Logical multiplexed network separation communication method through VPN hopping and communication system performing the same

The method of logically separating networks through VPN hopping with VRs addresses security vulnerabilities and cost issues by forming independent networks for each server or terminal, improving security and reducing costs while maintaining scalability.

JP2025186992AActive Publication Date: 2025-12-24ARAD NETWORKS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024197685
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-12
Filing Date
2024-11-12
Publication Date
2025-12-24
Estimated Expiration
2044-11-12

AI Technical Summary

Technical Problem

Conventional virtual private network (VPN) technologies fail to create independent networks for each server or terminal, leading to security vulnerabilities when multiple terminals communicate with multiple servers, and building physically separated networks is costly.

Method used

A method and system for logically separating multiple networks through VPN hopping using multiple Virtual Routers (VRs), where a controller determines conditions for VR changes, requests VR changes, and executes VR hopping to form independent networks for each server or terminal, authenticated terminals are allowed to communicate, and VRs in different networks have distinct configurations.

Benefits of technology

This approach enhances security by controlling and managing network access, reduces costs compared to physical separation, and minimizes damage to unaffected terminals if one is hacked, while allowing scalable network construction with minimal physical changes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025186992000001_ABST
    Figure 2025186992000001_ABST
Patent Text Reader

Abstract

To provide a logical multiplexed network separation communication method through virtual private network (VPN) hopping and a communication system performing the same.SOLUTION: A communication system logically separates a large number of networks formed between a large number of terminals and computing devices by generating and using a virtual router (VR) corresponding to each of the multiple terminals at a service gateway, thereby forming independent networks for each server or terminal, and enhancing security by changing the VR used in each network according to specific rules.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a method and system for logically separating multiple networks through VPN hopping, and more particularly to a method and system for logically separating multiple networks formed between multiple terminals and computing devices using multiple VRs (Virtual Routers), thereby forming independent networks for each server or terminal, and changing the VRs used in each network according to specific rules, thereby increasing security. [Background technology]

[0002] Networks can be broadly divided into private networks and public networks. Private networks are networks owned and used exclusively by specific companies or organizations. They are available only to authorized users and have the advantage of being highly secure, but they have the disadvantage of being difficult to use over a wide area due to high installation costs due to distance and high maintenance costs. Public networks are networks that are open to the public and available to anyone, like the telephone network or the Internet, and have the advantage of being able to exchange information with anyone at any time, but they also have the disadvantage of being less secure.

[0003] A technology developed to obtain the benefits of both private and public networks is the Virtual Private Network (VPN). A Virtual Private Network (VPN) is a technology that uses a public network, such as the Internet, to replace expensive private networks. It refers to a network that uses a public network to create a virtual tunnel and transmit encrypted data in order to securely connect two or more networks (e.g., private networks) or terminals. Such Virtual Private Network technology provides confidentiality against threats such as personal information leakage, data interception, and data modification from the public network, thereby providing a secure network.

[0004] Technologies for implementing virtual private networks include tunneling and key management. Tunneling technology is a technology that forms a virtual tunnel between two endpoints to achieve an effect similar to an end-to-end dedicated line connection, and provides encryption and authentication. There are tunneling protocols for each layer, such as PPTP, L2TP, IPSEC, and Sock v5. Key management technology is a key management framework technology used to negotiate security matters required for VPN services, and representative examples include ISAKMP and OAKLEY.

