Adaptive Device Protection Through VPN Policy Continuity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional device protection mechanisms fail to apply security policies from one network to another when a connected device transitions between networks, leaving devices unprotected and unmanaged.
Innovation Solution
A decision intelligence-based computerized framework that establishes a virtual private network (VPN) connection to seamlessly apply host network security policies to disparate networks, ensuring consistent device management and security across network transitions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional device protection mechanisms are used, then device security is maintained on the host network, but security policies cannot be applied when the device connects to other networks
Solution Approach 1:
The patent introduces a VPN gateway as an intermediary component that mediates between the device and external networks. When a device disconnects from the host network, the VPN gateway establishes a virtual connection, allowing security policies to be enforced through this intermediary channel. The gateway acts as a bridge that maintains policy enforcement capability regardless of the device's physical network location.
Solution Approach 2:
The patent transitions security enforcement from a single-dimension approach (relying solely on physical network connection) to a multi-dimensional approach by adding a virtual network dimension. The VPN creates a layered architecture where security policies operate at the virtual network layer, independent of the physical network layer, enabling consistent enforcement across different physical networks.
2Reliability
If a VPN connection is established to enforce policies remotely, then security consistency is maintained across networks, but system complexity increases
Solution Approach 1:
The device protection agent implements self-service functionality by automatically detecting network disconnection events and initiating VPN reconnection without user intervention. The system autonomously manages the transition from host network to VPN-based security enforcement, reducing the need for manual configuration and complex user-side management.
Solution Approach 2:
The patent implements preliminary action by pre-configuring the device protection agent with VPN credentials and security policies before network disconnection occurs. The agent is prepared in advance to establish VPN connections and enforce policies, eliminating the need for complex real-time decision-making and reducing system complexity during actual security events.
Data Source
AI summary
Disclosed are systems and methods that provide a computerized device management framework that adaptively determines and applies security and configuration parameters to a device on a first network, and enables the adaptive application of such parameters as the device disconnects and connects to other networks. The disclosed framework enables the automatic detection of different networks being relied upon by the device for access to the Internet, upon which, management control policies of the device's activities can be controlled and managed in a unified manner. Accordingly, the disclosed framework can enable security and configuration mechanisms applied on a first network, upon which they are associated, to be seamlessly applied on another disparate network via a virtual private network connection enabled via proprietary mechanisms implemented on the device.


