Secure Connection Adapter for Automatic Enterprise Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Non-technical users, such as corporate executives, face challenges in accessing enterprise resources securely when outside the protective structures of their enterprise network, as they lack understanding of secure versus unsecured network connections and are vulnerable to threats in unsecured environments.

Innovation Solution

A secure connection adapter is installed in client devices to detect network environments and establish secure connections to enterprise networks using IPSec or SSL, providing secure access to enterprise resources and optionally allowing direct access to Internet or local network resources through split-tunnel operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual tunneling protocols or VPN access are used to establish secure connections, then secure access to enterprise resources is achieved, but the complexity of operation increases and non-technical users cannot easily use these solutions

Engineering Contradiction:
Improvesecure accessVSAvoiduser operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically detects the network environment and establishes secure connections without requiring user intervention. The secure connection adapter monitors network conditions and autonomously initiates VPN or tunneling protocols when untrusted networks are detected, eliminating the need for users to manually configure security settings

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A transparent secure connection adapter is introduced as an intermediary component between the client application and the network. This adapter operates at the network layer, automatically managing secure connections without requiring applications or users to understand or configure security protocols, thus maintaining ease of use while ensuring security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If automatic secure connection establishment is implemented, then ease of operation is improved, but device complexity increases due to the secure connection adapter

Engineering Contradiction:
Improveautomatic accessVSAvoidsystem structure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The secure connection functionality is segmented into a separate, modular secure connection adapter component. This adapter operates independently from the main operating system and applications, encapsulating the complexity of secure connection management in a dedicated module that can be added or removed without affecting the core system

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure connection adapter operates at the network layer, adding a new dimension of security abstraction between the application layer and the physical network. This layered approach allows automatic secure connection establishment without requiring changes to existing applications or user interfaces, maintaining system simplicity while enhancing functionality

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS8560833B2Automatic secure client access
Publication Date: 2013.10.15 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8560833B2 patent drawing
  • US8560833B2 patent drawing
  • US8560833B2 patent drawing

AI summary

Providing secure network access in a networked client device. A client device is provided with a secure connection adapter. In operation, the secure connection adapter detects the network environment of the client device and determines of the network environment is trusted or untrusted. If the client device is operating in an untrusted network environment, the secure connection adapter establishes a secure connection to an enterprise host using a secure tunnel such as IPSec, SSL, or other secure connection. Programs executing on the client device now operate in the secure network environment, with all network activity routed through the secure connection to the enterprise. Optionally, a split tunnel mechanism may be used to direct some network traffic directly to the Internet from the client device.