[0005] On the other hand, when multiple terminals communicate with multiple servers, simply applying conventional virtual private network technology makes it impossible to form independent networks for each server, resulting in security vulnerabilities. To address this, building physically separated networks for each server would be costly, and there is a need for technology that can solve these problems. Summary of the Invention [Problem to be solved by the invention]

[0006] The present invention provides a method and system for logically separating multiple networks through VPN hopping, and more specifically, a method and system for logically separating multiple networks formed between multiple terminals and computing devices using multiple VRs (Virtual Routers), thereby forming independent networks for each server or terminal, and changing the VRs used in each network according to specific rules, thereby improving security. [Means for solving the problem]

[0007] In order to solve the above problems, one embodiment of the present invention provides a method for logically separating multiple networks through VPN hopping in a communication system including a plurality of terminals, a service gateway, a controller, and one or more computing devices, the method comprising: a hopping determination step in the controller determining whether a network between each of the terminals and the computing devices satisfies a predetermined first condition; a VR change request step in the controller requesting a VR (Virtual Router) change from a service gateway that mediates communication between the terminals and the computing devices if a network that satisfies the first condition exists; a VR change response step in the service gateway transmitting new VR information related to a new VR corresponding to the request to the controller; a VR change information transmission step in the controller transferring new VR change information corresponding to the new VR information to the terminal and the service gateway; and a VR hopping step in the service gateway hopping an existing VR that was previously used in a network that satisfies the first condition to the new VR based on the new VR change information.

[0008] The service gateway assigns one of the multiple VRs generated by the service gateway to each network connecting the multiple terminals and the one or more computing devices, and the VRs used in different networks are different so that each network is logically separated.

[0009] The logical multiplexed network separation communication method further includes a terminal authentication step in the controller for authenticating the terminal that will communicate, the terminal authentication step including an identification information receiving step for receiving identification information for the terminal from the terminal, and a verification result sending step for sending a verification result of the identification information to the service gateway, and the service gateway generates a network that allows only authenticated terminals to communicate with the computing device.

[0010] The VR change response step includes the steps of generating a new VR corresponding to the request and transmitting new VR information related to the new VR to the controller, wherein the new VR has VR information that is different from other VRs generated and in operation in the service gateway.

[0011] For a terminal and a computing device connected to a network that satisfies the first condition, the VR hopping step includes the steps of generating a new network between the terminal and the computing device using a new VR, blocking communication of the network that previously mediated communication between the terminal and the computing device, and deleting the existing VR included in the blocked network.

[0012] The plurality of terminals include a point gateway that generates one or more VRs, and after generating one or more VRs, the point gateway uses the one or more VRs to generate networks between one or more edge terminals and the service gateway, and the VRs used in each generated network are different so that each network is logically separated, and a network switch unit is provided between the point gateway and the service gateway.

[0013] The logical multiplexed network separation communication method includes the steps of: in the controller, determining whether there is a network between the edge terminal and the service gateway that satisfies a predetermined second condition; in the controller, if a network that satisfies the second condition exists, requesting the point gateway to change the VR; in the point gateway, sending information related to the VR that corresponds to the controller's request to the controller; in the controller, passing information corresponding to the information related to the VR to the edge terminal and the point gateway; and in the point gateway, hopping the VR used in the network that satisfies the second condition to the generated VR.

[0014] The first condition is related to the amount of traffic in the network between the terminal and the computing device, and the hopping determination step determines that the network satisfies the first condition if the amount of traffic measured in each predetermined period in the network between the terminal and the computing device exceeds a first determination criterion.

[0015] In order to solve the above problems, a communication system is provided which includes a plurality of terminals, a service gateway, a controller, and one or more computing devices, and which performs a logical multiplexed network separation communication method through VPN hopping, and which is characterized by including: a hopping determination unit in the controller which determines whether a network between each of the terminals and the computing devices satisfies a predetermined first condition; a VR change request unit in the controller which, if a network that satisfies the first condition exists, requests a service gateway that mediates communication between the terminals and the computing devices to change a VR (Virtual Router); a VR change response unit in the service gateway which transmits new VR information related to a new VR corresponding to the request to the controller; a VR change information transmission unit in the controller which delivers new VR change information corresponding to the new VR information to the terminal and the service gateway; and a VR hopping unit in the service gateway which hops an existing VR that was previously used in a network that satisfies the first condition to the new VR based on the VR change information. [Effects of the Invention]

[0016] According to the present invention, by configuring independent networks for media, customers, and servers, it is possible to control and manage network access, thereby enhancing security.

