Secure Remote Access Gateway for Enterprise Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current VPN solutions pose a high security risk by providing unrestricted access to the enterprise network, lack seamless remote access without user intervention, and do not adequately authenticate both users and devices, nor control access based on device location.

Innovation Solution

A system with a secure remote access gateway and central controller that authenticates both users and devices, uses micro-segmentation, and enforces firewall policies to allow access only to required enterprise applications, enabling seamless and secure remote access with zero user intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If VPN solution is used to provide remote access to enterprise network, then remote employees can access enterprise applications, but security risk increases due to unrestricted network access

Engineering Contradiction:
Improveremote access capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the enterprise network into application-specific access paths instead of providing blanket network access. Each remote user receives access only to specific applications they need, not the entire network. This is achieved through a gateway system that routes traffic selectively to specific applications, eliminating the security risk of unrestricted VPN access while maintaining remote access capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a gateway system as an intermediary between remote users and enterprise applications. This gateway acts as a mediator that authenticates users, enforces security policies, and routes traffic to specific applications. The gateway prevents direct access to the entire network, thereby reducing security risks while enabling controlled remote access to necessary applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If VPN client installation and configuration is required, then network access can be controlled, but user intervention and training are required

Engineering Contradiction:
Improveaccess controlVSAvoiduser intervention requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a self-service mechanism where the gateway system automatically detects the user's network environment and configures the appropriate access profile without requiring manual user intervention. The system automatically installs necessary clients, configures connection parameters, and sets up security policies based on the user's role and requirements. This eliminates the need for users to manually configure VPN settings while maintaining reliable access control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary configuration actions by pre-configuring access profiles and security policies in advance. When a user needs remote access, the system has already prepared the appropriate configuration parameters, authentication methods, and application routing rules. This preliminary preparation eliminates the need for real-time user intervention during the connection setup process.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If VPN provides network access upon user connection, then remote access is enabled, but access control based on device location and dual authentication is not implemented

Engineering Contradiction:
Improveremote access enablementVSAvoidauthentication and access control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent creates a universal gateway system that performs multiple functions: authentication, device location detection, security policy enforcement, and application routing. This multi-functional gateway handles both user authentication and device authentication, determines geographic location, and controls access to specific applications based on combined credentials and location data. This universal approach enables seamless remote access while implementing comprehensive security controls.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements feedback mechanisms where the gateway continuously monitors user authentication status, device location, and access patterns. Based on this feedback, the system dynamically adjusts access permissions and can terminate connections if security policies are violated. The system provides real-time feedback to users about their access status and any security concerns, enabling productive remote access with reliable security monitoring.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11063959B2Secure and seamless remote access to enterprise applications with zero user intervention
Publication Date: 2021.07.13 COLORTOKENS INC
  • US11063959B2 patent drawing
  • US11063959B2 patent drawing
  • US11063959B2 patent drawing

AI summary

In secure and seamless remote access to enterprise applications with zero user intervention, a first set of policies is generated at a controller based on a user role. A user device associated with the user role is in an enterprise network. The first set of policies is pushed to the security agent in the user device associated with a user, an enterprise server, and a secure remote access gateway from the controller. Upon determining that the user device moves to a remote network, a secure connection is initiated by the security agent from the user device to the secure remote access gateway. Upon determining by the controller that the user is authenticated for the secure connection, a second set of policies is generated by the controller for the user device, the enterprise server and the secure remote access gateway. The second set of policies is pushed to the devices.