Managed Service Platform for Private Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for securely accessing privately hosted or cloud applications from mobile devices require on-device software applications and PKI certificate installations, leading to high integration costs and low mobile enterprise application adoption due to reliance on public Internet connections and VPN setups.
Innovation Solution
A system and method that determine data traffic paths based on destination IP addresses, using a managed service platform to route traffic through private networks without public Internet access, eliminating the need for on-device installations and enabling seamless access to both personal and work-related applications by utilizing APN-based routing and multiprotocol label switching.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If VPN setup or PKI certificate installation is used on mobile devices to access privately hosted applications, then secure access is achieved, but device complexity and integration costs increase
Solution Approach 1:
The patent introduces a network-side intermediary system (service gateway) that mediates between mobile devices and privately hosted applications. Instead of requiring VPN clients or PKI certificates on devices, the service gateway performs authentication and routing decisions centrally, eliminating complex on-device software installations while maintaining secure access.
Solution Approach 2:
The system enables self-service access by using the mobile device's inherent APN (Access Point Name) configuration to automatically route traffic through the service gateway. No additional VPN setup or certificate installation is needed on the device side - the device simply uses its existing network settings, and the gateway handles security and routing automatically.
2Ease of operation
If public Internet connection is used for accessing applications, then device simplicity is maintained, but security and network reliability deteriorate
Solution Approach 1:
The service gateway acts as an intermediary that sits between the mobile device and the privately hosted applications. It receives traffic from the device, authenticates the user, and routes traffic to the appropriate application servers through private network connections, eliminating the need for direct public Internet exposure while maintaining device simplicity.
Solution Approach 2:
The network path is segmented into distinct segments: mobile device -> service gateway -> private network -> application servers. This segmentation allows secure private network access without requiring the device to directly connect to the public Internet, maintaining both simplicity and security.
3Reliability
If VPN application or MDM solution is deployed to enable secure access, then access security is improved, but integration costs and deployment complexity increase
Solution Approach 1:
The system eliminates the need for complex VPN applications or MDM solutions by using the mobile device's native APN configuration. The service gateway handles authentication and security functions centrally, removing the need for expensive on-device VPN clients, certificate management systems, and complex integration with mobile device management platforms.
Solution Approach 2:
The patent extracts the security and routing functions from the mobile device and concentrates them in the service gateway. By taking out VPN client software, PKI certificate management, and complex authentication logic from the device and placing them in the gateway, the solution eliminates integration costs and deployment complexity associated with on-device software installations.
Data Source
AI summary
A method and a system for determining a path of data traffic based on a destination Internet Protocol (IP) address, the destination IP address being either private or public and belonging to any one of multiple organizations. In the method and system, a subscribed device identifier and the destination IP address of one of the multiple organizations is received at a managed service platform. If both the subscribed device identifier and the destination IP address of the one of the multiple organizations are not registered in a predetermined policy database, a subscriber or an owner of the subscribed device is prompted, at a telecommunications endpoint associated with the subscribed device identifier, to register the endpoint. The subscribed device identifier is then registered in the predetermined policy database, based on information received from the telecommunications endpoint in response to the prompting. If the subscribed device identifier and the destination IP address of the one of the multiple organizations are registered in the predetermined policy database, a service device of the managed service platform on a private network routes the data traffic to a private network resource of the one of the multiple organizations. If the subscribed device identifier is registered in the policy database and the destination IP address of the one of the multiple organizations is not registered in the predetermined policy database, the service device of the managed service platform on the private network routes the data traffic via an IP transit service to the public internet.


