Adaptive Device Protection Through VPN Policy Continuity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional device protection mechanisms fail to apply security policies from one network to another when a connected device transitions between networks, leaving devices unprotected and unmanaged.

Innovation Solution

A decision intelligence-based computerized framework that establishes a virtual private network (VPN) connection to seamlessly apply host network security policies to disparate networks, ensuring consistent device management and security across network transitions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional device protection mechanisms are used, then device security is maintained on the host network, but security policies cannot be applied when the device connects to other networks

Engineering Contradiction:
Improvenetwork adaptabilityVSAvoidsecurity consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a VPN gateway as an intermediary component that mediates between the device and external networks. When a device disconnects from the host network, the VPN gateway establishes a virtual connection, allowing security policies to be enforced through this intermediary channel. The gateway acts as a bridge that maintains policy enforcement capability regardless of the device's physical network location.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transitions security enforcement from a single-dimension approach (relying solely on physical network connection) to a multi-dimensional approach by adding a virtual network dimension. The VPN creates a layered architecture where security policies operate at the virtual network layer, independent of the physical network layer, enabling consistent enforcement across different physical networks.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If a VPN connection is established to enforce policies remotely, then security consistency is maintained across networks, but system complexity increases

Engineering Contradiction:
Improvesecurity consistencyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The device protection agent implements self-service functionality by automatically detecting network disconnection events and initiating VPN reconnection without user intervention. The system autonomously manages the transition from host network to VPN-based security enforcement, reducing the need for manual configuration and complex user-side management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements preliminary action by pre-configuring the device protection agent with VPN credentials and security policies before network disconnection occurs. The agent is prepared in advance to establish VPN connections and enforce policies, eliminating the need for complex real-time decision-making and reducing system complexity during actual security events.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12363000B2Computerized systems and methods for adaptive device protection
Publication Date: 2025.07.15 PLUME DESIGN INC
  • US12363000B2 patent drawing
  • US12363000B2 patent drawing
  • US12363000B2 patent drawing

AI summary

Disclosed are systems and methods that provide a computerized device management framework that adaptively determines and applies security and configuration parameters to a device on a first network, and enables the adaptive application of such parameters as the device disconnects and connects to other networks. The disclosed framework enables the automatic detection of different networks being relied upon by the device for access to the Internet, upon which, management control policies of the device's activities can be controlled and managed in a unified manner. Accordingly, the disclosed framework can enable security and configuration mechanisms applied on a first network, upon which they are associated, to be seamlessly applied on another disparate network via a virtual private network connection enabled via proprietary mechanisms implemented on the device.