agent gathers information about the client node. The policy engine receives the gathered information, and makes an access control decision based on the received information. The session server establishes a connection between a client computer operated by the user and the one or more application sessions associated with the user of the client node identified in response to the received information.