Persistent VPN Endpoint Security Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices frequently roam between various computer networks, often accessing unsecured or minimally secured networks, which poses a significant challenge for network security, especially in corporate and "bring your own device" environments.
Innovation Solution
Establishing a persistent virtual private network (VPN) connection between an endpoint device and a security server, with the endpoint device configured to automatically establish this connection upon network connectivity, and providing a network address translation (NAT) firewall service to secure data communications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If mobile devices roam between multiple networks, then network accessibility and versatility are improved, but security protection deteriorates
Solution Approach 1:
The patent introduces a security server as an intermediary between the mobile device and the network. The server establishes a persistent VPN connection with the device and inspects all data packets before they reach the network or return to the device. This intermediary security server maintains consistent security protection across multiple networks without requiring the device itself to have security capabilities installed.
Solution Approach 2:
The patent implements preliminary security actions by establishing a persistent VPN connection before the device connects to any network. The security server proactively inspects packets and enforces security rules before malicious content can reach the device, rather than relying on post-infection detection or device-based prevention mechanisms.
2Reliability
If device-based firewalls and security software are installed, then security protection is improved, but device complexity and ease of operation deteriorate
Solution Approach 1:
The patent extracts the security function from the mobile device and relocates it to a centralized security server. Instead of installing firewalls, intrusion detection systems, and security software on the device, these functions are performed remotely by the server, which then communicates security decisions to the device without requiring any complex local security infrastructure.
Solution Approach 2:
The mobile device performs self-service by automatically establishing the persistent VPN connection to the security server upon network connectivity without requiring user intervention. The device also automatically forwards all data packets through the server for inspection, eliminating the need for manual security configuration while maintaining comprehensive protection.
3Reliability
If network security inspection is performed for all data packets, then security protection is improved, but processing time and productivity deteriorate
Solution Approach 1:
The patent maintains continuous security inspection of all data packets as they pass through the security server, ensuring that security protection is applied consistently without interruption. The server continuously monitors packet content against security rules and maintains the persistent VPN connection throughout the data transmission process, preventing security gaps while managing performance through efficient inspection mechanisms.
Data Source
AI summary
A method for automatically securing endpoint device data communications includes establishing, between a first server and an endpoint device, a persistent virtual private network (VPN) connection, the endpoint device configured to automatically establish the persistent VPN connection upon establishing network connectivity. The first server provides, for the endpoint device, a network address translation (NAT) firewall service. The first server receives a plurality of data packets from a third computing device. The first server inspects each of the received plurality of data packets. The first server determines whether to block one of the plurality of data packets or to forward the one of the plurality of data packets to the second computing device. The first server blocks the one of the plurality of data packets based upon a determination that the one of the plurality of data packets fails to satisfy a security rule.


