Application-Policing Mobile VPN Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional virtual private networks (VPNs) on mobile devices grant all applications equal authorization for network access, posing security risks due to broad authorization, especially with applications from unknown developers, and fail to discriminate between privileged and non-privileged applications, potentially allowing unauthorized access to restricted information.
Innovation Solution
A secure mobile communication system that establishes a VPN between a mobile device and a server, discriminates between trusted and untrusted applications by blocking data transmission from untrusted applications, authenticates trusted applications, and encrypts data packets using certificates and private keys, enforcing network policies to ensure secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional VPN grants all applications equal authorization for network access, then network accessibility is improved, but security deteriorates due to broad authorization and inability to discriminate between privileged and non-privileged applications
Solution Approach 1:
The patent segments network access authorization by application, creating distinct authorization levels for different applications. The system divides the previously unified VPN access into multiple authorized channels, with each application receiving access rights appropriate to its trust level and intended function, thereby maintaining security while preserving necessary accessibility.
Solution Approach 2:
The patent applies local quality by assigning different authorization characteristics to different applications based on their specific needs and trust levels. Each application receives customized access permissions rather than uniform authorization, allowing privileged applications to access restricted information while preventing untrusted applications from doing so.
2Ease of operation
If VPN allows all applications to communicate with server, then ease of operation is improved, but harmful factors increase due to potential unauthorized access and data injection
Solution Approach 1:
The patent implements preliminary action by establishing application authorization policies before VPN connections are established. The system pre-configures which applications are permitted to access the VPN and under what conditions, preventing unauthorized applications from attempting connections in the first place and eliminating the security risk before it can materialize.
Solution Approach 2:
The patent introduces an intermediary authorization mechanism between applications and the VPN connection. This intermediary layer validates each application's right to access the VPN based on predefined policies, acting as a gatekeeper that allows legitimate traffic while blocking potentially harmful applications without affecting the operation of trusted applications.
3Reliability
If VPN implements application-level authorization, then security is improved, but device complexity increases due to authentication and certificate management
Solution Approach 1:
The patent applies self-service by enabling applications to autonomously establish their authorization status with the VPN system. Trusted applications can self-authenticate using pre-configured credentials or certificates, eliminating the need for manual administrative intervention for each connection attempt and reducing the operational complexity of managing application-level authorization.
Data Source
AI summary
A computer-implemented method for establishing secure mobile communications is described. A virtual private network (VPN) between a mobile device and a server is established. A transmission of at least a portion of data between a first application and the server is blocked. It is determined whether the first application on the mobile device is a trusted application. Upon determining the first application is an untrusted application, a transmission of at least a portion of data between the untrusted application and the server continues to be blocked.


