Intermediary SSL VPN Policy Enforcement for Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in managing access to resources across various networks, particularly in determining when and how to provide secure access to clients from different networks, ensuring sensitive information is protected while allowing necessary access through SSL VPN sessions.

Innovation Solution

An intermediary device establishes SSL VPN sessions based on policy, determining whether to use a client-based or clientless SSL VPN session by identifying session policies associated with client requests, allowing for fine-grained control over URL rewriting and embedded URL detection across different content types.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the enterprise allows all clients to access resources, then access convenience is improved, but security is worsened

Engineering Contradiction:
Improveaccess convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary device positioned between clients and servers that acts as a policy enforcement point. This intermediary intercepts HTTP requests, evaluates them against configured security policies, and determines whether to allow or block access. This resolves the contradiction by maintaining open access paths while inserting security control mechanisms that evaluate each request independently, thus preserving convenience while enhancing security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary security evaluation by pre-configuring access policies and evaluating client requests against these policies before granting access to servers. The intermediary device assesses security conditions in advance of actual resource access, determining authentication requirements and authorization levels beforehand. This allows the system to maintain open access architecture while ensuring security checks are completed proactively, resolving the contradiction between ease of access and security enforcement.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the enterprise protects sensitive information from all clients, then security is improved, but access flexibility is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidaccess flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements local quality by applying different security policies to different clients, resources, and request types. The intermediary device evaluates each HTTP request individually and applies specific access controls based on the particular client identity, target resource, and request characteristics. This allows sensitive information to be protected from unauthorized access while simultaneously permitting flexible access for authenticated users with appropriate permissions, thus resolving the contradiction between security and access flexibility.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system employs dynamic policy evaluation where access decisions are not static but adapt based on real-time request characteristics. The intermediary device dynamically assesses each HTTP request against configurable policies that can vary by client, resource, time, and other parameters. This dynamic approach enables the system to maintain strong security protections while providing flexible access pathways when conditions warrant, resolving the contradiction between security enforcement and access adaptability.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If the enterprise implements fine grain policy control, then security control precision is improved, but system complexity is worsened

Engineering Contradiction:
Improvesecurity control precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing security policy control into discrete, manageable components within the intermediary device. The system segments policy evaluation into separate processing stages: request interception, policy matching, decision rendering, and response modification. This segmentation allows fine-grained security control to be implemented through modular policy rules that can be independently configured and managed, reducing the perceived complexity while maintaining high precision control over access decisions.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2241082B1Systems and methods for configuration and fine grain policy driven web content detection and rewrite
Publication Date: 2019.05.29 CITRIX SYSTEMS INC
  • EP2241082B1 patent drawingFigure 1A
  • EP2241082B1 patent drawingFigure 1B
  • EP2241082B1 patent drawingFigure 1C

AI summary

The present disclosure provides solutions that may enable an enterprise providing services to a number of clients to determine whether to establish a client based SSL VPN session or a clientless SSL VPN session with a client based on an information associated with the client. An intermediary establishing SSL VPN sessions between clients and servers may receive a request from a client to access a server. The intermediary may identify a session policy based on the request. The session policy may indicate whether to establish a client based SSL VPN session or clientless SSL VPN session with the server. The intermediary may determine, responsive to the policy, to establish a clientless or client based SSL VPN session between the client and the server.