VPN Traffic Segregation via Application Identity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security architectures, such as VLANs and physical cabling, are inadequate for segregating VPN traffic effectively, especially in mobile device contexts, as they fail to provide fine-grained access controls and are not suitable for devices connected through wireless networks or the Internet.
Innovation Solution
Implementing micro-segmentation using software-defined networking to create virtual network segments for specific user groups or applications, allowing traffic routing based on characteristics beyond traditional network addresses or port numbers, and interfacing managed mobile devices with these segments through a VPN gateway.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical cabling segregation is used to separate network traffic by department, then network security is improved, but device complexity and ease of operation deteriorate due to difficult implementation and maintenance
Solution Approach 1:
The patent replaces physical cabling systems with software-based virtual network segmentation. Instead of using physically separate cabling for different departments, the system uses virtual switches and software-defined networking to create logical network segments that provide the same security isolation without physical hardware changes.
Solution Approach 2:
The patent creates virtual copies of network segments through software. Virtual network interfaces and virtual switches replicate the functionality of physical network segmentation, allowing multiple virtual network segments to coexist on the same physical infrastructure, thereby eliminating the need for physical cabling segregation.
2Ease of operation
If VLAN architecture is used to allow reconfiguration without changing physical cabling, then ease of operation is improved, but manufacturing precision and reliability worsen due to error-prone configuration
Solution Approach 1:
The patent implements automated network segmentation management where the system automatically assigns devices to appropriate virtual network segments based on device identity, user credentials, or policy rules. This eliminates manual VLAN configuration errors by using automated enrollment and segmentation assignment processes.
Solution Approach 2:
The patent creates dynamically adjustable virtual network segments that can be modified in real-time without reconfiguration errors. The software-based architecture allows flexible reassignment of devices between segments through policy changes rather than manual configuration, making the system adaptive and error-resistant.
3Reliability
If traditional VLAN or physical cabling is used, then network security is improved through segmentation, but adaptability worsens because these systems do not account for mobile devices connected through wireless networks or the Internet
Solution Approach 1:
The patent creates a universal network segmentation system that works across multiple connection types including wired Ethernet, wireless Wi-Fi, and remote VPN connections. The virtual network architecture provides consistent segmentation policies regardless of how devices connect to the network, enabling secure access for mobile devices, laptops, and remote users through the same segmentation framework.
Data Source
AI summary
Disclosed are various examples for segregating virtual private network (VPN) traffic based on the originating client application. A network gateway receives network traffic from a tunnel endpoint of an application-specific virtual private network tunnel. The network traffic originates from a client application executed in a client device. The network gateway identifies a particular virtual local area network through which the network traffic is received. The network gateway determines, using an identifier of the particular virtual local area network and a mapping of virtual local area network identifiers, characteristics of the client application or the client device from a set of mobile device management attributes. The network gateway determines whether to route the network traffic to a destination based at least in part on the characteristics.


