Remote Application Linking Infrastructure for Segmented Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large enterprises, certain users need to access specific software applications while being segregated from the rest of the corporate data network, but existing solutions fail to provide controlled access, leading to broad firewall rules and security concerns.

Innovation Solution

A remote application linking infrastructure is implemented using Citrix Presentation Server-based Windows applications, where a shortcut or 'linker' file is installed on the user's desktop, pointing to the X drive for configuration information, allowing controlled access to remote Citrix-based applications while maintaining segregation and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users are fully segregated from the corporate data network using broad firewall rules, then security is improved, but access to required software applications is lost

Engineering Contradiction:
ImprovesecurityVSAvoidaccess to software applications
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments the network into a segregated network for security-sensitive users and a non-segregated network hosting applications. Instead of broad firewall rules blocking all access, the solution creates targeted pathways through the firewall by publishing specific applications on the non-segregated network that segmented users can access without compromising overall network security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The non-segregated network acts as an intermediary layer between segmented users and the corporate data network. Applications are published on this intermediate network, allowing segmented users to access required applications without direct access to the internal corporate network, thus maintaining security while enabling application access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If applications are published on the non-segregated network for segmented users, then access to applications is improved, but security control is reduced

Engineering Contradiction:
Improveaccess to applicationsVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system applies different security qualities to different parts of the network architecture. The non-segregated network allows broader access for application hosting, while the segregated network maintains strict security controls for user workstations. This local differentiation of security policies enables both application accessibility and security control to coexist.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If dynamic enumeration of applications is implemented, then user flexibility is improved, but system complexity and administration overhead increase

Engineering Contradiction:
Improveuser flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Instead of implementing dynamic enumeration at runtime, the system performs preliminary action by pre-configuring and publishing applications on the non-segregated network before users need them. This upfront preparation eliminates the need for complex runtime discovery mechanisms, reducing system complexity while maintaining user flexibility through the published application interfaces.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8117240B1Remote application linking infrastructure
Publication Date: 2012.02.14 SOUTHERN CO SERVICES INC
  • US8117240B1 patent drawing
  • US8117240B1 patent drawing
  • US8117240B1 patent drawing

AI summary

A method, system, and computer readable medium for controlling user access from a segmented network to shared remote applications stored on a remote server. The method begins by generating a folder/file structure for a remote application that is to be shared on the segmented network. A file server drive mapping to a linking infrastructure data is generated for the remote application and an icon associated with the remote application is retrieved. An application launcher file is generated for the remote application. Then, an application linker file associated with the application launcher file for the remote application is generated. A command file is generated for copying the application linker file to a user's desktop. The linker file is updated to point to the file server drive. A folder for user access to the remote application is then deployed that includes the remote application icon, the application linker file, the application launcher file, and the command file.