Per-Application VPN Policy Enforcement via Virtual NICs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtualized environments, manually configuring VPN access for each application is cumbersome and insecure, especially in dynamic desktop pools where applications are delivered in real-time, leading to impractical administrative efforts and potential security breaches.
Innovation Solution
Implementing network virtualization software to automatically assign and manage VPN tunnels on a per-application basis by creating virtual network interface cards (NICs) and enforcing VPN policies through in-guest operating system scripts, allowing seamless and secure access to VPN connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual VPN configuration is implemented on each desktop, then per-application VPN access control is achieved, but administrative complexity and time consumption increase significantly
Solution Approach 1:
The patent introduces a network virtualization layer as an intermediary between the physical network infrastructure and the virtual desktops. This layer includes virtual network interface cards (vNICs) and virtual switches that automatically handle VPN tunneling, eliminating the need for manual VPN configuration on each desktop while maintaining security control through centralized policy management.
Solution Approach 2:
The system enables automatic VPN tunnel establishment through integration with the virtual desktop infrastructure. When a desktop is provisioned or updated with new applications, the system automatically detects VPN requirements and configures appropriate tunnels without human intervention, allowing the infrastructure to self-configure based on application needs.
2Ease of operation
If VPN is enabled for all applications, then access to private resources is simplified, but security control over specific applications is lost
Solution Approach 1:
The patent segments network connectivity by creating separate virtual network interface cards for different applications. Each vNIC is associated with specific applications and configured with appropriate VPN policies, allowing granular control over which applications can access private resources while maintaining simple user experience through automatic routing.
Solution Approach 2:
The system applies different network security qualities to different applications locally. Each application receives customized VPN access rights through its associated vNIC configuration, enabling security policies to be tailored to specific application requirements rather than applying a blanket approach to all applications.
3Productivity
If desktop pools are made floating and applications delivered in real-time, then resource utilization improves, but VPN configuration becomes impractical
Solution Approach 1:
The system performs preliminary configuration of VPN capabilities at the virtualization layer before applications are delivered to desktops. The network virtualization infrastructure is pre-configured with VPN tunneling capabilities and policies, so when applications are dynamically assigned to floating desktops, VPN access is automatically available without requiring post-delivery configuration.
Solution Approach 2:
The network virtualization layer provides universal VPN functionality that serves all applications and desktops uniformly. By implementing VPN capabilities in the virtualization infrastructure rather than at the application or desktop level, the system achieves a single solution that works across all dynamically provisioned desktops and applications, enabling both resource efficiency and configuration simplicity.
Data Source
AI summary
A VPN tunnel policy is defined on a per-application basis. The VPN tunnel policy may specify that a particular application is permitted to transmit data on a specific VPN tunnel. Subsequently, the specified application is delivered to one or more virtual machines and an application tunnel manager creates a new virtual network interface card (NIC) on the VM, corresponding to the delivered application. The newly created virtual NIC is attached to a specified subnet. The subnet may be a VPN transition network with a connection to a VPN gateway device. The subnet may have been previously defined or generated at the time of assigning the application to the VPN tunnel. Once the virtual NIC has been created on the VM, an OS script is executed to force the delivered application to use the newly created virtual NIC and to prevent users from changing the application and virtual NIC linkage.