[0017] According to the present invention, by forming a logically separated network, security can be improved and costs can be reduced compared to constructing physically independent networks.

[0018] According to the present invention, by using the VPN hopping technology, it is possible to have higher security than the conventional VPN technology.

[0019] According to the present invention, since each of the multiple terminals is operated on an independent network, even if one terminal is hacked, damage to the remaining terminals can be minimized.

[0020] According to the present invention, even in an environment where an existing network has been constructed, a new network can be constructed with minimal physical configuration changes, and wide scalability can be achieved. [Brief explanation of the drawings]

[0021] [Figure 1] FIG. 1 is a diagram illustrating a configuration of a communication system in which a logical multiplexed network separation communication method using VPN hopping according to an embodiment of the present invention is performed. [Figure 2] FIG. 2 is a diagram illustrating a configuration in which multiple terminals and a single computing device are connected through a service gateway according to an embodiment of the present invention. [Figure 3] FIG. 3 is a diagram illustrating a configuration in which a plurality of terminals and a plurality of computing devices are connected through a service gateway according to an embodiment of the present invention. [Figure 4] FIG. 4 is a diagram illustrating the steps of a logically multiplexed network separation communication method through VPN hopping according to an embodiment of the present invention. [Figure 5] FIG. 5 is a diagram schematically illustrating the internal configuration of a service gateway and a controller according to an embodiment of the present invention. [Figure 6] FIG. 6 is a diagram illustrating a process of receiving network information in a controller according to an embodiment of the present invention. [Figure 7] FIG. 7 is a diagram illustrating the steps of performing a hopping decision step according to an embodiment of the present invention. [Figure 8] FIG. 8 is a diagram illustrating a process of performing a VR hopping step according to an embodiment of the present invention. [Figure 9] FIG. 9 is a diagram illustrating a process of performing a VR hopping step according to another embodiment of the present invention. [Figure 10] FIG. 10 is a diagram illustrating a connection configuration of a communication system including a point gateway according to an embodiment of the present invention. [Figure 11] FIG. 11 is a diagram illustrating a configuration in which multiple terminals and a single computing device are connected through a point gateway and a service gateway according to an embodiment of the present invention. [Figure 12] FIG. 12 is a diagram illustrating a process of performing VR hopping in a point gateway according to an embodiment of the present invention. [Figure 13] FIG. 13 is a diagram illustrating a process of performing VR hopping in a point gateway according to another embodiment of the present invention. [Figure 14] FIG. 14 is a diagram schematically illustrating differences between an embodiment of the present invention and the prior art. DETAILED DESCRIPTION OF THE INVENTION

[0022] Various embodiments and / or aspects are described below with reference to the drawings. In the following description, for purposes of explanation, numerous specific details are set forth in order to facilitate a general understanding of one or more aspects. However, those skilled in the art will recognize that these aspects may be practiced without such specific details. The following description and the accompanying drawings set forth certain exemplary aspects of one or more aspects in detail. However, such aspects are illustrative, and only a portion of various methods may be utilized in accordance with the principles of the various aspects, and the description is intended to include all such aspects and their equivalents.

[0023] Additionally, various aspects and features are presented in terms of systems that include multiple devices, components, and / or modules, etc. It should also be understood and appreciated that various systems can include additional devices, components, and / or modules, etc. and / or may not include all of the devices, components, modules, etc. discussed in connection with the figures.

[0024] As used herein, the terms "embodiment," "example," "manner," "exemplary," and the like may not be construed as constituting any particular embodiment or design that is better or more advantageous than other embodiments or designs. As used below, the terms "module," "component," "module," "system," "interface," and the like generally refer to computer-related entities, such as hardware, a combination of hardware and software, or software.

