Application-Policing Mobile VPN Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional virtual private networks (VPNs) on mobile devices grant all applications equal authorization for network access, posing security risks due to broad authorization, especially with applications from unknown developers, and fail to discriminate between privileged and non-privileged applications, potentially allowing unauthorized access to restricted information.

Innovation Solution

A secure mobile communication system that establishes a VPN between a mobile device and a server, discriminates between trusted and untrusted applications by blocking data transmission from untrusted applications, authenticates trusted applications, and encrypts data packets using certificates and private keys, enforcing network policies to ensure secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional VPN grants all applications equal authorization for network access, then network accessibility is improved, but security deteriorates due to broad authorization and inability to discriminate between privileged and non-privileged applications

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments network access authorization by application, creating distinct authorization levels for different applications. The system divides the previously unified VPN access into multiple authorized channels, with each application receiving access rights appropriate to its trust level and intended function, thereby maintaining security while preserving necessary accessibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by assigning different authorization characteristics to different applications based on their specific needs and trust levels. Each application receives customized access permissions rather than uniform authorization, allowing privileged applications to access restricted information while preventing untrusted applications from doing so.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If VPN allows all applications to communicate with server, then ease of operation is improved, but harmful factors increase due to potential unauthorized access and data injection

Engineering Contradiction:
Improveapplication connectivityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent implements preliminary action by establishing application authorization policies before VPN connections are established. The system pre-configures which applications are permitted to access the VPN and under what conditions, preventing unauthorized applications from attempting connections in the first place and eliminating the security risk before it can materialize.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authorization mechanism between applications and the VPN connection. This intermediary layer validates each application's right to access the VPN based on predefined policies, acting as a gatekeeper that allows legitimate traffic while blocking potentially harmful applications without affecting the operation of trusted applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If VPN implements application-level authorization, then security is improved, but device complexity increases due to authentication and certificate management

Engineering Contradiction:
ImprovesecurityVSAvoidauthorization system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by enabling applications to autonomously establish their authorization status with the VPN system. Trusted applications can self-authenticate using pre-configured credentials or certificates, eliminating the need for manual administrative intervention for each connection attempt and reducing the operational complexity of managing application-level authorization.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8918860B1Systems and methods for application-policing a VPN
Publication Date: 2014.12.23 CA TECH INC
  • US8918860B1 patent drawing
  • US8918860B1 patent drawing
  • US8918860B1 patent drawing

AI summary

A computer-implemented method for establishing secure mobile communications is described. A virtual private network (VPN) between a mobile device and a server is established. A transmission of at least a portion of data between a first application and the server is blocked. It is determined whether the first application on the mobile device is a trusted application. Upon determining the first application is an untrusted application, a transmission of at least a portion of data between the untrusted application and the server continues to be blocked.