Application-Aware VPN Client for Bandwidth Conservation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VPN technologies often establish secure connections unnecessarily, leading to bandwidth consumption and resource wastage, as they automatically create VPN tunnels for all network activities, even when access to enterprise resources is not required.

Innovation Solution

A VPN client that monitors application activities and selectively establishes a VPN connection only when necessary, using rules to determine if an application requires access to enterprise resources, thereby partitioning traffic between VPN-dependent and VPN-independent data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VPN client software automatically establishes a VPN connection for all network activities, then security assurance is improved, but bandwidth consumption and resource wastage increase

Engineering Contradiction:
Improvesecurity assuranceVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments network traffic into two categories: enterprise resource traffic that requires VPN encryption and general internet traffic that does not. The VPN client monitors application activities and selectively establishes VPN connections only for enterprise resource access, partitioning traffic between VPN-dependent and VPN-independent data flows. This segmentation resolves the contradiction by maintaining security for enterprise resources while avoiding unnecessary bandwidth consumption for general internet activities.

Inventive Principle:
Principle #1Segmentation

2Reliability

If VPN connection is established for all applications, then access security is improved, but network connection speed deteriorates

Engineering Contradiction:
Improveaccess securityVSAvoidnetwork connection speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent implements dynamic VPN connection management where the VPN client continuously monitors application activities and adjusts VPN connection status in real-time. The system transitions between connected and disconnected states based on whether enterprise resource access is detected, rather than maintaining a static always-connected state. This dynamic approach preserves security when needed while improving network speed by eliminating unnecessary VPN overhead for non-enterprise activities.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If automatic VPN establishment is implemented, then ease of operation is improved, but unnecessary resource wastage occurs

Engineering Contradiction:
Improveautomatic connectionVSAvoidresource wastage
Core Design Contradiction:
Ease of operationVSLoss of substance

Solution Approach 1:

The patent implements self-service VPN management where the VPN client autonomously monitors application activities, determines when enterprise resource access is required, and automatically establishes or terminates VPN connections without user intervention. The system uses application monitoring to detect enterprise resource access attempts and autonomously manages the VPN connection lifecycle, resolving the contradiction by providing automatic operation while avoiding resource wastage through intelligent connection management.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10581803B1Application-aware connection rules for network access client
Publication Date: 2020.03.03 PULSE SECURE LLC
  • US10581803B1 patent drawing
  • US10581803B1 patent drawing
  • US10581803B1 patent drawing

AI summary

Virtual private network (VPN)-related techniques are described. The techniques provide intuitive mechanisms by which a client device more efficiently establishes a VPN connection. In one example, a client device includes a memory, processor(s), and a VPN handler. The VPN handler is configured to monitor actions initiated by one or more applications executable by the programmable processor(s), and determine whether each of the initiated actions requires a VPN connection via which to transmit outbound data traffic corresponding to a respective application of the one or more applications. The VPN handler is further configured to, in response to a detection that at least one initiated action requires the VPN connection via which to transmit the outbound data traffic, automatically establish the VPN connection to couple the client device to an enterprise network, and transmit the outbound data traffic corresponding to the respective application, via the VPN connection.