Unmanaged Device Security via Network Intermediary Test Links
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Providing effective security services to unmanaged devices is challenging due to their connection to multiple networks and lack of control by business administrators, as existing solutions struggle to enforce security policies and manage data routing effectively.
Innovation Solution
A communication system that uses a reverse proxy to intercept interactions, insert test links, and enforce security policies by routing traffic through a network services platform, which coaches users to configure their devices to meet desired security standards, and takes remedial actions if non-compliant.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security policies are enforced on unmanaged devices, then network security is improved, but device complexity and user control are worsened
Solution Approach 1:
The patent introduces a network service platform as an intermediary between unmanaged devices and the network. This platform intercepts device interactions, inserts test links, and enforces security policies without requiring direct modification of the unmanaged device. The intermediary handles the complexity of security enforcement while keeping the end device simple and user-friendly.
Solution Approach 2:
The security enforcement system is segmented into separate functional components: a network service platform that handles policy enforcement, a reverse proxy that intercepts traffic, and a test link insertion mechanism. This segmentation allows security policies to be enforced at the network layer rather than requiring complex device-level configurations.
2Reliability
If traffic is routed through a network services platform, then security policy enforcement is improved, but network latency and complexity are worsened
Solution Approach 1:
The system performs preliminary actions by pre-configuring test links and security policies in the network service platform before actual device interactions occur. This allows the platform to quickly match and enforce appropriate security policies without real-time analysis delays, reducing latency while maintaining enforcement effectiveness.
3Reliability
If unmanaged devices are monitored and classified, then network security visibility is improved, but privacy concerns and user control are worsened
Solution Approach 1:
The system implements self-service mechanisms where devices automatically undergo classification and testing through the network service platform. The classification process is transparent and automated, with devices being evaluated based on their interactions with test links rather than requiring manual user input or revealing sensitive user information.
Data Source
AI summary
Particular embodiments described herein provide for a network element that can be configured to receive, from an electronic device, a request to access a network service. In response to the request, the network element can send data related to the network service to the electronic device and add a test link to the data related to the network service. The network element can also be configured to determine if the test link was successfully executed and classify the electronic device as untrusted if the test link was not successfully executed.


