Dynamic Variance Mechanism for Enterprise VPN Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As enterprise data is increasingly accessed by employees and other individuals using client devices, there is a growing risk of data exposure and compromise due to unlocked and unmanaged devices, necessitating regular and periodic authentication checks.

Innovation Solution

A dynamic variance mechanism that utilizes a virtual private network (VPN) to validate client devices using cryptographic keys, detect anomalies in device interactions, and periodically re-authenticate devices to ensure legitimate access to enterprise resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If regular and periodic authentication checks are implemented to secure enterprise resources, then data security is improved, but device complexity and authentication overhead increase

Engineering Contradiction:
Improvedata securityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic authentication variance where the frequency and strictness of authentication checks are adjusted based on risk assessments, device trust levels, and user behavior patterns. This dynamic approach maintains high security while reducing unnecessary authentication overhead for trusted devices, resolving the contradiction between security reliability and system complexity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes authentication parameters such as check frequency, verification strength, and re-authentication intervals based on contextual factors like device history, user role, and access sensitivity. This parameter adaptation allows the system to maintain security reliability while optimizing complexity by applying stricter checks only when necessary.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If cryptographic validation and anomaly detection are implemented, then detection precision is improved, but computational energy consumption increases

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidcomputational energy consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent applies cryptographic validation and anomaly detection selectively rather than uniformly to all devices and access patterns. Low-risk, trusted devices receive reduced scrutiny while high-risk or unfamiliar devices undergo comprehensive cryptographic validation and detailed anomaly analysis. This partial action approach maintains high detection precision for suspicious activities while significantly reducing overall computational energy consumption.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If periodic re-authentication is implemented, then security reliability is improved, but loss of time in access operations increases

Engineering Contradiction:
Improveaccess securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements periodic re-authentication with variable intervals based on device trust levels, user roles, and access patterns. Trusted devices experience longer intervals between re-authentication requirements, while devices showing suspicious behavior or accessing sensitive resources face more frequent checks. This periodic action with adaptive timing maintains security reliability while minimizing time loss for legitimate users.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS12206647B2Dynamic variance mechanism for securing enterprise resources using a virtual private network
Publication Date: 2025.01.21 OMNISSA LLC
  • US12206647B2 patent drawing
  • US12206647B2 patent drawing
  • US12206647B2 patent drawing

AI summary

Disclosed are various examples for securing enterprise resources using a virtual private network. At least one computing device that can authenticate a client device for a virtual private network (VPN) connection based on a first device identifier received from the client device and a second device identifier received from a remote management service. The at least one computing device can determine that a network event associated with the client device has been observed and execute a machine learning routine to identify a pattern of access for the client device. A network access anomaly is determined in response to a network interaction of the client device deviating from the pattern of access for the client device. A remedial action is performed based on an anomaly type associated with the network access anomaly.