Centralized VPN Session Initiation for Remote Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VPN technologies face challenges in securely and efficiently managing VPN connections across devices, particularly in initiating and executing VPN sessions on remote devices without compromising security and accessibility.

Innovation Solution

A system and method that allows a mobile device to initiate a VPN session on a remote device by authenticating the request, transmitting lists of authorized devices and applications, and facilitating a VPN connection between the remote device and a service node, enabling secure execution of selected applications within the VPN session.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a mobile device initiates a VPN session on behalf of remote devices, then VPN connection management becomes more efficient and accessible, but security control and authentication complexity increase

Engineering Contradiction:
ImproveVPN session initiationVSAvoidauthentication process
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The mobile device serves as an intermediary that initiates VPN sessions on behalf of remote devices. The mobile device communicates with the VPN server to establish connections, acting as a mediator between the remote devices and the VPN infrastructure, thereby simplifying the operation for remote devices while centralizing authentication control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service VPN connectivity where authenticated mobile devices can automatically initiate VPN sessions for associated remote devices without requiring manual configuration on each remote device. The mobile device stores authentication credentials and uses them to establish connections autonomously.

Inventive Principle:
Principle #25Self-service

2Reliability

If all connectivity is controlled from a central VPN server, then security is enhanced, but network latency and connection establishment time increase

Engineering Contradiction:
Improvesecurity controlVSAvoidconnection establishment
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication credentials are pre-configured and stored on mobile devices beforehand. When a VPN session needs to be initiated, the mobile device uses these pre-stored credentials to quickly establish connections without requiring real-time authentication exchanges, thereby reducing connection establishment time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication and credential verification processes are extracted from the connection establishment phase and performed in advance during device provisioning. This separates the security verification step from the actual connection setup, allowing faster connection establishment while maintaining centralized security control.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If VPN sessions are established between multiple devices, then accessibility and device compatibility improve, but network complexity and management overhead increase

Engineering Contradiction:
Improvedevice compatibilityVSAvoidnetwork management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The VPN system is designed to work across multiple device types (mobile devices, remote devices, servers) through a universal architecture. The mobile device can initiate sessions for various types of remote devices, and the VPN server provides unified management, allowing the system to adapt to different device platforms without increasing management complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The VPN server acts as a central intermediary that manages all device connections and sessions. It handles authentication, session establishment, and resource allocation, thereby simplifying network management despite the presence of multiple device types. The server abstracts the complexity of multi-device management from individual devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10243947B2Method and system to enable a virtual private network client
Publication Date: 2019.03.26 AT&T INTELLECTUAL PROPERTY I L P
  • US10243947B2 patent drawing
  • US10243947B2 patent drawing
  • US10243947B2 patent drawing

AI summary

Aspects of the subject disclosure may include, for example, a method comprising transmitting, by a controller comprising a processor, a request to a server to enable initiation of a virtual private network session on behalf of devices other than the controller. The controller transmits authentication information to enable the server to validate the request, and receives a first list of computing devices. The controller transmits a first selection of a target device from the first list to cause the server to initiate the virtual private network session between the target device and a service node providing services to the target device via the virtual private network session. The controller receives a second list of applications executable on each of the computing devices, and transmits to the server a second selection of an application from the second list that is executable by the target device. Other embodiments are disclosed.