Application Access Control via VPN Tunnel Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in managing access to enterprise data securely, as smartphones often grant unfettered access to both trusted and untrusted applications, posing a significant security risk due to the potential for malicious applications to exploit enterprise resources.

Innovation Solution

A communication system that employs VPN technology to differentiate between trusted and untrusted applications by routing traffic based on application metadata, using VPN tunnels to isolate untrusted applications and allow trusted applications to access enterprise resources while preventing untrusted applications from accessing sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If smartphones grant unfettered access to applications, then application functionality and ease of operation are improved, but security risk and vulnerability to malicious applications worsen

Engineering Contradiction:
Improveapplication accessVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments network traffic into trusted and untrusted streams based on application characteristics. A segmentation rule set classifies applications as trusted or untrusted, routing trusted application traffic directly to enterprise resources while directing untrusted application traffic through a VPN tunnel for inspection and isolation, thereby maintaining security while preserving functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a VPN tunnel as an intermediary for untrusted applications. This mediator provides a controlled communication path that isolates untrusted applications from direct access to enterprise resources, allowing monitoring and filtering of traffic while still enabling necessary functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traffic is routed based on application classification, then security is improved, but device complexity and processing overhead worsen

Engineering Contradiction:
ImprovesecurityVSAvoidrouting complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary classification of applications into trusted and untrusted categories before traffic routing decisions are made. Application characteristics are evaluated in advance, and routing rules are pre-configured based on this classification, simplifying real-time traffic management while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies different routing qualities to different traffic streams. Trusted application traffic receives direct, low-latency access to enterprise resources, while untrusted application traffic is routed through the VPN tunnel with enhanced security processing. This localized quality differentiation optimizes both security and performance for each traffic type.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2767058B1Method and apparatus for managing access for trusted and untrusted applications
Publication Date: 2017.02.01 CISCO TECHNOLOGY INC
  • EP2767058B1 patent drawing
  • EP2767058B1 patent drawing
  • EP2767058B1 patent drawing

AI summary

A method is provided in one example embodiment and includes identifying a network location of an endpoint (12), which is attempting to initiate an application (14, 16); identifying whether the endpoint (12) is operating in an enterprise environment; determining whether the application is trusted based on metadata (66) associated with the application (14); and provisioning a tunnel for data traffic associated with the application. In more detailed implementations, the tunnel can be provisioned if the application (14) is trusted and the endpoint (12) is outside of an enterprise environment. In addition, the tunnel can be provisioned if the application (16) is untrusted and the endpoint (12) is within an enterprise environment.