Application Access Control via VPN Tunnel Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge lies in managing access to enterprise data securely, as smartphones often grant unfettered access to both trusted and untrusted applications, posing a significant security risk due to the potential for malicious applications to exploit enterprise resources.
Innovation Solution
A communication system that employs VPN technology to differentiate between trusted and untrusted applications by routing traffic based on application metadata, using VPN tunnels to isolate untrusted applications and allow trusted applications to access enterprise resources while preventing untrusted applications from accessing sensitive data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If smartphones grant unfettered access to applications, then application functionality and ease of operation are improved, but security risk and vulnerability to malicious applications worsen
Solution Approach 1:
The patent segments network traffic into trusted and untrusted streams based on application characteristics. A segmentation rule set classifies applications as trusted or untrusted, routing trusted application traffic directly to enterprise resources while directing untrusted application traffic through a VPN tunnel for inspection and isolation, thereby maintaining security while preserving functionality.
Solution Approach 2:
The patent introduces a VPN tunnel as an intermediary for untrusted applications. This mediator provides a controlled communication path that isolates untrusted applications from direct access to enterprise resources, allowing monitoring and filtering of traffic while still enabling necessary functionality.
2Reliability
If traffic is routed based on application classification, then security is improved, but device complexity and processing overhead worsen
Solution Approach 1:
The patent performs preliminary classification of applications into trusted and untrusted categories before traffic routing decisions are made. Application characteristics are evaluated in advance, and routing rules are pre-configured based on this classification, simplifying real-time traffic management while maintaining security.
Solution Approach 2:
The patent applies different routing qualities to different traffic streams. Trusted application traffic receives direct, low-latency access to enterprise resources, while untrusted application traffic is routed through the VPN tunnel with enhanced security processing. This localized quality differentiation optimizes both security and performance for each traffic type.
Data Source
AI summary
A method is provided in one example embodiment and includes identifying a network location of an endpoint (12), which is attempting to initiate an application (14, 16); identifying whether the endpoint (12) is operating in an enterprise environment; determining whether the application is trusted based on metadata (66) associated with the application (14); and provisioning a tunnel for data traffic associated with the application. In more detailed implementations, the tunnel can be provisioned if the application (14) is trusted and the endpoint (12) is outside of an enterprise environment. In addition, the tunnel can be provisioned if the application (16) is untrusted and the endpoint (12) is within an enterprise environment.


