Mobile VPN Client Fast Reconnect via Session Cookie
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing use of cellular mobile devices for computer data services poses challenges for enterprises in enabling secure and easy connectivity, particularly due to misconfiguration issues that can lead to security risks and network conflicts, making it difficult for IT staff to provide seamless access across various devices and locations.
Innovation Solution
A secure VPN gateway system that includes a multi-service network client on cellular mobile devices, enabling secure, controlled access to enterprise networks through a unified client that handles VPN connections, security, and data acceleration, simplifying user experience and reducing the need for complex interactions with network access and security software.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple separate security and connectivity software applications are installed on each mobile device, then security coverage and functionality are improved, but device complexity and potential for conflicts increase
Solution Approach 1:
The patent combines multiple separate security and connectivity software applications into a single integrated VPN client application. This unified client provides both security functions (virus scanning, spyware detection, firewall) and connectivity functions (VPN establishment, network access) through one software package, reducing the number of separate applications from multiple to one, thereby reducing device complexity while maintaining comprehensive security coverage
Solution Approach 2:
The VPN client is designed as a universal multi-functional application that performs multiple roles simultaneously: it acts as a VPN client for secure network access, an antivirus scanner for malware detection, a spyware detector for unauthorized software identification, and a firewall for network traffic control. This multi-functionality eliminates the need for separate specialized applications while providing comprehensive protection and connectivity
2Reliability
If users are provided with complex network access and security software, then security control and network management are improved, but ease of operation deteriorates due to required user interaction
Solution Approach 1:
The VPN client implements self-service functionality by automatically establishing VPN connections, performing security scans, and managing network access without requiring user intervention. The system autonomously handles authentication, connection establishment, and security policy enforcement, eliminating the need for users to interact with complex configuration options or understand technical details while maintaining strong security controls
Solution Approach 2:
The unified VPN client acts as an intermediary between the user and the complex network security infrastructure. It abstracts away the complexity of multiple security protocols and network configurations, presenting a simple interface to users while handling all complex security and connectivity operations in the background, thus improving ease of operation without compromising network security
3Speed
If fast reconnect functionality is implemented, then connectivity speed and user experience are improved, but network traffic usage increases during reconnection
Solution Approach 1:
The system performs preliminary actions by maintaining connection state information and authentication credentials in memory during temporary network disruptions. When connectivity is restored, the client can immediately re-establish the VPN connection using cached credentials without requiring full re-authentication, enabling fast reconnection while minimizing additional network traffic to only what is necessary for connection establishment rather than complete authentication sequences
Data Source
AI summary
A virtual private network client for cellular mobile devices is described. The VPN network client establishes a secure VPN connection with a remote VPN security device. The VPN network client establishes a secure control channel with the secure VPN gateway and, upon a successful authentication, receives a session cookie with a unique identifier. In the event communication with the secure VPN gateway is subsequently temporarily lost, the VPN network client performs a fast reconnect without requiring re-authentication of the cellular mobile device by communicating the session cookie to the secure VPN gateway. Prior to performing the fast reconnect, the VPN network client identifies a set of transport mechanisms currently available to the cellular mobile device and, when only a cellular network is available and not a wireless packet-based connection, the VPN network client defers the fast reconnect until application-layer data is received from a user application and is ready to be sent to the remote VPN security device via the VPN connection.


