Managed Service Platform for Private Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for securely accessing privately hosted or cloud applications from mobile devices require on-device software applications and PKI certificate installations, leading to high integration costs and low mobile enterprise application adoption due to reliance on public Internet connections and VPN setups.

Innovation Solution

A system and method that determine data traffic paths based on destination IP addresses, using a managed service platform to route traffic through private networks without public Internet access, eliminating the need for on-device installations and enabling seamless access to both personal and work-related applications by utilizing APN-based routing and multiprotocol label switching.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VPN setup or PKI certificate installation is used on mobile devices to access privately hosted applications, then secure access is achieved, but device complexity and integration costs increase

Engineering Contradiction:
Improvesecure accessVSAvoidon-device software installation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network-side intermediary system (service gateway) that mediates between mobile devices and privately hosted applications. Instead of requiring VPN clients or PKI certificates on devices, the service gateway performs authentication and routing decisions centrally, eliminating complex on-device software installations while maintaining secure access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service access by using the mobile device's inherent APN (Access Point Name) configuration to automatically route traffic through the service gateway. No additional VPN setup or certificate installation is needed on the device side - the device simply uses its existing network settings, and the gateway handles security and routing automatically.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If public Internet connection is used for accessing applications, then device simplicity is maintained, but security and network reliability deteriorate

Engineering Contradiction:
Improvedevice simplicityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The service gateway acts as an intermediary that sits between the mobile device and the privately hosted applications. It receives traffic from the device, authenticates the user, and routes traffic to the appropriate application servers through private network connections, eliminating the need for direct public Internet exposure while maintaining device simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network path is segmented into distinct segments: mobile device -> service gateway -> private network -> application servers. This segmentation allows secure private network access without requiring the device to directly connect to the public Internet, maintaining both simplicity and security.

Inventive Principle:
Principle #1Segmentation

3Reliability

If VPN application or MDM solution is deployed to enable secure access, then access security is improved, but integration costs and deployment complexity increase

Engineering Contradiction:
Improveaccess securityVSAvoidintegration cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system eliminates the need for complex VPN applications or MDM solutions by using the mobile device's native APN configuration. The service gateway handles authentication and security functions centrally, removing the need for expensive on-device VPN clients, certificate management systems, and complex integration with mobile device management platforms.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent extracts the security and routing functions from the mobile device and concentrates them in the service gateway. By taking out VPN client software, PKI certificate management, and complex authentication logic from the device and placing them in the gateway, the solution eliminates integration costs and deployment complexity associated with on-device software installations.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12108489B2Accessing a privately hosted application from a device connected to a wireless network
Publication Date: 2024.10.01 TATA COMM UK LTD
  • US12108489B2 patent drawing
  • US12108489B2 patent drawing
  • US12108489B2 patent drawing

AI summary

A method and a system for determining a path of data traffic based on a destination Internet Protocol (IP) address, the destination IP address being either private or public and belonging to any one of multiple organizations. In the method and system, a subscribed device identifier and the destination IP address of one of the multiple organizations is received at a managed service platform. If both the subscribed device identifier and the destination IP address of the one of the multiple organizations are not registered in a predetermined policy database, a subscriber or an owner of the subscribed device is prompted, at a telecommunications endpoint associated with the subscribed device identifier, to register the endpoint. The subscribed device identifier is then registered in the predetermined policy database, based on information received from the telecommunications endpoint in response to the prompting. If the subscribed device identifier and the destination IP address of the one of the multiple organizations are registered in the predetermined policy database, a service device of the managed service platform on a private network routes the data traffic to a private network resource of the one of the multiple organizations. If the subscribed device identifier is registered in the policy database and the destination IP address of the one of the multiple organizations is not registered in the predetermined policy database, the service device of the managed service platform on the private network routes the data traffic via an IP transit service to the public internet.