Split Tunneling Packet Forwarding Security Rule Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing split tunneling techniques have limitations when applied to packets destined for unspecified destinations, as they often rely on IP, port, or domain name-based decisions, which can be inefficient and restrictive.

Innovation Solution

A method where packets are encapsulated and transmitted to a packet forwarding server, with the source address changed to that of the packet forwarding server, allowing for dynamic determination of whether to include or exclude packets from the VPN tunnel based on security rules that inspect specific elements of the packet, such as protocol information, port numbers, and version information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all transmitted data is included in the VPN tunnel, then data transmission security is improved, but transmission efficiency deteriorates

Engineering Contradiction:
Improvedata transmission securityVSAvoidtransmission efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments traffic into two categories: traffic that requires VPN tunneling for security and traffic that can bypass the tunnel for efficiency. The split tunneling device divides the network traffic flow, applying different transmission paths to different segments, thereby simultaneously achieving security for sensitive data and efficiency for non-sensitive data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different quality characteristics to different parts of the traffic flow. Specifically, it applies security-oriented VPN tunneling to certain traffic segments while applying efficiency-oriented direct transmission to other segments, based on local traffic characteristics and security requirements.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If existing split tunneling techniques are applied to packets with unspecified destinations, then routing flexibility is improved, but decision accuracy deteriorates

Engineering Contradiction:
Improverouting flexibilityVSAvoiddecision accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent performs preliminary actions by establishing default routing rules and security policies before packets with unspecified destinations need to be routed. The split tunneling device pre-configures decision criteria and security parameters, enabling rapid and accurate routing decisions without requiring complex real-time analysis of destination information.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If packet inspection is performed on multiple elements, then security rule accuracy is improved, but processing complexity increases

Engineering Contradiction:
Improvesecurity rule accuracyVSAvoidprocessing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the packet inspection process into distinct stages, examining different elements (such as source address, destination address, port numbers, protocol types) in a structured sequence. This segmented approach allows comprehensive security analysis while organizing complexity into manageable, modular inspection steps.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic inspection depth adjustment based on traffic characteristics. The system adaptively determines how many packet elements require inspection for each flow, increasing inspection depth for suspicious or high-risk traffic while reducing inspection overhead for trusted or low-risk traffic, thereby balancing accuracy and complexity.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12255873B2Method and device for split tunneling
Publication Date: 2025.03.18 SAMSUNG ELECTRONICS CO LTD
  • US12255873B2 patent drawing
  • US12255873B2 patent drawing
  • US12255873B2 patent drawing

AI summary

An electronic device may obtain a security rule for supporting split tunneling, check a condition for executing a first operation related to bypassing the VPN tunnel by comparing a first value to information based on a first offset in a first element of the packet based on the security rule, check a condition for performing a second operation related to bypassing the VPN tunnel by comparing a second value to information based on a second offset in a second element of the packet when the condition for executing the first operation is satisfied and the first operation instructs that the second element of the packet be inspected, encapsulate the packet while not including the packet in the VPN tunnel and transmit the encapsulated packet to a packet forwarding server, and include the packet in the VPN tunnel and transmit the packet to the packet forwarding server.