VPN Traffic Segregation via Application Identity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security architectures, such as VLANs and physical cabling, are inadequate for segregating VPN traffic effectively, especially in mobile device contexts, as they fail to provide fine-grained access controls and are not suitable for devices connected through wireless networks or the Internet.

Innovation Solution

Implementing micro-segmentation using software-defined networking to create virtual network segments for specific user groups or applications, allowing traffic routing based on characteristics beyond traditional network addresses or port numbers, and interfacing managed mobile devices with these segments through a VPN gateway.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical cabling segregation is used to separate network traffic by department, then network security is improved, but device complexity and ease of operation deteriorate due to difficult implementation and maintenance

Engineering Contradiction:
Improvenetwork securityVSAvoidcabling complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces physical cabling systems with software-based virtual network segmentation. Instead of using physically separate cabling for different departments, the system uses virtual switches and software-defined networking to create logical network segments that provide the same security isolation without physical hardware changes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates virtual copies of network segments through software. Virtual network interfaces and virtual switches replicate the functionality of physical network segmentation, allowing multiple virtual network segments to coexist on the same physical infrastructure, thereby eliminating the need for physical cabling segregation.

Inventive Principle:
Principle #26Copying

2Ease of operation

If VLAN architecture is used to allow reconfiguration without changing physical cabling, then ease of operation is improved, but manufacturing precision and reliability worsen due to error-prone configuration

Engineering Contradiction:
Improvereconfiguration capabilityVSAvoidconfiguration accuracy
Core Design Contradiction:
Ease of operationVSManufacturing precision

Solution Approach 1:

The patent implements automated network segmentation management where the system automatically assigns devices to appropriate virtual network segments based on device identity, user credentials, or policy rules. This eliminates manual VLAN configuration errors by using automated enrollment and segmentation assignment processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates dynamically adjustable virtual network segments that can be modified in real-time without reconfiguration errors. The software-based architecture allows flexible reassignment of devices between segments through policy changes rather than manual configuration, making the system adaptive and error-resistant.

Inventive Principle:
Principle #15Dynamics

3Reliability

If traditional VLAN or physical cabling is used, then network security is improved through segmentation, but adaptability worsens because these systems do not account for mobile devices connected through wireless networks or the Internet

Engineering Contradiction:
Improvenetwork securityVSAvoidmobile device support
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal network segmentation system that works across multiple connection types including wired Ethernet, wireless Wi-Fi, and remote VPN connections. The virtual network architecture provides consistent segmentation policies regardless of how devices connect to the network, enabling secure access for mobile devices, laptops, and remote users through the same segmentation framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11689581B2Segregating VPN traffic based on the originating application
Publication Date: 2023.06.27 OMNISSA LLC
  • US11689581B2 patent drawing
  • US11689581B2 patent drawing
  • US11689581B2 patent drawing

AI summary

Disclosed are various examples for segregating virtual private network (VPN) traffic based on the originating client application. A network gateway receives network traffic from a tunnel endpoint of an application-specific virtual private network tunnel. The network traffic originates from a client application executed in a client device. The network gateway identifies a particular virtual local area network through which the network traffic is received. The network gateway determines, using an identifier of the particular virtual local area network and a mapping of virtual local area network identifiers, characteristics of the client application or the client device from a set of mobile device management attributes. The network gateway determines whether to route the network traffic to a destination based at least in part on the characteristics.