Resource-Specific Secure Tunnel for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VPN technologies do not adequately ensure secure and isolated network communications between a user's device and specific resources within an organization's private network, failing to prevent access to unauthorized resources and lacking robust security measures for session management and intrusion detection.

Innovation Solution

Establishing a secure network communications tunnel that is specific to the user's device and the requested resource, with authentication and authorization mechanisms, and terminating the tunnel upon detection of security events or deviations from expected user behavior, ensuring that users can only access the intended resource and not the entire network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a VPN establishes a virtual point-to-point connection to extend private network access across public networks, then users can remotely access organization applications and network resources, but the system cannot prevent users from accessing unauthorized resources beyond their intended scope

Engineering Contradiction:
Improveremote access capabilityVSAvoidunauthorized resource access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network tunnel into resource-specific virtual channels, where each channel is dedicated to accessing a particular network resource. This segmentation prevents users from using a single VPN connection to access multiple unauthorized resources, as each resource requires its own authenticated and authorized tunnel channel.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by implementing resource-specific authentication and authorization policies within the tunnel system. Each resource endpoint enforces its own access control rules, ensuring that users can only access resources they are explicitly authorized for, while maintaining flexible remote access capabilities.

Inventive Principle:
Principle #3Local quality

2Reliability

If a VPN uses encrypted layered tunneling protocol to secure network communication, then data transmission is protected from non-authorized users, but the system lacks the ability to detect and respond to security events in real-time

Engineering Contradiction:
Improvedata transmission securityVSAvoidsecurity event detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback mechanisms through security agents deployed at tunnel endpoints and network resources. These agents continuously monitor traffic patterns, authentication events, and resource access attempts, providing real-time feedback to the tunnel management system. This enables dynamic detection and response to security events while maintaining encrypted communication.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces intermediary security agents and monitoring components that act between the encrypted tunnel protocol and the network resources. These intermediaries detect security events without decrypting the tunnel traffic, allowing real-time security monitoring while preserving the confidentiality and integrity of encrypted communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If a VPN allows users to access network resources through a virtual connection, then remote work functionality is enabled, but the system cannot enforce isolation between different user sessions or terminate connections upon security threats

Engineering Contradiction:
Improveremote work functionalityVSAvoidsession isolation and threat response
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic session management where tunnel connections can be created, modified, and terminated based on real-time security conditions and user actions. Each user session receives dynamically allocated virtual channels that are automatically terminated upon security events or session completion, ensuring isolation between users while maintaining ease of remote work access.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies preliminary action by pre-configuring session isolation policies and threat response protocols before users establish connections. Authentication and authorization decisions are made in advance, and security agents are pre-positioned to detect and respond to threats, ensuring automatic session termination when security events occur without requiring manual intervention.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11206242B2Secure communication tunnels specific to network resource
Publication Date: 2021.12.21 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11206242B2 patent drawing
  • US11206242B2 patent drawing
  • US11206242B2 patent drawing

AI summary

An approach is disclosed that receives a request from a first device connected to a first network to connect to a second device connected to a second network. In response to verifying that a connection between the first device and the second device is allowed, the approach operates to establish a secure network communications tunnel between the first device and the second device. The secure network communications tunnel is specific to the first and second devices and the first device is inhibited from accessing other devices that are connected to the second network using the secure network communications tunnel. The secure network communications tunnel is then terminated in response to a detection of a security event.