Per-Application VPN Tunneling for Mobile Enterprise Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional VPN solutions lack the ability to discriminate between authorized and unauthorized applications on mobile devices, allowing rogue applications to access enterprise resources and potentially infiltrate the server, leading to security breaches.
Innovation Solution
Implementing a per-application VPN solution that tags network traffic to identify authorized applications and restrict access to enterprise resources, allowing only authorized applications to access the VPN, while providing secure data storage and malware protection without requiring device rooting or modification of third-party applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional VPN solutions are used to allow mobile devices to access enterprise resources, then remote access capability is improved, but security is worsened because unauthorized applications can access enterprise resources
Solution Approach 1:
The patent segments the VPN access control from the device level to the application level. Instead of controlling access at the operating system level where all applications share equal access, the invention creates individual VPN tunnels for each authorized application. This segmentation allows the system to maintain remote access capability while preventing unauthorized applications from accessing enterprise resources, as each application must be individually authorized to create its own VPN tunnel.
2Ease of operation
If device-level VPN access is granted to all applications, then ease of access is improved, but harmful factors increase because rogue applications can infiltrate the server
Solution Approach 1:
The patent introduces an intermediary component - the VPN manager - that acts as a mediator between applications and enterprise resources. The VPN manager receives requests from applications, verifies their authorization status, and selectively establishes VPN tunnels only for authorized applications. This intermediary prevents rogue applications from directly accessing enterprise resources, as any access attempt must pass through the VPN manager's authorization check, thereby eliminating security threats while maintaining convenient access for legitimate applications.
3Reliability
If per-application VPN filtering is implemented, then security is improved, but device complexity increases due to traffic analysis and tagging requirements
Solution Approach 1:
The patent implements a self-service mechanism where authorized applications automatically register themselves with the VPN manager and obtain their own VPN tunnel credentials. The system uses existing application identifiers and routing information that are already available in the mobile operating system, eliminating the need for complex external tagging mechanisms. The VPN manager automatically matches routing data to authorized applications and establishes tunnels without requiring manual configuration or complex analysis, thereby achieving enhanced security while minimizing additional system complexity.
Data Source
AI summary
Described are systems and methods for managing network packet traffic between a client device and an enterprise server. A list of enterprise-authorized applications is maintained. Data packets, such as TCP and UDP data packets, communicated from applications running on the device are analyzed to determine an originating application corresponding to each packet. The originating application is compared to the list of authorized applications, and a VPN tunnel is created for the packet to access the enterprise server if the corresponding originating application is an authorized application.


