Sandboxed Virtual Workspaces for Context-Based Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional access control paradigms in computer networks result in inefficient and privileged access management, leading to loopholes where users can access resources they are not entitled to, and lack context-based entitlement governance.

Innovation Solution

Implementing a context-based access control system that generates isolated virtual computing environments with specific entitlements, sandboxing them from others, and allowing access based on these entitlements to manage network resources efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If traditional access control assigns entitlements directly to users, then implementation is simple and straightforward, but access management becomes inefficient and creates security loopholes

Engineering Contradiction:
Improveease of implementationVSAvoidaccess management efficiency
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The patent introduces a virtual computing environment as an intermediary layer between users and network resources. Instead of directly assigning entitlements to users, the system creates virtual environments that act as mediators, each with their own sandboxed entitlements. This resolves the contradiction by maintaining implementation simplicity while dramatically improving access management efficiency through automated provisioning and context-based access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the access control system by creating multiple isolated virtual computing environments, each with its own entitlements and context. This segmentation allows independent management of access rights without affecting other users or resources, thereby improving overall access management efficiency while keeping each segment's implementation straightforward.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If traditional access control provisions access to each user individually, then entitlement assignment is straightforward, but provisioning time increases and friction increases

Engineering Contradiction:
Improveentitlement assignment simplicityVSAvoidprovisioning time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent merges multiple user entitlements into a single virtual computing environment. Instead of provisioning access to each user individually, the system creates one virtual environment that consolidates the necessary entitlements, thereby reducing provisioning time and friction while maintaining ease of operation through centralized management.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary actions by pre-configuring virtual computing environments with necessary entitlements before users need access. This advance preparation eliminates the time-consuming individual provisioning process while keeping the user experience simple through automated, context-based access granting.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If users have access to multiple network resources, then users can perform diverse tasks, but security loopholes arise where users can access resources they are not entitled to

Engineering Contradiction:
Improvetask diversity capabilityVSAvoidaccess control security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by creating sandboxed virtual computing environments where each environment has its own specific entitlements tailored to particular tasks. This allows users to perform diverse tasks through different virtual environments with appropriate access rights, while preventing unauthorized access to resources outside each environment's specific entitlement scope, thereby maintaining both versatility and security.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The virtual computing environment acts as an intermediary that enables task diversity while enforcing security boundaries. Each virtual environment mediates between user requests and network resources, allowing legitimate access to diverse resources while blocking unauthorized access through its sandboxed entitlement structure.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If context-based access control with virtual environments is implemented, then access management efficiency and security improve, but system complexity increases

Engineering Contradiction:
Improveaccess management efficiencyVSAvoidsystem architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling virtual computing environments to automatically manage their own entitlements and access controls. The system provisions and configures virtual environments with appropriate sandboxed entitlements without requiring manual intervention for each user, thereby improving access management efficiency while reducing the perceived complexity through automation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12495046B2Method and system for context-based access control of network resources
Publication Date: 2025.12.09 JPMORGAN CHASE BANK NA
  • US12495046B2 patent drawing
  • US12495046B2 patent drawing
  • US12495046B2 patent drawing

AI summary

A system for context-based access control within a computer network that comprises existing virtual computing environments that exclude a first virtual computing environment. The system may comprise memory storing instructions that, when executed, cause a processor to: generate the first virtual computing environment within the computer network; sandbox the first virtual computing environment from each of the existing virtual computing environments; associate the first virtual computing environment with entitlements; provide, to network accounts, access to the first virtual computing environment; and access, by at least one of the network accounts, a network resource based on the access to the first virtual computing environment and according to at least one of the entitlements.