Per-Application VPN Tunnel Policy Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for managing mobile devices in enterprise environments lack efficient control over application access to resources, authentication, and data security, particularly when devices access corporate intranets from foreign networks, as traditional VPNs do not discriminate between trusted and untrusted applications.

Innovation Solution

Implementing a per-application policy-controlled VPN tunnel system that uses tickets for authentication and policy management, allowing specific applications to access enterprise resources based on role-based policies, and enabling secure data encryption and selective wiping of enterprise data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional VPN is used to provide access to enterprise resources, then network access is provided, but security control over individual applications is lost

Engineering Contradiction:
Improveapplication-level access controlVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the traditional monolithic VPN connection into individual application-level tunnels. Each application receives its own dedicated tunnel with independent authentication and policy enforcement, allowing granular control over which applications can access which enterprise resources. This segmentation enables the system to provide both broad adaptability (different policies for different apps) and strong reliability (each tunnel is independently secured).

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying different security policies, authentication methods, and encryption parameters to each individual application tunnel rather than using a uniform approach for all applications. Each application can have customized security characteristics appropriate to its specific requirements and risk profile, enabling both versatile control and targeted security enforcement.

Inventive Principle:
Principle #3Local quality

2Reliability

If per-application VPN tunnels are created for each application, then security is enhanced, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the functionality of multiple individual application tunnels into a unified gateway system that manages all tunnels centrally. The access gateway consolidates authentication, policy enforcement, and tunnel management functions, reducing the complexity burden on individual applications while maintaining the security benefits of per-application tunnels. This combining approach allows the system to achieve high security without proportionally increasing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The access gateway acts as an intermediary between applications and enterprise resources, mediating all communication through centralized control points. This intermediary architecture simplifies the system by providing a single management interface for all application tunnels, handling authentication, policy enforcement, and tunnel establishment centrally rather than requiring complex distributed coordination between multiple independent components.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If authentication is required for each application connection, then security is maintained, but user experience deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by performing authentication once at the gateway level before applications establish their tunnels. The gateway pre-authenticates users and devices, then uses these preliminary authentication results to automatically establish secured application tunnels without requiring additional user interaction. This preliminary authentication maintains strong security verification while eliminating repeated authentication prompts that would degrade user experience.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service by automatically managing application tunnel establishment and authentication based on pre-configured policies. Once initial user authentication is complete, the system automatically provisions appropriate tunnels for applications without requiring manual user intervention or repeated authentication. The gateway autonomously handles tunnel configuration, security parameter selection, and connection management, maintaining security while providing a seamless user experience.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9973489B2Providing virtualized private network tunnels
Publication Date: 2018.05.15 CITRIX SYSTEMS INC
  • US9973489B2 patent drawing
  • US9973489B2 patent drawing
  • US9973489B2 patent drawing

AI summary

Various aspects of the disclosure relate to providing a per-application policy-controlled virtual private network (VPN) tunnel. In some embodiments, tickets may be used to provide access to an enterprise resource without separate authentication of the application and, in some instances, can be used in such a manner as to provide a seamless experience to the user when reestablishing a per-application policy controlled VPN tunnel during the lifetime of the ticket. Additional aspects relate to an access gateway providing updated policy information and tickets to a mobile device. Other aspects relate to selectively wiping the tickets from a secure container of the mobile device. Yet further aspects relate to operating applications in multiple modes, such as a managed mode and an unmanaged mode, and providing authentication-related services based on one or more of the above aspects.