Per-Application VPN Tunnel Policy Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions for managing mobile devices in enterprise environments lack efficient control over application access to resources, authentication, and data security, particularly when devices access corporate intranets from foreign networks, as traditional VPNs do not discriminate between trusted and untrusted applications.
Innovation Solution
Implementing a per-application policy-controlled VPN tunnel system that uses tickets for authentication and policy management, allowing specific applications to access enterprise resources based on role-based policies, and enabling secure data encryption and selective wiping of enterprise data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional VPN is used to provide access to enterprise resources, then network access is provided, but security control over individual applications is lost
Solution Approach 1:
The patent segments the traditional monolithic VPN connection into individual application-level tunnels. Each application receives its own dedicated tunnel with independent authentication and policy enforcement, allowing granular control over which applications can access which enterprise resources. This segmentation enables the system to provide both broad adaptability (different policies for different apps) and strong reliability (each tunnel is independently secured).
Solution Approach 2:
The patent implements local quality by applying different security policies, authentication methods, and encryption parameters to each individual application tunnel rather than using a uniform approach for all applications. Each application can have customized security characteristics appropriate to its specific requirements and risk profile, enabling both versatile control and targeted security enforcement.
2Reliability
If per-application VPN tunnels are created for each application, then security is enhanced, but system complexity increases
Solution Approach 1:
The patent merges the functionality of multiple individual application tunnels into a unified gateway system that manages all tunnels centrally. The access gateway consolidates authentication, policy enforcement, and tunnel management functions, reducing the complexity burden on individual applications while maintaining the security benefits of per-application tunnels. This combining approach allows the system to achieve high security without proportionally increasing overall system complexity.
Solution Approach 2:
The access gateway acts as an intermediary between applications and enterprise resources, mediating all communication through centralized control points. This intermediary architecture simplifies the system by providing a single management interface for all application tunnels, handling authentication, policy enforcement, and tunnel establishment centrally rather than requiring complex distributed coordination between multiple independent components.
3Reliability
If authentication is required for each application connection, then security is maintained, but user experience deteriorates
Solution Approach 1:
The patent implements preliminary action by performing authentication once at the gateway level before applications establish their tunnels. The gateway pre-authenticates users and devices, then uses these preliminary authentication results to automatically establish secured application tunnels without requiring additional user interaction. This preliminary authentication maintains strong security verification while eliminating repeated authentication prompts that would degrade user experience.
Solution Approach 2:
The system implements self-service by automatically managing application tunnel establishment and authentication based on pre-configured policies. Once initial user authentication is complete, the system automatically provisions appropriate tunnels for applications without requiring manual user intervention or repeated authentication. The gateway autonomously handles tunnel configuration, security parameter selection, and connection management, maintaining security while providing a seamless user experience.
Data Source
AI summary
Various aspects of the disclosure relate to providing a per-application policy-controlled virtual private network (VPN) tunnel. In some embodiments, tickets may be used to provide access to an enterprise resource without separate authentication of the application and, in some instances, can be used in such a manner as to provide a seamless experience to the user when reestablishing a per-application policy controlled VPN tunnel during the lifetime of the ticket. Additional aspects relate to an access gateway providing updated policy information and tickets to a mobile device. Other aspects relate to selectively wiping the tickets from a secure container of the mobile device. Yet further aspects relate to operating applications in multiple modes, such as a managed mode and an unmanaged mode, and providing authentication-related services based on one or more of the above aspects.


