NDIS Firewall VPN Enforcement for Mobile Endpoints

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Corporate computing assets face challenges in enforcing secure internet connections, especially in public or insecure locations, as existing tools lack the ability to confirm and enforce VPN usage, leading to security risks when devices move between locations.

Innovation Solution

Implementing a security policy that enforces a full VPN tunnel connection through an NDIS firewall, monitors packet traffic for compliance, and quarantines devices if policies are not met, with automatic remediation measures to ensure secure internet access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing tools launch VPN connections, then VPN connection capability is provided, but enforcement and confirmation of correct VPN usage is not achieved

Engineering Contradiction:
ImproveVPN usage enforcementVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where the system continuously monitors network traffic to verify VPN connection status and compliance. The policy enforcement module receives feedback about connection state and takes corrective actions (blocking traffic, alerting users) when compliance is not achieved, thereby ensuring reliable VPN usage enforcement without requiring complex manual verification procedures

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs self-verification by automatically monitoring its own network traffic and compliance state. The policy enforcement module autonomously detects whether VPN connections are properly established and maintained, and automatically blocks non-compliant traffic without requiring external verification, simplifying the overall system architecture while ensuring reliable enforcement

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If corporate assets connect in public locations, then mobility and accessibility are improved, but security risks increase

Engineering Contradiction:
Improvelocation flexibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a policy enforcement module as an intermediary between the corporate network and public networks. This module acts as a security gatekeeper that inspects all network traffic, enforces VPN connection requirements, and blocks unauthorized access attempts, thereby enabling location flexibility while maintaining security by filtering harmful factors before they reach the corporate network

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system applies preliminary anti-action by proactively blocking potentially harmful network traffic before it can compromise security. The policy enforcement module pre-establishes security policies that automatically prevent connections to known malicious networks and block traffic from unsecured locations, countering security risks before they materialize while allowing legitimate mobile access

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If VPN tunnel connections are established, then secure communication is achieved, but packet traffic monitoring and compliance verification become complex

Engineering Contradiction:
Improvecommunication securityVSAvoidcompliance verification
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies preliminary action by pre-configuring the policy enforcement module with compliance criteria and monitoring rules before VPN connections are established. The system proactively sets up traffic filtering policies and compliance verification mechanisms in advance, making it easier to detect and measure compliance status without requiring complex real-time analysis of encrypted VPN traffic

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8387131B2Enforcing secure internet connections for a mobile endpoint computing device
Publication Date: 2013.02.26 MICRO FOCUS SOFTWARE INC
  • US8387131B2 patent drawing
  • US8387131B2 patent drawing
  • US8387131B2 patent drawing

AI summary

Methods and apparatus enforce a secure internet connection from a mobiles endpoint computing device. A security policy for the endpoint is defined based on its location. From that location, an internet connection is established and detected. This event triggers the launching of a full VPN tunnel connection including an NDIS firewall forcing packet traffic through a port of the endpoint computing device assigned by the security policy and/or MAC/IP addresses of a VPN concentrator. Thereafter, the packet traffic is monitored for compliance with the security policy. This includes determining whether packet traffic over the assigned port is observed within a given time or packet traffic is attempted over other ports. Monitoring occurs whether or not the protocol of the VPN tunnel connection is known. Other features contemplate quarantining for improper operation of the VPN tunnel, undertaking remediation, and computer program products, to name a few.