Selective VPN Proxy Routing for Application-Specific Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional VPNs route all network traffic through a tunnel, leading to significant latency, packet loss, and reduced throughput on slow connections, compromising user experience despite having high bandwidth access to non-VPN resources.

Innovation Solution

Implementing a proxy that selectively routes only certain network traffic through a VPN, using VPN software to distinguish between applications that require VPN protection and those that do not, establishing a secure connection via the proxy to a VPN server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all network traffic is routed through a VPN tunnel, then security and privacy of network traffic is improved, but latency increases and throughput decreases

Engineering Contradiction:
Improvesecurity and privacyVSAvoidthroughput
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent segments network traffic into different categories: traffic requiring VPN protection (first set of applications) and traffic not requiring VPN protection (second set of applications). This segmentation allows selective routing through the VPN tunnel, improving throughput for non-sensitive traffic while maintaining security for sensitive traffic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different quality treatments to different portions of network traffic based on their security requirements. Critical traffic receives full VPN protection while non-critical traffic bypasses the VPN, creating local quality differentiation in the network routing system.

Inventive Principle:
Principle #3Local quality

2Reliability

If all network traffic is routed through a VPN tunnel, then security and privacy of network traffic is improved, but user experience deteriorates

Engineering Contradiction:
Improvesecurity and privacyVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically segments traffic based on application identification, transparently routing only necessary traffic through the VPN while allowing other traffic to proceed normally. This segmentation improves user experience by eliminating the performance degradation that would otherwise affect all applications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The VPN system performs automatic application identification and traffic classification without requiring user intervention. The system self-manages the routing decisions, automatically optimizing performance while maintaining security, thereby improving ease of operation.

Inventive Principle:
Principle #25Self-service

3Reliability

If all network traffic is routed through a VPN tunnel, then protection of network traffic is improved, but data transmission performance deteriorates

Engineering Contradiction:
ImproveprotectionVSAvoiddata transmission performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent divides network traffic into protected and unprotected segments based on application type and security requirements. This segmentation enables parallel processing where sensitive traffic receives full protection while non-sensitive traffic maintains high transmission performance, thereby improving overall data transmission productivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically changes routing parameters based on traffic analysis, switching between VPN-protected routing and direct routing depending on the application and traffic characteristics. This parameter adjustment optimizes data transmission performance while maintaining necessary protection levels.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12432180B2Selective virtual private network
Publication Date: 2025.09.30 SERVICENOW INC
  • US12432180B2 patent drawing
  • US12432180B2 patent drawing
  • US12432180B2 patent drawing

AI summary

A connection request is received from a client to establish a first connection associated with a second connection of a virtual private network for selective network communications of a first group of one or more applications of the client. Network communications of a second group of one or more applications different from the first group of one or more applications of the client are to be routed outside the virtual private network. The second connection of the virtual private network is established between a proxy and a virtual private network server. The first connection is established between the proxy and the client. A network packet received from the client via the first connection is routed to the virtual private network server via the second connection of the virtual private network.