Secure Access Connector for Mobile Enterprise Content

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise content access via mobile devices poses challenges in maintaining control and ensuring secure, unified access to network resources across different platforms like end user devices, home directories, and SharePoint systems.

Innovation Solution

A mobile app and infrastructure solution that provides secure access to network resources by using secure access connectors, enforcing policies at multiple layers, and utilizing user credentials to manage access privileges, allowing seamless and secure access while adhering to access control lists and location-based policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If mobile access to enterprise content is enabled, then user convenience and accessibility are improved, but network security and access control are compromised

Engineering Contradiction:
Improvemobile access convenienceVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A gateway server acts as an intermediary between mobile devices and enterprise network resources. The gateway receives authentication requests from mobile devices, validates credentials against the Active Directory domain controller, and establishes secure connections without requiring mobile devices to directly access internal network resources. This mediator architecture enables mobile access while maintaining network security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication and access control system is segmented into distinct layers: mobile device authentication, gateway server validation, domain controller verification, and resource access control. Each layer handles specific security functions independently, allowing mobile access to be enabled without compromising the security of internal network resources. The segmentation isolates mobile device risks from the core enterprise network.

Inventive Principle:
Principle #1Segmentation

2Productivity

If unified access to multiple enterprise resources is provided, then user productivity is improved, but system complexity increases

Engineering Contradiction:
Improveaccess efficiencyVSAvoidsystem architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The gateway server is designed as a universal access point that handles multiple types of enterprise resources including file shares, SharePoint sites, and other network resources through a single authentication mechanism. Mobile devices can access diverse resources uniformly through the gateway without requiring separate authentication systems for each resource type, simplifying the user experience while maintaining backend complexity management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication system implements feedback loops where the gateway server continuously monitors authentication outcomes, connection status, and resource access patterns. Based on this feedback, the system dynamically adjusts authentication tokens, updates session management, and coordinates with domain controllers to maintain secure access states. This feedback mechanism automates complex coordination tasks across multiple system components.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10148637B2Secure authentication to provide mobile access to shared network resources
Publication Date: 2018.12.04 EMC IP HLDG CO LLC
  • US10148637B2 patent drawing
  • US10148637B2 patent drawing
  • US10148637B2 patent drawing

AI summary

Techniques to perform secure authentication to provide mobile access to shared content are disclosed. In various embodiments, a user credential associated with a request to access content is received at a connector node from a mobile application running on a mobile device. The user credential is used to create at the connector node a secure credential token that includes the user credential. The secure credential token is used to provide to the mobile application on the mobile device, via the connector node, access to content on two or more servers residing on a protected network with which the user credential is associated.