Reverse Proxy Session Control Templates for Application Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing networked computer systems lack customized policy enforcement for specific applications, leading to inefficient and inflexible monitoring and control of user activities, as predefined policy rules do not account for unique requirements of line-of-business (LOB) applications.
Innovation Solution
Implementing a reverse proxy service that applies custom session control templates to client requests, allowing administrators to create and deploy application-specific policies via an integrated development environment (IDE), which are then enforced by a forward proxy service to determine permitted or restricted actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If predefined policy rules are used for monitoring user activities, then the proxy service can enforce basic security policies, but the system lacks adaptability to specific application requirements
Solution Approach 1:
The patent segments the policy management system into modular session control templates, each designed for specific applications or protocols. These templates can be independently configured, deployed, and managed, allowing the system to adapt to different application requirements without requiring complete policy reconfiguration. Each template handles specific monitoring and control rules for particular applications, enabling granular adaptability.
Solution Approach 2:
The system implements dynamic policy management through session control templates that can be created, modified, deployed, and activated at runtime. Administrators can dynamically add new templates for emerging applications or modify existing ones to adapt to changing requirements. The proxy service dynamically selects and applies appropriate templates based on the specific application being accessed, enabling the system to evolve and adapt without downtime.
2Adaptability or versatility
If custom session control templates are created and deployed for each application, then the system achieves high adaptability to specific application requirements, but the device complexity increases
Solution Approach 1:
The patent implements self-service capabilities through an integrated development environment (IDE) that enables administrators to independently create, test, validate, and deploy session control templates without requiring vendor support or complex configuration procedures. The IDE provides automated template generation, syntax validation, and testing facilities, allowing administrators to self-configure application-specific policies. This self-service approach reduces the operational complexity of managing custom templates while maintaining high adaptability.
3Reliability
If comprehensive monitoring and control is implemented for all client requests, then security is improved, but the processing time and system overhead increase
Solution Approach 1:
The patent applies partial monitoring and control by selectively applying session control templates based on the specific application, protocol, and user context. Rather than uniformly monitoring all client requests with the same level of scrutiny, the system applies appropriate monitoring depth and control measures only where necessary. The proxy service evaluates each request against relevant template criteria and applies control actions only when policy violations are detected, reducing unnecessary processing overhead while maintaining security.
4Ease of operation
If predefined policy rules are used, then the system is easy to operate, but it cannot be customized for specific applications
Solution Approach 1:
The patent introduces session control templates as intermediary components between the proxy service and application-specific requirements. These templates serve as pre-configured policy packages that encapsulate application-specific monitoring and control rules. Administrators can deploy templates as intermediaries to enforce application-specific policies without directly configuring complex proxy service parameters. The templates act as mediators that translate high-level policy requirements into actionable monitoring and control rules, simplifying operations while enabling customization.
Data Source
AI summary
A computer-implemented method includes receiving, by a reverse proxy device, a session control template, and a client request directed to a service provider regarding an application. The method includes determining, by the reverse proxy device, whether the client request should be allowed or blocked based on the received session control template. If the reverse proxy device determines that the client request should be allowed, the client request is forwarded from the reverse proxy device to the service provider. If the reverse proxy device determines that the client request should be blocked, the client request is blocked from proceeding to the service provider.


