Multi-Tenant VPN Cloud for Mobile Security Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in securing corporate data on mobile devices due to blurred lines between personal and enterprise usage, the complexity of multiple mobile platforms, and the difficulty in enforcing security policies across various networks and devices, as traditional security measures are ineffective and resource-intensive.

Innovation Solution

A distributed, multi-tenant Virtual Private Network (VPN) cloud system that establishes VPN tunnels between mobile devices and enforcement nodes for real-time security analysis and policy enforcement, filtering data before it reaches the device, thereby ensuring security without the need for platform-specific applications or signature updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security applications are installed on mobile devices, then security protection is provided, but device performance deteriorates and user experience is degraded

Engineering Contradiction:
Improvesecurity protectionVSAvoiddevice performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the security analysis function from the mobile device and relocates it to a remote server. The mobile device only needs to establish a VPN connection and send traffic for analysis, while the computationally intensive security scanning, malware detection, and policy enforcement are performed remotely on the server infrastructure, thereby preserving device performance while maintaining security protection.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a VPN tunnel as an intermediary between the mobile device and the remote security server. All traffic passes through this encrypted tunnel to the server for analysis and policy enforcement, allowing security functions to be performed remotely without requiring direct installation or execution of security applications on the device itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If platform-specific security applications are developed for each mobile operating system, then security coverage is improved, but development complexity and costs increase

Engineering Contradiction:
Improveplatform coverageVSAvoiddevelopment complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal security solution that works across all mobile platforms by moving the security functionality to a platform-agnostic remote server. The server receives traffic from any mobile device regardless of its operating system through standard VPN protocols, eliminating the need to develop and maintain separate security applications for iOS, Android, Windows Mobile, and other platforms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements automatic policy updates and threat intelligence feedback loops where the server receives information about new threats and security policies, processes them centrally, and automatically pushes updated security rules to connected devices. This eliminates the need for manual updates on each platform and ensures consistent security across all devices.

Inventive Principle:
Principle #23Feedback

3Reliability

If security policies are enforced on mobile devices, then security compliance is improved, but ease of operation deteriorates due to constant updates and management overhead

Engineering Contradiction:
Improvesecurity complianceVSAvoidoperation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service security enforcement where the server automatically monitors traffic, detects policy violations, and enforces security rules without requiring user intervention. The mobile device simply connects to the VPN and allows traffic to flow through the server, which handles all security compliance tasks automatically in the background.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The server performs preliminary security analysis and policy enforcement actions before potentially blocking or allowing traffic. Threat intelligence, security policies, and compliance rules are pre-configured and continuously updated on the server, so when a device connects, security enforcement is already in place and ready to operate immediately without requiring setup or updates on the device itself.

Inventive Principle:
Principle #10Preliminary action

4Ease of operation

If enterprise data is accessed through uncontrolled wireless networks, then accessibility is improved, but security risk increases

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a VPN tunnel as an intermediary layer between the mobile device and enterprise data resources. Even when devices connect to uncontrolled public Wi-Fi or cellular networks, all traffic is encrypted and routed through the secure VPN tunnel to the enterprise server, which then provides controlled access to corporate data. This maintains accessibility while eliminating the security risks of uncontrolled networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8464335B1Distributed, multi-tenant virtual private network cloud systems and methods for mobile security and policy enforcement
Publication Date: 2013.06.11 ZSCALER INC
  • US8464335B1 patent drawing
  • US8464335B1 patent drawing
  • US8464335B1 patent drawing

AI summary

The present disclosure provides distributed, multi-tenant Virtual Private Network (VPN) cloud systems and methods for mobile security and user based policy enforcement. In an exemplary embodiment, plural mobile devices are configured to connect to one or more enforcement or processing nodes over VPN connections. The enforcement or processing nodes are configured to perform content filtering, policy enforcement, and the like on some or all of the traffic from the mobile devices. The present invention is described as multi-tenant as it can connect to plural clients across different companies with different policies in a single distributed system. Advantageously, the present invention allows smartphone and tablet users to protect themselves from mobile malware, without requiring a security applications on the device. It allows administrators to seamless enforce policy for a user regardless of the device or network they are connecting to, as well as get granular visibility into the user's network behavior.