[0025] Additionally, the terms "comprise" and / or "comprising" should be understood to mean that the feature and / or component is present, but not to exclude the presence or addition of one or more other features, components and / or groups thereof.

[0026] Furthermore, terms including ordinal numbers, such as "first," "second," etc., are used to describe various elements, but the elements are not limited by these terms. These terms are used only to distinguish one element from another. For example, a first element can be referred to as a "second element," and similarly, a second element can be referred to as a "first element," without departing from the scope of the present invention. The term "and / or" includes a combination of multiple related listed items or any of multiple related listed items.

[0027] Furthermore, unless otherwise defined in the embodiments of the present invention, all terms used herein, including technical and scientific terms, have the same meaning as commonly understood by a person of ordinary skill in the art to which the present invention belongs. Terms defined in commonly used dictionaries should be interpreted as having a meaning consistent with the meaning they have in the context of the related art, and should not be interpreted as idealized or overly formal unless explicitly defined in the embodiments of the present invention.

[0028] FIG. 1 is a diagram illustrating a configuration of a communication system in which a logical multiplexed network separation communication method using VPN hopping according to an embodiment of the present invention is performed.

[0029] As shown in FIG. 1, a communication system in which a logical multiplexed network separation communication method through VPN hopping is performed includes a plurality of terminals (1000.1 to 1000.N, hereinafter referred to as 1000), a service gateway 2000, one or more computing devices (3000.1 to 3000.M, hereinafter referred to as 3000), and a controller 4000.

[0030] In general terms, the service gateway 2000 functions to mediate communications between multiple terminals 1000 and one or more computing devices 3000, and the controller 4000 controls the operation of the service gateway 2000, which performs operations related to VPN hopping.

[0031] Specifically, the logical multiplexed network separation communication method through VPN hopping of the present invention has a technical feature of forming a network between a plurality of terminals 1000 and one or more computing devices 3000, generating a VR (Virtual Router) corresponding to each of the plurality of terminals 1000 in the service gateway 2000, and forming a network using the VR, thereby allowing the networks connected to each terminal to be operated independently of each other.

[0032] Here, each of the plurality of terminals 1000 includes any terminal 1000 capable of performing network communication, such as a mobile phone, an IoT terminal, a PC, a laptop computer, and a server device. According to one embodiment of the present invention, at least one of the plurality of terminals 1000 corresponds to a point gateway 1100. According to another embodiment of the present invention, the terminal 1000 corresponds to any terminal 1000 equipped with the function performed by the point gateway 1100. For example, the terminal 1000 corresponds to a wall pad installed in a house, and the wall pad corresponds to the terminal 1000 that performs the function of the point gateway 1100. A more detailed description of the point gateway 1100 will be given later. Meanwhile, in terminal #N (1000.N) in FIG. 1, N corresponds to a natural number equal to or greater than 2.

[0033] In a preferred embodiment, the computing device 3000 includes a server system having one or more processors and one or more memories. Referring to FIG. 2, one computing device 3000 communicates with a plurality of terminals 1000. In one embodiment of the present invention, if the communication system is established in a shared residence such as an apartment, the computing device 3000 may be embodied as a home network server, but this is merely an example and possible implementations are not limited thereto. Meanwhile, in computing device #M (3000M) in FIG. 1, M corresponds to a natural number equal to or greater than 1.

[0034] The controller 4000 is connected to the service gateway 2000 and controls part or all of the operation of the service gateway 2000. Although not shown in FIG. 1, the controller 4000 can be directly or indirectly connected to the plurality of terminals 1000 and the computing device 3000 to communicate with them.

[0035] The following describes a method for generating and communicating through logically separated multiplexed networks through multiple VRs generated by a service gateway 2000 in a communication system. The content described below focuses on the technical features of the present invention, but does not limit all the functions that the communication system of the present invention can perform.

