Unified Mobile VPN Client for Endpoint Security and Acceleration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing use of cellular mobile devices for computer data services poses challenges for enterprises in enabling secure and easy connectivity, particularly due to misconfiguration issues that can lead to security risks and network conflicts, making it difficult for IT staff to provide seamless access across various devices and locations.
Innovation Solution
A secure VPN gateway system that includes a multi-service network client on cellular mobile devices, enabling secure, controlled access to enterprise networks through a VPN connection, which simplifies user experience by handling provisioning and security without requiring complex user interaction, and provides unified client functionality for VPN remote access, WAN acceleration, and endpoint compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users install multiple endpoint security and connectivity software applications on mobile devices, then security coverage is improved, but device complexity and network conflicts increase
Solution Approach 1:
The patent combines multiple security and connectivity software functions into a single unified endpoint security application. This consolidation provides comprehensive security coverage (antivirus, firewall, VPN, device hardening) while reducing the number of separate applications users must install and manage, thereby decreasing device complexity and potential network conflicts.
Solution Approach 2:
The endpoint security application is designed as a universal solution that performs multiple security functions simultaneously - antivirus scanning, firewall management, VPN connectivity, and device hardening. This multi-functional approach improves security coverage without requiring users to install separate specialized applications for each security function.
2Reliability
If IT staff implement comprehensive security policies and monitoring, then network security is improved, but ease of operation and user experience deteriorate
Solution Approach 1:
The endpoint security application implements self-service capabilities including automatic virus definition updates, automated vulnerability scanning, and self-configuring security policies. This automation allows IT staff to enforce comprehensive security policies without requiring manual user intervention, maintaining high network security while preserving ease of operation and user experience.
Solution Approach 2:
The application performs preliminary security actions such as automatic device hardening, pre-configuration of security policies, and proactive vulnerability patching before users encounter security issues. This preliminary action ensures comprehensive security enforcement while keeping the user experience smooth and uninterrupted.
3Ease of operation
If endpoint devices are allowed to access enterprise networks freely, then ease of operation is improved, but security risks from misconfigured devices increase
Solution Approach 1:
The endpoint security application acts as an intermediary between the device and enterprise network, automatically assessing device security compliance and mediating network access accordingly. This intermediary function allows easy connectivity for compliant devices while blocking or remediating access from misconfigured devices, thereby reducing security risks without significantly impacting user experience.
Solution Approach 2:
The application performs preliminary security assessments and applies corrective actions (such as automatic firewall configuration or vulnerability patching) before the device attempts to access the enterprise network. This preliminary anti-action prevents misconfigured devices from compromising network security while maintaining ease of operation for properly configured devices.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An integrated, multi-service network client for cellular mobile devices is described. The multi-service network client can be deployed as a single software package on cellular mobile network devices to provide integrated services including secure enterprise virtual private network (VPN) connectivity, acceleration, security management including monitored and enforced endpoint compliance, and collaboration services. Once installed on the cellular mobile device, the multi-service client integrates with an operating system of the device to provide a single entry point for user authentication for secure enterprise connectivity, endpoint security services including endpoint compliance with respect to anti-virus and spyware software, and comprehensive integrity checks. That is, the multi-service client provides a common user interface to the integrated services, and provides a VPN handler that interfaces with the operating system to provide an entry point for network traffic to which the integrated services can be seamlessly applied.