Remote Proximity Control for Secure VPN Access Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VPN systems face challenges in managing network traffic effectively when the web application firewall (WAF) API is not provided or is incorrect, leading to potential denial of necessary traffic or allowance of malicious traffic.

Innovation Solution

Implementing a system that allows for remote governance of VPN access using a device separate from the VPN endpoint, which initiates and terminates VPN connections based on the relative distance between devices, using proximity-based controls to manage VPN connections and prevent insecure active connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a WAF uses an API to identify expected network traffic, then traffic filtering accuracy is improved, but the system becomes vulnerable when the API is not provided or is incorrect

Engineering Contradiction:
Improvetraffic filtering accuracyVSAvoidsystem reliability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces a remote device as an intermediary between the endpoint device and the WAF. This remote device determines proximity to the endpoint and sends control messages to initiate or terminate VPN connections. The WAF receives API information from this intermediary rather than directly from the endpoint, providing an additional verification layer that improves reliability when the original API is unavailable or incorrect.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual VPN initiation is required at the endpoint device, then connection security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveconnection securityVSAvoidoperation convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables automatic VPN connection management where the endpoint device itself initiates and terminates VPN connections based on proximity detection messages from the remote device. The endpoint device autonomously responds to proximity-based control messages without requiring manual user intervention, combining automated security enforcement with operational convenience.

Inventive Principle:
Principle #25Self-service

3Reliability

If physical presence at the endpoint is required for VPN management, then security control is improved, but adaptability deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoidremote management capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions VPN management from a single-location (endpoint-only) model to a multi-dimensional model where a remote device can initiate and control VPN connections wirelessly. By adding the spatial dimension of remote device proximity detection, the system maintains security control through proximity verification while enabling remote management capabilities without requiring physical presence at the endpoint.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11792043B2Systems and methods for governing VPN access using a remote device in proximity to a VPN endpoint
Publication Date: 2023.10.17 FORTINET INC
  • US11792043B2 patent drawing
  • US11792043B2 patent drawing
  • US11792043B2 patent drawing

AI summary

Various embodiments provide for governing VPN access using a device remote from a VPN endpoint.