Mobile DNS Proxy Policy Control Beyond VPN Tunnels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network monitoring systems for mobile devices struggle to provide visibility and control over network communications outside VPN tunnels, especially for name queries, and require extensive human intervention for policy rule creation and machine learning training, leading to inefficiencies and performance degradation.

Innovation Solution

A system that captures all network flows on mobile devices, steers name queries inside or outside the VPN tunnel based on policy rules, processes data in real-time using machine learning algorithms to automatically create and apply network policies, and aggregates data for centralized analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If VPN solutions are used to provide visibility and control of mobile network communications, then control over network flows inside the VPN tunnel is improved, but visibility and control over network flows that bypass the VPN tunnel deteriorates

Engineering Contradiction:
Improvecontrol over network flowsVSAvoidvisibility over all network flows
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent introduces a DNS proxy as an intermediary component that intercepts and redirects DNS queries. This mediator enables the system to observe and control all network flows including those that bypass the VPN tunnel, since DNS queries must pass through the proxy regardless of whether the subsequent traffic uses the VPN tunnel or not.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments network flow control into two independent components: DNS query handling (through the DNS proxy) and VPN tunneling. This segmentation allows the system to control DNS queries for all destinations while maintaining selective VPN tunneling for specific traffic, thereby achieving visibility and control over both tunneled and non-tunneled flows.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If network monitoring systems scale up to handle more mobile devices, then coverage of mobile workers is improved, but system complexity and human intervention requirements deteriorates

Engineering Contradiction:
Improvecoverage of mobile workersVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements self-service through automated machine learning algorithms that continuously analyze network traffic patterns and automatically create policy rules. The system monitors mobile worker behavior, identifies anomalies, and generates control policies without requiring manual intervention from network administrators, thereby reducing complexity as the system scales.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback loops where network traffic data is continuously collected, analyzed by machine learning algorithms, and used to automatically update policy rules. This closed-loop feedback mechanism enables the system to adapt to changing network conditions and worker behavior patterns automatically, reducing the need for manual system configuration and complexity management.

Inventive Principle:
Principle #23Feedback

3Stability of the object's composition

If centralized mechanisms are used for network control, then policy consistency is improved, but network performance and user experience deteriorates due to bottlenecks

Engineering Contradiction:
Improvepolicy consistencyVSAvoidnetwork performance
Core Design Contradiction:
Stability of the object's compositionVSSpeed

Solution Approach 1:

The patent segments the network control function into distributed components: a centralized policy management plane that defines high-level policies and local enforcement points (such as the DNS proxy and VPN client) that execute policies autonomously. This segmentation maintains policy consistency through centralized coordination while eliminating performance bottlenecks by allowing local devices to make real-time control decisions without waiting for centralized processing.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250379823A1Mobile management system
Publication Date: 2025.12.11 MOBILE SONIC INC
  • US20250379823A1 patent drawing
  • US20250379823A1 patent drawing
  • US20250379823A1 patent drawing

AI summary

Mobile management method, system and client. The method includes receiving a DNS query for a host name from an application on a client; retrieving reputation data associated with the host name from a local cache on the client; determining a policy for the host name, which is associated with the host name and the reputation data associated with the host name; based on the determined policy for the host name, blocking attempted network flows to a host corresponding to the host name; sending at least attempted network flow metadata related to the blocked attempted network flows to a collector on the client; and transmitting the attempted network flow metadata in the collector to a VPN server pool via a VPN tunnel.