Dynamic VPN Gateway Switching for Mobile Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile terminals face security challenges when connecting to corporate business systems, especially when outside the company network, due to limited application of security policies and the need for varying security levels based on connection environments.
Innovation Solution
A system and method for controlling VPN access that includes a first and second VPN gateway, a WLAN access control server, and a VPN setting change server to dynamically switch between VPN gateways based on the connection environment, ensuring appropriate security policies are applied when connecting to a corporate intranet or external networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a separate security environment is set for every business application using SSL, then security is improved, but device complexity and ease of operation deteriorate
Solution Approach 1:
The patent merges multiple separate security environments into a single unified secure area within the mobile terminal's operating system. This secure area is centrally managed and can provide security services to multiple business applications simultaneously, eliminating the need for each application to maintain its own separate security configuration while maintaining high security standards.
Solution Approach 2:
The secure area is designed as a universal security environment that can serve multiple business applications and connection scenarios (corporate intranet, mobile network, WiFi) through a single integrated architecture. This multi-functional secure area can dynamically adapt to different connection types and apply appropriate security policies without requiring separate dedicated security environments for each use case.
2Reliability
If security policies are strictly applied to mobile terminals, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The system dynamically adjusts security policies based on the connection environment and terminal state. When a mobile terminal connects to a corporate intranet via VPN, the system automatically applies appropriate security policies and switches to a secure area. The security level is not fixed but adapts in real-time based on detected connection types (intranet, mobile network, WiFi) and terminal authentication status, making security management automated and context-aware rather than static and cumbersome.
Solution Approach 2:
The mobile terminal autonomously detects its connection environment and automatically triggers the appropriate security procedures. The terminal itself identifies when it needs to switch to secure area, performs authentication, and establishes VPN connections without requiring manual security configuration or complex user intervention, thereby maintaining ease of operation while enforcing security policies.
3Device complexity
If the same security mode is used for both intranet and external connections, then device complexity is reduced, but security adequacy deteriorates
Solution Approach 1:
The system applies different security characteristics to different connection scenarios within the unified secure area. When detecting a corporate intranet connection, the system applies stricter security policies and switches to secure area with enhanced protection. For external mobile network or WiFi connections, the system applies appropriate but potentially less stringent security measures. This localized differentiation of security quality based on connection type allows the system to maintain high security where needed while avoiding unnecessary complexity in other scenarios.
Data Source
AI summary
Provided are a system and method for controlling virtual private network (VPN) access. The system includes a first VPN gateway, a second VPN gateway, a wireless local area network (WLAN) access control server configured to detect a corporate intranet connection of a wireless communication terminal connecting to a corporate intranet via the first VPN gateway, and a VPN setting change server configured to receive a request to change a VPN setting of the wireless communication terminal from the WLAN access control server and control the wireless communication terminal to change the VPN gateway currently in connection with the wireless communication terminal to the second VPN gateway in accordance with the VPN setting change request.


