Hybrid Mobile Security Agent with Cloud Policy Broker
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing mobility and use of cloud services in enterprises pose challenges for IT administrators, including the need for unified service discovery and secure availability, as traditional VPNs fail to scale with the growth of mobile devices and cloud services, leading to security risks and performance issues due to the complexity of managing multiple applications and network traffic segmentation.
Innovation Solution
A hybrid architecture that combines client-side and cloud-based processing, utilizing a lightweight agent on mobile devices for traffic interception and filtering, with periodic updates from a cloud-based system to enforce security policies and enable service-driven split tunneling, allowing granular control over network traffic based on port, protocol, and destination IP address, thereby optimizing security and performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional VPN is used for mobile users, then security policy enforcement is maintained, but the system does not scale with the growth of mobile devices and cloud services
Solution Approach 1:
The patent segments network traffic into different categories (corporate traffic, internet traffic, cloud service traffic) and routes them through different channels. Mobile users can access cloud services directly without VPN while corporate traffic is routed through the VPN gateway, eliminating the need for a single comprehensive VPN application and improving scalability.
Solution Approach 2:
The patent introduces a cloud-based service broker that acts as an intermediary between mobile users and cloud services. This broker discovers services, authenticates users, and establishes direct connections to cloud services, eliminating the need for users to manually configure multiple VPN applications and simplifying the overall system complexity.
2Reliability
If all traffic is routed through the well-defined perimeter, then security control is maintained, but bandwidth consumption increases and latency increases
Solution Approach 1:
The patent segments traffic routing based on destination and type. Corporate internal traffic is routed through the VPN gateway for security control, while cloud service traffic and internet traffic are routed directly without backhauling through the perimeter, reducing bandwidth consumption and latency for non-critical traffic.
Solution Approach 2:
The patent applies different routing qualities to different traffic types. Critical corporate traffic receives the highest security control through gateway routing, while less sensitive cloud and internet traffic receives local direct routing, optimizing the balance between security and performance for each traffic category.
3Reliability
If client-side agents are deployed for security, then security and compliance are provided, but battery drainage increases and processor consumption increases
Solution Approach 1:
The patent moves the heavy security processing workload from the mobile device to a cloud-based security gateway. The mobile device only needs to establish basic connections and authenticate, while the gateway performs complex security checks, threat detection, and compliance verification, significantly reducing battery drainage and processor consumption on mobile devices.
Solution Approach 2:
The patent replaces the mechanical approach of running full security agents on mobile devices with a cloud-based security service model. Security functions are delivered as services from the gateway, transforming the system from device-centric security processing to cloud-centric security processing, which reduces local resource consumption.
4Adaptability or versatility
If multiple applications are deployed for different services, then service coverage is improved, but device complexity increases and ease of operation decreases
Solution Approach 1:
The patent implements a universal access point that provides multiple services through a single interface. The service broker discovers and manages multiple cloud services, VPN connections, and internet access through one application, eliminating the need for users to configure and manage multiple separate applications while maintaining comprehensive service coverage.
Solution Approach 2:
The patent enables the system to automatically discover services, authenticate users, and establish connections without manual configuration. The service broker autonomously manages service discovery, credential verification, and connection establishment, freeing users from complex configuration tasks while providing access to multiple services through a single application.
Data Source
AI summary
Systems and methods include intercepting traffic on a mobile device based on a set of rules; determining whether a connection associated with the traffic is allowed based on a local map associated with an application; responsive to the connection being allowed or blocked based on the local map, one of forwarding the traffic associated with the connection when allowed and generating a block of the connection at the mobile device when blocked; and, responsive to the connection not having an entry in the local map, forwarding a request for the connection to a cloud-based system for processing therein. The cloud-based system is configured to allow or block the connection based on the connection not having an entry in the local map.


