Application-Based VPN Routing for Enterprise Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The operation of virtual private networks (VPNs) presents security risks to enterprise networks and assets, as unauthorized applications on remote devices can access VPN assets, increasing the risk of security breaches.

Innovation Solution

A VPN asset control system and method that provides granular access control by using a VPN client module, policy repository, and application-based routing module to manage access restrictions based on application specifications and IT policies, routing unauthorized applications to the internet instead of the enterprise network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If VPN access is allowed for remote devices, then users can access enterprise assets remotely, but unauthorized applications can access VPN assets increasing security risks

Engineering Contradiction:
Improveremote access capabilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments VPN access control by application, creating separate routing paths for authorized and unauthorized applications. The system divides network traffic into distinct streams based on application identity, allowing legitimate applications to access VPN assets while blocking unauthorized applications from reaching the same assets.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary routing module that sits between applications and VPN assets. This intermediary evaluates application credentials, checks authorization policies, and determines whether to route traffic through the VPN or block it. The intermediary acts as a gatekeeper without requiring changes to the applications or VPN infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If all applications are allowed to access VPN assets, then application functionality is maximized, but security control is reduced

Engineering Contradiction:
Improveapplication access flexibilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements dynamic access control where routing decisions are made in real-time based on application credentials and current authorization policies. The system continuously evaluates each application's right to access VPN assets rather than using static allow/deny lists, enabling flexible adaptation to changing security requirements while maintaining granular control.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies different access control qualities to different applications. Each application receives customized routing treatment based on its specific credentials and authorization level. Authorized applications receive full VPN access to their designated assets, while unauthorized applications are blocked, creating localized security policies tailored to each application's needs.

Inventive Principle:
Principle #3Local quality

3Reliability

If granular application-based access control is implemented, then security is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoidaccess control system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal routing module that handles all application traffic through a single code path. This multi-functional module can evaluate any application's credentials, enforce any authorization policy, and route any traffic stream. By using a single versatile component rather than separate controls for each application, the system achieves granular security without proportional increases in complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The routing module automatically evaluates application credentials and enforces authorization policies without requiring manual intervention. The system self-manages the complex task of identifying applications, checking their authorization status, and making routing decisions, thereby reducing operational complexity despite the sophisticated security control mechanism.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9584523B2Virtual private network access control
Publication Date: 2017.02.28 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9584523B2 patent drawing
  • US9584523B2 patent drawing
  • US9584523B2 patent drawing

AI summary

According to an example, a method for virtual private network (VPN) access control includes receiving a request from an application on a user device to access a remote computer network asset, and determining, by a processor, an authorization of the application to access the remote computer network asset based on a policy. In response to a determination that the application is authorized to access the remote computer network asset, the method includes setting a VPN connection between the user device and a remote computer network including the remote computer network asset, and routing traffic from the application to the remote computer network asset via the VPN. In response to a determination that the application is not authorized to access the remote computer network asset, the method includes routing traffic from the application to a network different than the remote computer network.