Resource-Specific Secure Tunnel for Network Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing VPN technologies do not adequately ensure secure and isolated network communications between a user's device and specific resources within an organization's private network, failing to prevent access to unauthorized resources and lacking robust security measures for session management and intrusion detection.
Innovation Solution
Establishing a secure network communications tunnel that is specific to the user's device and the requested resource, with authentication and authorization mechanisms, and terminating the tunnel upon detection of security events or deviations from expected user behavior, ensuring that users can only access the intended resource and not the entire network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a VPN establishes a virtual point-to-point connection to extend private network access across public networks, then users can remotely access organization applications and network resources, but the system cannot prevent users from accessing unauthorized resources beyond their intended scope
Solution Approach 1:
The patent segments the network tunnel into resource-specific virtual channels, where each channel is dedicated to accessing a particular network resource. This segmentation prevents users from using a single VPN connection to access multiple unauthorized resources, as each resource requires its own authenticated and authorized tunnel channel.
Solution Approach 2:
The patent applies local quality by implementing resource-specific authentication and authorization policies within the tunnel system. Each resource endpoint enforces its own access control rules, ensuring that users can only access resources they are explicitly authorized for, while maintaining flexible remote access capabilities.
2Reliability
If a VPN uses encrypted layered tunneling protocol to secure network communication, then data transmission is protected from non-authorized users, but the system lacks the ability to detect and respond to security events in real-time
Solution Approach 1:
The patent implements feedback mechanisms through security agents deployed at tunnel endpoints and network resources. These agents continuously monitor traffic patterns, authentication events, and resource access attempts, providing real-time feedback to the tunnel management system. This enables dynamic detection and response to security events while maintaining encrypted communication.
Solution Approach 2:
The patent introduces intermediary security agents and monitoring components that act between the encrypted tunnel protocol and the network resources. These intermediaries detect security events without decrypting the tunnel traffic, allowing real-time security monitoring while preserving the confidentiality and integrity of encrypted communications.
3Ease of operation
If a VPN allows users to access network resources through a virtual connection, then remote work functionality is enabled, but the system cannot enforce isolation between different user sessions or terminate connections upon security threats
Solution Approach 1:
The patent implements dynamic session management where tunnel connections can be created, modified, and terminated based on real-time security conditions and user actions. Each user session receives dynamically allocated virtual channels that are automatically terminated upon security events or session completion, ensuring isolation between users while maintaining ease of remote work access.
Solution Approach 2:
The patent applies preliminary action by pre-configuring session isolation policies and threat response protocols before users establish connections. Authentication and authorization decisions are made in advance, and security agents are pre-positioned to detect and respond to threats, ensuring automatic session termination when security events occur without requiring manual intervention.
Data Source
AI summary
An approach is disclosed that receives a request from a first device connected to a first network to connect to a second device connected to a second network. In response to verifying that a connection between the first device and the second device is allowed, the approach operates to establish a secure network communications tunnel between the first device and the second device. The secure network communications tunnel is specific to the first and second devices and the first device is inhibited from accessing other devices that are connected to the second network using the secure network communications tunnel. The secure network communications tunnel is then terminated in response to a detection of a security event.


