Per-App VPN Encryption Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
VPN clients and endpoints typically employ an all-or-nothing approach to encryption, failing to provide varying levels of encryption based on ambient conditions such as geographic location or network type, which can compromise security when connecting to untrusted networks.
Innovation Solution
A framework that allows for per-app VPN configurations to specify encryption keys and levels based on ambient conditions, enabling flexible encryption management for network traffic routed through a tunnel client and endpoint, ensuring secure access to protected networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a single encrypted tunnel is created for all network traffic, then setup simplicity is improved, but security is worsened because all traffic receives the same encryption level regardless of sensitivity
Solution Approach 1:
The patent segments network traffic into different categories (sensitive and non-sensitive) and creates separate encrypted tunnels for each category. This allows different encryption levels to be applied to different types of traffic, resolving the contradiction by maintaining simplicity of individual tunnel configuration while achieving security through traffic segmentation.
Solution Approach 2:
The patent applies different encryption qualities to different portions of network traffic based on their sensitivity. Sensitive traffic receives higher encryption levels while non-sensitive traffic uses lower encryption levels, allowing each traffic type to have locally optimized security properties rather than forcing a uniform encryption level across all traffic.
2Reliability
If high encryption levels are applied to all traffic, then security is improved, but processing overhead increases
Solution Approach 1:
The patent segments traffic into sensitive and non-sensitive categories, applying high encryption only to sensitive traffic. This segmentation reduces the total volume of traffic requiring high-level encryption, thereby reducing processing overhead while maintaining security for sensitive data.
Solution Approach 2:
The patent changes the encryption parameter (encryption level) based on traffic sensitivity. By adjusting the encryption parameter dynamically according to traffic type, the system achieves high security where needed while reducing processing overhead for less sensitive traffic.
3Reliability
If varying encryption levels are implemented for different applications, then security is improved, but device complexity increases
Solution Approach 1:
The patent segments applications into categories (sensitive and non-sensitive) and associates each category with a specific encrypted tunnel. This segmentation approach simplifies management by providing clear rules for traffic routing while achieving varying encryption levels, thus resolving the contradiction between security and complexity.
Solution Approach 2:
The patent creates multiple encrypted tunnels that can serve different application categories, with each tunnel having its own encryption level. This multi-functional approach allows the system to handle different security requirements through a standardized tunnel-based architecture, reducing overall system complexity while maintaining security.
Data Source
AI summary
Disclosed are various examples for establishing encrypted channels or tunnels within a TCP or other communication session between a tunnel endpoint and tunnel client on a client device. A tunnel endpoint on the client device can determine an encryption key based upon whether a client device is in compliance with encryption policies of the enterprise.


