Per-Application VPN Policy Enforcement via Virtual NICs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized environments, manually configuring VPN access for each application is cumbersome and insecure, especially in dynamic desktop pools where applications are delivered in real-time, leading to impractical administrative efforts and potential security breaches.

Innovation Solution

Implementing network virtualization software to automatically assign and manage VPN tunnels on a per-application basis by creating virtual network interface cards (NICs) and enforcing VPN policies through in-guest operating system scripts, allowing seamless and secure access to VPN connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual VPN configuration is implemented on each desktop, then per-application VPN access control is achieved, but administrative complexity and time consumption increase significantly

Engineering Contradiction:
ImproveVPN access control securityVSAvoidadministrative configuration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces a network virtualization layer as an intermediary between the physical network infrastructure and the virtual desktops. This layer includes virtual network interface cards (vNICs) and virtual switches that automatically handle VPN tunneling, eliminating the need for manual VPN configuration on each desktop while maintaining security control through centralized policy management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables automatic VPN tunnel establishment through integration with the virtual desktop infrastructure. When a desktop is provisioned or updated with new applications, the system automatically detects VPN requirements and configures appropriate tunnels without human intervention, allowing the infrastructure to self-configure based on application needs.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If VPN is enabled for all applications, then access to private resources is simplified, but security control over specific applications is lost

Engineering Contradiction:
ImproveVPN access simplicityVSAvoidapplication-specific security control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments network connectivity by creating separate virtual network interface cards for different applications. Each vNIC is associated with specific applications and configured with appropriate VPN policies, allowing granular control over which applications can access private resources while maintaining simple user experience through automatic routing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies different network security qualities to different applications locally. Each application receives customized VPN access rights through its associated vNIC configuration, enabling security policies to be tailored to specific application requirements rather than applying a blanket approach to all applications.

Inventive Principle:
Principle #3Local quality

3Productivity

If desktop pools are made floating and applications delivered in real-time, then resource utilization improves, but VPN configuration becomes impractical

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidVPN configuration feasibility
Core Design Contradiction:
ProductivityVSEase of manufacture

Solution Approach 1:

The system performs preliminary configuration of VPN capabilities at the virtualization layer before applications are delivered to desktops. The network virtualization infrastructure is pre-configured with VPN tunneling capabilities and policies, so when applications are dynamically assigned to floating desktops, VPN access is automatically available without requiring post-delivery configuration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network virtualization layer provides universal VPN functionality that serves all applications and desktops uniformly. By implementing VPN capabilities in the virtualization infrastructure rather than at the application or desktop level, the system achieves a single solution that works across all dynamically provisioned desktops and applications, enabling both resource efficiency and configuration simplicity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10447656B2Enforcing per-application VPN policies for applications delivered in virtualized computing environments
Publication Date: 2019.10.15 OMNISSA LLC
  • US10447656B2 patent drawing
  • US10447656B2 patent drawing
  • US10447656B2 patent drawing

AI summary

A VPN tunnel policy is defined on a per-application basis. The VPN tunnel policy may specify that a particular application is permitted to transmit data on a specific VPN tunnel. Subsequently, the specified application is delivered to one or more virtual machines and an application tunnel manager creates a new virtual network interface card (NIC) on the VM, corresponding to the delivered application. The newly created virtual NIC is attached to a specified subnet. The subnet may be a VPN transition network with a connection to a VPN gateway device. The subnet may have been previously defined or generated at the time of assigning the application to the VPN tunnel. Once the virtual NIC has been created on the VM, an OS script is executed to force the delivered application to use the newly created virtual NIC and to prevent users from changing the application and virtual NIC linkage.