Per-App VPN Encryption Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

VPN clients and endpoints typically employ an all-or-nothing approach to encryption, failing to provide varying levels of encryption based on ambient conditions such as geographic location or network type, which can compromise security when connecting to untrusted networks.

Innovation Solution

A framework that allows for per-app VPN configurations to specify encryption keys and levels based on ambient conditions, enabling flexible encryption management for network traffic routed through a tunnel client and endpoint, ensuring secure access to protected networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single encrypted tunnel is created for all network traffic, then setup simplicity is improved, but security is worsened because all traffic receives the same encryption level regardless of sensitivity

Engineering Contradiction:
ImproveVPN configuration simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments network traffic into different categories (sensitive and non-sensitive) and creates separate encrypted tunnels for each category. This allows different encryption levels to be applied to different types of traffic, resolving the contradiction by maintaining simplicity of individual tunnel configuration while achieving security through traffic segmentation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different encryption qualities to different portions of network traffic based on their sensitivity. Sensitive traffic receives higher encryption levels while non-sensitive traffic uses lower encryption levels, allowing each traffic type to have locally optimized security properties rather than forcing a uniform encryption level across all traffic.

Inventive Principle:
Principle #3Local quality

2Reliability

If high encryption levels are applied to all traffic, then security is improved, but processing overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments traffic into sensitive and non-sensitive categories, applying high encryption only to sensitive traffic. This segmentation reduces the total volume of traffic requiring high-level encryption, thereby reducing processing overhead while maintaining security for sensitive data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the encryption parameter (encryption level) based on traffic sensitivity. By adjusting the encryption parameter dynamically according to traffic type, the system achieves high security where needed while reducing processing overhead for less sensitive traffic.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If varying encryption levels are implemented for different applications, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidVPN management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments applications into categories (sensitive and non-sensitive) and associates each category with a specific encrypted tunnel. This segmentation approach simplifies management by providing clear rules for traffic routing while achieving varying encryption levels, thus resolving the contradiction between security and complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates multiple encrypted tunnels that can serve different application categories, with each tunnel having its own encryption level. This multi-functional approach allows the system to handle different security requirements through a standardized tunnel-based architecture, reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10785196B2Encryption key management of client devices and endpoints within a protected network
Publication Date: 2020.09.22 OMNISSA LLC
  • US10785196B2 patent drawing
  • US10785196B2 patent drawing
  • US10785196B2 patent drawing

AI summary

Disclosed are various examples for establishing encrypted channels or tunnels within a TCP or other communication session between a tunnel endpoint and tunnel client on a client device. A tunnel endpoint on the client device can determine an encryption key based upon whether a client device is in compliance with encryption policies of the enterprise.