[0036] FIG. 2 is a diagram illustrating a configuration in which multiple terminals 1000 and a single computing device 3000 are connected through a service gateway 2000 according to an embodiment of the present invention, and FIG. 3 is a diagram illustrating a configuration in which multiple terminals 1000 and multiple computing devices 3000 are connected through a service gateway 2000 according to an embodiment of the present invention.

[0037] As shown in Figures 2 and 3, the service gateway 2000 assigns one of the multiple VRs generated by the service gateway 2000 to each network connecting each of the multiple terminals 1000 and the one or more computing devices 3000, and the VRs used in different networks are different so that each network is logically separated.

[0038] Figure 2 shows a network formed between multiple terminals 1000 and a single computing device 3000, Figure 3(a) shows a network in which multiple terminals 1000 and multiple computing devices 3000 communicate with each other, with each terminal 1000 and each computing device 3000 being connected 1:1, and Figure 3(b) shows a network in which multiple terminals 1000 and multiple computing devices 3000 communicate with each other, with each terminal 1000 and each of one or more computing devices 3000 being connected 1:1 or a:1 (a is a natural number greater than or equal to 2)

[0039] Specifically, as shown in Figures 2 and 3, the service gateway 2000 generates a virtual VR and forms a network for communication between the terminal 1000 and the computing device 3000 using the generated VR. For ease of explanation, hereinafter, the VR implemented by the service gateway 2000 will be referred to as a first VR, and the VR implemented by the point gateway 1100 will be referred to as a second VR. Preferably, a first VR is formed as many times as the number of terminals 1000 and connected to each of the plurality of terminals 1000, and each of the first VRs (first VR #1 to first VR #n in Figures 2 and 3, n is a natural number equal to or greater than 2) has other VR information (e.g., IP information, etc.).

[0040] As shown in FIG. 2, when multiple terminals 1000 communicate with a single computing device 3000, each of the multiple terminals 1000 communicates with the computing device 3000 through multiple different first VRs implemented in the service gateway 2000. The configuration of the communication system of the present invention in FIGS. 2 and 3 has the effect that even if a specific terminal 1000 among the multiple terminals 1000 is hacked, the other terminals 1000 can avoid the risk of hacking.

[0041] FIG. 4 is a diagram illustrating the execution steps of a logical multiplexed network separation communication method through VPN hopping according to one embodiment of the present invention, and FIG. 5 is a diagram illustrating the internal configuration of a service gateway 2000 and a controller 4000 according to one embodiment of the present invention.

[0042] As shown in FIG. 4, the method for logically separating multiple networks through VPN hopping is performed in a communication system including a plurality of terminals 1000, a service gateway 2000, a controller 4000, and one or more computing devices 3000. The method includes a hopping determination step in which the controller 4000 determines whether a network that satisfies a predetermined first condition exists between the terminals 1000 and the computing devices 3000, and a step in which the controller 4000 determines whether a network that satisfies the first condition exists in the network between the terminals 1000 and the computing devices 3000. If a network that satisfies the first condition exists, the controller 4000 assigns a VR (Virtual Real Time Network) to the service gateway 2000 that mediates communication between the terminals 1000 and the computing devices 3000. the service gateway 2000 to transmit new VR information related to the new VR corresponding to the request to the controller 4000; the VR modification information transmission step in the controller 4000 to transfer new VR modification information corresponding to the new VR information to the terminal 1000 and the service gateway 2000; and the VR hopping step in the service gateway 2000 to hop an existing VR that has been used in the network that satisfies the first condition to the new VR based on the new VR modification information.

[0043] In addition, the logical multiplexed network separation communication method further includes a terminal authentication step in the controller 4000, which authenticates the terminal 1000 that will communicate, and the terminal authentication step includes an identification information receiving step of receiving identification information for the terminal 1000 from the terminal 1000, an identification information verification step of verifying the identification information, and a verification result sending step of sending the verification result of the identification information to the service gateway 2000, and the service gateway 2000 generates a network that can communicate with the computing device 3000 only for the authenticated terminal 1000.

