Application-Based VPN Routing for Enterprise Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The operation of virtual private networks (VPNs) presents security risks to enterprise networks and assets, as unauthorized applications on remote devices can access VPN assets, increasing the risk of security breaches.
Innovation Solution
A VPN asset control system and method that provides granular access control by using a VPN client module, policy repository, and application-based routing module to manage access restrictions based on application specifications and IT policies, routing unauthorized applications to the internet instead of the enterprise network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If VPN access is allowed for remote devices, then users can access enterprise assets remotely, but unauthorized applications can access VPN assets increasing security risks
Solution Approach 1:
The patent segments VPN access control by application, creating separate routing paths for authorized and unauthorized applications. The system divides network traffic into distinct streams based on application identity, allowing legitimate applications to access VPN assets while blocking unauthorized applications from reaching the same assets.
Solution Approach 2:
The patent introduces an intermediary routing module that sits between applications and VPN assets. This intermediary evaluates application credentials, checks authorization policies, and determines whether to route traffic through the VPN or block it. The intermediary acts as a gatekeeper without requiring changes to the applications or VPN infrastructure.
2Adaptability or versatility
If all applications are allowed to access VPN assets, then application functionality is maximized, but security control is reduced
Solution Approach 1:
The patent implements dynamic access control where routing decisions are made in real-time based on application credentials and current authorization policies. The system continuously evaluates each application's right to access VPN assets rather than using static allow/deny lists, enabling flexible adaptation to changing security requirements while maintaining granular control.
Solution Approach 2:
The patent applies different access control qualities to different applications. Each application receives customized routing treatment based on its specific credentials and authorization level. Authorized applications receive full VPN access to their designated assets, while unauthorized applications are blocked, creating localized security policies tailored to each application's needs.
3Reliability
If granular application-based access control is implemented, then security is improved, but system complexity increases
Solution Approach 1:
The patent implements a universal routing module that handles all application traffic through a single code path. This multi-functional module can evaluate any application's credentials, enforce any authorization policy, and route any traffic stream. By using a single versatile component rather than separate controls for each application, the system achieves granular security without proportional increases in complexity.
Solution Approach 2:
The routing module automatically evaluates application credentials and enforces authorization policies without requiring manual intervention. The system self-manages the complex task of identifying applications, checking their authorization status, and making routing decisions, thereby reducing operational complexity despite the sophisticated security control mechanism.
Data Source
AI summary
According to an example, a method for virtual private network (VPN) access control includes receiving a request from an application on a user device to access a remote computer network asset, and determining, by a processor, an authorization of the application to access the remote computer network asset based on a policy. In response to a determination that the application is authorized to access the remote computer network asset, the method includes setting a VPN connection between the user device and a remote computer network including the remote computer network asset, and routing traffic from the application to the remote computer network asset via the VPN. In response to a determination that the application is not authorized to access the remote computer network asset, the method includes routing traffic from the application to a network different than the remote computer network.


