Per-Application Split-Tunneled Proxy for Network Traffic Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current operating systems, such as Microsoft Windows, do not provide fine-grained VPN support, resulting in all applications being subject to the same VPN settings, which can lead to inefficient use of network resources as different applications have varying VPN access requirements.
Innovation Solution
Implementing a system that allows for split-tunneled network connectivity on a per-application basis, where each application can have its network traffic routed based on specific rules, such as destination hostname or IP address, using a network driver, tunnel client, and DNS resolver to manage routing policies and intercept network traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all applications use the same VPN configuration, then VPN access is simplified and reliably provided to all applications, but network resource efficiency deteriorates because applications with different VPN requirements cannot be differentiated
Solution Approach 1:
The patent segments the monolithic VPN configuration into application-specific VPN configurations. Each application can have its own routing rules, DNS settings, and tunnel parameters, allowing differentiated treatment of applications with different VPN requirements while maintaining reliable VPN access for each through its customized configuration.
Solution Approach 2:
The patent applies local quality by allowing different VPN parameters and routing rules to be assigned to different applications based on their specific needs. For example, email clients can have strict VPN routing while web browsers can have more flexible routing, optimizing network resource usage for each application's specific requirements.
2Loss of energy
If a per-application VPN configuration system is implemented, then network resource efficiency is improved by routing only necessary traffic through VPN, but device complexity increases due to multiple routing policies and configuration management
Solution Approach 1:
The patent introduces an intermediary component (tunnel client or network driver) that automatically manages the complex routing policies. This intermediary intercepts network traffic, determines the appropriate VPN configuration for each application, and handles the routing decisions, thereby reducing the perceived complexity for users while maintaining efficient per-application routing.
Solution Approach 2:
The system implements self-service by allowing applications to automatically receive appropriate VPN configurations based on their identity and requirements. The tunnel client automatically identifies applications, selects appropriate routing policies, and configures VPN parameters without requiring manual user intervention for each application, thus managing complexity internally while maintaining simplicity externally.
3Ease of operation
If a single DNS resolver is used by all applications, then DNS resolution is simplified and consistently provided, but adaptability deteriorates because different applications cannot use different DNS resolvers for their specific needs
Solution Approach 1:
The patent segments the single DNS resolver into multiple application-specific DNS resolvers. Each application can be assigned its own DNS resolver configuration, allowing different applications to query different DNS servers based on their requirements while maintaining simple DNS resolution operations within each application's context.
Solution Approach 2:
The patent applies local quality by allowing different DNS resolver configurations to be assigned to different applications. For example, internal applications can use an internal DNS resolver while external applications use public DNS resolvers, providing adaptability for each application's specific DNS needs while maintaining operational simplicity through automatic configuration.
Data Source
AI summary
Disclosed are various embodiments for providing split-tunneled network connectivity on a per-application basis. A request to make a connection, such as a transmission control protocol (TCP) or a universal datagram protocol (UDP) connection, to a remote host specified by an internet protocol (IP) address in the request is received from a network driver. A hostname lookup table is queried to determine a hostname associated with the IP address for the remote host. A policy is identified based on the hostname associated with the IP address for the remote host. Then, the connection is routed based on the policy.


