Multi-service VPN Client for Mobile Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing use of cellular mobile devices for computer data services poses challenges for enterprises in enabling secure and easy connectivity, particularly due to misconfiguration issues that can lead to security risks and network conflicts, making it difficult for IT staff to provide seamless access across various devices and locations.

Innovation Solution

A secure VPN gateway system that includes a multi-service network client on cellular mobile devices, enabling secure, anytime/anywhere connectivity with integrated acceleration and security features, simplifying user experience by handling provisioning and deployment automatically, and allowing granular security policies and role-based access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple endpoint security and connectivity software applications are added to mobile devices, then security coverage is improved, but device complexity and network conflicts increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsoftware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security and connectivity software applications into a single integrated endpoint security appliance. This consolidation maintains comprehensive security coverage while reducing device complexity by eliminating the need for multiple separate applications and their associated configurations.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The endpoint security appliance is designed to perform multiple functions including antivirus, firewall, and connectivity management within a single device. This multi-functionality approach provides comprehensive security coverage without requiring multiple specialized applications, thereby reducing overall software complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If users are given full configuration freedom on mobile devices, then ease of operation is improved, but security risks increase due to misconfiguration

Engineering Contradiction:
Improveuser configuration freedomVSAvoidsecurity security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements automatic configuration and provisioning of security settings through the endpoint security appliance. The appliance autonomously manages security parameters and connectivity settings, providing ease of operation through simplified user interfaces while eliminating security risks associated with manual misconfiguration.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The endpoint security appliance continuously monitors device configuration status and provides real-time feedback to users. When misconfiguration is detected, the system automatically adjusts settings or notifies users, maintaining security integrity while preserving user operational freedom through intelligent oversight.

Inventive Principle:
Principle #23Feedback

3Reliability

If IT staff implement comprehensive security policies, then security reliability is improved, but ease of operation deteriorates due to complex provisioning requirements

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidprovisioning complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The endpoint security appliance acts as an intermediary between IT staff's security policies and mobile device operations. It translates complex security requirements into automated configuration actions, maintaining high security reliability while simplifying provisioning for IT staff through centralized management interfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary configuration of security settings and policies before devices are deployed to users. By pre-configuring security parameters and connectivity settings through the endpoint security appliance, the system ensures security reliability is established upfront while eliminating complex provisioning tasks during deployment.

Inventive Principle:
Principle #10Preliminary action

4Speed

If acceleration services are added to improve network performance, then speed is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork access speedVSAvoidclient software complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent integrates acceleration services into the unified endpoint security appliance alongside security functions. This consolidation provides network performance acceleration while avoiding increased device complexity by sharing common infrastructure and management mechanisms with existing security components.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2403206B1Multi-service VPN network client for mobile device having integrated acceleration
Publication Date: 2017.11.22 PULSE SECURE LLC
  • EP2403206B1 patent drawingFigure 1
  • EP2403206B1 patent drawingFigure 2
  • EP2403206B1 patent drawingFigure 3

AI summary

An integrated, multi-service virtual private network (VPN) network client for cellular mobile devices is described. The multi-service network client can be deployed as a single software package on cellular mobile network devices to provide integrated services including secure enterprise VPN connectivity, acceleration, security management including monitored and enforced endpoint compliance, and collaboration services. The multi-service client integrates with an operating system of the device to provide a VPN handler to establish a VPN connection with a remote VPN security device. The VPN network client includes to data acceleration module exchange network packets with the VPN handler and apply at least one acceleration service to the network packets, and a VPN control application that provides a unified user interface that allows a user to configure both the VPN handler and the data acceleration module.