Intermediary SSL VPN Policy Enforcement for Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face challenges in managing access to resources across various networks, particularly in determining when and how to provide secure access to clients from different networks, ensuring sensitive information is protected while allowing necessary access through SSL VPN sessions.
Innovation Solution
An intermediary device establishes SSL VPN sessions based on policy, determining whether to use a client-based or clientless SSL VPN session by identifying session policies associated with client requests, allowing for fine-grained control over URL rewriting and embedded URL detection across different content types.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the enterprise allows all clients to access resources, then access convenience is improved, but security is worsened
Solution Approach 1:
The patent introduces an intermediary device positioned between clients and servers that acts as a policy enforcement point. This intermediary intercepts HTTP requests, evaluates them against configured security policies, and determines whether to allow or block access. This resolves the contradiction by maintaining open access paths while inserting security control mechanisms that evaluate each request independently, thus preserving convenience while enhancing security.
Solution Approach 2:
The system performs preliminary security evaluation by pre-configuring access policies and evaluating client requests against these policies before granting access to servers. The intermediary device assesses security conditions in advance of actual resource access, determining authentication requirements and authorization levels beforehand. This allows the system to maintain open access architecture while ensuring security checks are completed proactively, resolving the contradiction between ease of access and security enforcement.
2Reliability
If the enterprise protects sensitive information from all clients, then security is improved, but access flexibility is worsened
Solution Approach 1:
The patent implements local quality by applying different security policies to different clients, resources, and request types. The intermediary device evaluates each HTTP request individually and applies specific access controls based on the particular client identity, target resource, and request characteristics. This allows sensitive information to be protected from unauthorized access while simultaneously permitting flexible access for authenticated users with appropriate permissions, thus resolving the contradiction between security and access flexibility.
Solution Approach 2:
The system employs dynamic policy evaluation where access decisions are not static but adapt based on real-time request characteristics. The intermediary device dynamically assesses each HTTP request against configurable policies that can vary by client, resource, time, and other parameters. This dynamic approach enables the system to maintain strong security protections while providing flexible access pathways when conditions warrant, resolving the contradiction between security enforcement and access adaptability.
3Measurement precision
If the enterprise implements fine grain policy control, then security control precision is improved, but system complexity is worsened
Solution Approach 1:
The patent applies segmentation by dividing security policy control into discrete, manageable components within the intermediary device. The system segments policy evaluation into separate processing stages: request interception, policy matching, decision rendering, and response modification. This segmentation allows fine-grained security control to be implemented through modular policy rules that can be independently configured and managed, reducing the perceived complexity while maintaining high precision control over access decisions.
Data Source
Figure 1A
Figure 1B
Figure 1C
AI summary
The present disclosure provides solutions that may enable an enterprise providing services to a number of clients to determine whether to establish a client based SSL VPN session or a clientless SSL VPN session with a client based on an information associated with the client. An intermediary establishing SSL VPN sessions between clients and servers may receive a request from a client to access a server. The intermediary may identify a session policy based on the request. The session policy may indicate whether to establish a client based SSL VPN session or clientless SSL VPN session with the server. The intermediary may determine, responsive to the policy, to establish a clientless or client based SSL VPN session between the client and the server.