Dynamic VPN Gateway Switching for Mobile Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile terminals face security challenges when connecting to corporate business systems, especially when outside the company network, due to limited application of security policies and the need for varying security levels based on connection environments.

Innovation Solution

A system and method for controlling VPN access that includes a first and second VPN gateway, a WLAN access control server, and a VPN setting change server to dynamically switch between VPN gateways based on the connection environment, ensuring appropriate security policies are applied when connecting to a corporate intranet or external networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a separate security environment is set for every business application using SSL, then security is improved, but device complexity and ease of operation deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple separate security environments into a single unified secure area within the mobile terminal's operating system. This secure area is centrally managed and can provide security services to multiple business applications simultaneously, eliminating the need for each application to maintain its own separate security configuration while maintaining high security standards.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The secure area is designed as a universal security environment that can serve multiple business applications and connection scenarios (corporate intranet, mobile network, WiFi) through a single integrated architecture. This multi-functional secure area can dynamically adapt to different connection types and apply appropriate security policies without requiring separate dedicated security environments for each use case.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If security policies are strictly applied to mobile terminals, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts security policies based on the connection environment and terminal state. When a mobile terminal connects to a corporate intranet via VPN, the system automatically applies appropriate security policies and switches to a secure area. The security level is not fixed but adapts in real-time based on detected connection types (intranet, mobile network, WiFi) and terminal authentication status, making security management automated and context-aware rather than static and cumbersome.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The mobile terminal autonomously detects its connection environment and automatically triggers the appropriate security procedures. The terminal itself identifies when it needs to switch to secure area, performs authentication, and establishes VPN connections without requiring manual security configuration or complex user intervention, thereby maintaining ease of operation while enforcing security policies.

Inventive Principle:
Principle #25Self-service

3Device complexity

If the same security mode is used for both intranet and external connections, then device complexity is reduced, but security adequacy deteriorates

Engineering Contradiction:
Improvedevice complexityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system applies different security characteristics to different connection scenarios within the unified secure area. When detecting a corporate intranet connection, the system applies stricter security policies and switches to secure area with enhanced protection. For external mobile network or WiFi connections, the system applies appropriate but potentially less stringent security measures. This localized differentiation of security quality based on connection type allows the system to maintain high security where needed while avoiding unnecessary complexity in other scenarios.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9565165B2System and method for controlling virtual private network access
Publication Date: 2017.02.07 SAMSUNG SDS CO LTD
  • US9565165B2 patent drawing
  • US9565165B2 patent drawing
  • US9565165B2 patent drawing

AI summary

Provided are a system and method for controlling virtual private network (VPN) access. The system includes a first VPN gateway, a second VPN gateway, a wireless local area network (WLAN) access control server configured to detect a corporate intranet connection of a wireless communication terminal connecting to a corporate intranet via the first VPN gateway, and a VPN setting change server configured to receive a request to change a VPN setting of the wireless communication terminal from the WLAN access control server and control the wireless communication terminal to change the VPN gateway currently in connection with the wireless communication terminal to the second VPN gateway in accordance with the VPN setting change request.