Unified Mobile VPN Client for Endpoint Security and Acceleration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing use of cellular mobile devices for computer data services poses challenges for enterprises in enabling secure and easy connectivity, particularly due to misconfiguration issues that can lead to security risks and network conflicts, making it difficult for IT staff to provide seamless access across various devices and locations.

Innovation Solution

A secure VPN gateway system that includes a multi-service network client on cellular mobile devices, enabling secure, controlled access to enterprise networks through a VPN connection, which simplifies user experience by handling provisioning and security without requiring complex user interaction, and provides unified client functionality for VPN remote access, WAN acceleration, and endpoint compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users install multiple endpoint security and connectivity software applications on mobile devices, then security coverage is improved, but device complexity and network conflicts increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsoftware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security and connectivity software functions into a single unified endpoint security application. This consolidation provides comprehensive security coverage (antivirus, firewall, VPN, device hardening) while reducing the number of separate applications users must install and manage, thereby decreasing device complexity and potential network conflicts.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The endpoint security application is designed as a universal solution that performs multiple security functions simultaneously - antivirus scanning, firewall management, VPN connectivity, and device hardening. This multi-functional approach improves security coverage without requiring users to install separate specialized applications for each security function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If IT staff implement comprehensive security policies and monitoring, then network security is improved, but ease of operation and user experience deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The endpoint security application implements self-service capabilities including automatic virus definition updates, automated vulnerability scanning, and self-configuring security policies. This automation allows IT staff to enforce comprehensive security policies without requiring manual user intervention, maintaining high network security while preserving ease of operation and user experience.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The application performs preliminary security actions such as automatic device hardening, pre-configuration of security policies, and proactive vulnerability patching before users encounter security issues. This preliminary action ensures comprehensive security enforcement while keeping the user experience smooth and uninterrupted.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If endpoint devices are allowed to access enterprise networks freely, then ease of operation is improved, but security risks from misconfigured devices increase

Engineering Contradiction:
Improveconnectivity accessVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The endpoint security application acts as an intermediary between the device and enterprise network, automatically assessing device security compliance and mediating network access accordingly. This intermediary function allows easy connectivity for compliant devices while blocking or remediating access from misconfigured devices, thereby reducing security risks without significantly impacting user experience.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The application performs preliminary security assessments and applies corrective actions (such as automatic firewall configuration or vulnerability patching) before the device attempts to access the enterprise network. This preliminary anti-action prevents misconfigured devices from compromising network security while maintaining ease of operation for properly configured devices.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP2403212B1Multi-service VPN network client for mobile device
Publication Date: 2017.11.29 PULSE SECURE LLC
  • EP2403212B1 patent drawingFigure 1
  • EP2403212B1 patent drawingFigure 2
  • EP2403212B1 patent drawingFigure 3

AI summary

An integrated, multi-service network client for cellular mobile devices is described. The multi-service network client can be deployed as a single software package on cellular mobile network devices to provide integrated services including secure enterprise virtual private network (VPN) connectivity, acceleration, security management including monitored and enforced endpoint compliance, and collaboration services. Once installed on the cellular mobile device, the multi-service client integrates with an operating system of the device to provide a single entry point for user authentication for secure enterprise connectivity, endpoint security services including endpoint compliance with respect to anti-virus and spyware software, and comprehensive integrity checks. That is, the multi-service client provides a common user interface to the integrated services, and provides a VPN handler that interfaces with the operating system to provide an entry point for network traffic to which the integrated services can be seamlessly applied.