[0044] 5(a) shows the internal configuration of the service gateway 2000, and FIG. 5(b) shows the internal configuration of the controller 4000. As shown in FIG.

[0045] Specifically, before a network is formed between the terminal 1000 and the computing device 3000, a terminal authentication step for authenticating the terminal 1000 is preferably performed by the terminal authentication unit 4100 of the controller 4000. The terminal authentication unit 4100 performs an identification information receiving step for receiving (S10) identification information for the terminal 1000 from the terminal 1000 that intends to communicate with the computing device 3000. In one embodiment of the present invention, the identification information includes a unique ID possessed by the terminal 1000 and a corresponding PW.

[0046] The terminal authentication unit 4100 that has received the identification information performs an identification information verification step of verifying the identification information (S11), and, as one embodiment of the present invention, performs a verification result transmission step of transmitting the verification result to the service gateway 2000 (S12.1). Meanwhile, according to another embodiment of the present invention, as shown in Fig. 4, the terminal authentication unit 4100 can simultaneously transmit the verification result to the service gateway 2000 and the corresponding terminal 1000 (S12.1 and S12.2), and the verification result transmitted from the terminal authentication unit 4100 is directly or indirectly passed to the terminal 1000.

[0047] The terminal 1000, having received the verification result, requests the network generation unit 2100 of the service gateway 2000 to generate a network with the computing device 3000 (S20), and the network generation unit 2100 transmits a response to the network generation request to the terminal 1000 (S21) according to an embodiment of the present invention. Although not shown in FIG. 4, according to another embodiment of the present invention, the network generation unit 2100 may transmit the response to the network generation request to the controller 4000.

[0048] As described above, the service gateway 2000 generates a first VR connected to the authenticated terminal 1000 in the terminal authentication step, thereby creating a network capable of communicating with the computing device 3000, thereby enhancing network security. Meanwhile, it is preferable that the step be performed individually for each of the multiple terminals 1000 that wish to communicate with the computing device 3000.

[0049] When a network between the terminal 1000 and the computing device 3000 is formed, the controller 4000 receives network information for each of the created networks from the network generation unit 2100 (S22). Here, the service gateway 2000 may transmit corresponding network information to the controller 4000 at a predetermined period corresponding to each of a plurality of networks as one embodiment of the present invention, and may transmit network information for all networks passing through the service gateway 2000 to the controller 4000 collectively at a predetermined period. That is, the configuration for transmitting the network information to the controller 4000 at a specific period is a configuration that can be modified by a person skilled in the art of the present invention, and is not limited to the above embodiment.

[0050] When the controller 4000 receives network information for each of a plurality of networks, the hopping determination unit 4200 of the controller 4000 performs a hopping determination step of determining whether there is a network that satisfies a predetermined first condition based on the network information for each of the networks. A more detailed description of the first condition will be given later with reference to FIG. 7.

[0051] If the hopping determination step finds a network that satisfies the first condition among the plurality of networks, the VR change request unit 4300 of the controller 4000 performs a VR change request step of requesting (S40) the service gateway 2000 to change the first VR of the corresponding network. The request generated by the VR change request unit 4300 is passed to the VR change response unit 2200, and the VR generation unit 2210 of the VR change response unit 2200 generates (S41) a first new VR (shown as new VR in FIG. 4) corresponding to the request.

[0052] Thereafter, the VR generator 2210 performs a step of transmitting (S50) first new VR information related to the generated first new VR to the controller 4000. Here, the newly generated first new VR has first VR information different from that of other first VRs (hereinafter referred to as first existing VRs) that have already been generated and operated in the service gateway 2000. In other words, all of the first VRs that have been generated and operated in the service gateway 2000 have different first VR information.

[0053] When the controller 4000 receives the first new VR information (S50), the VR modification information transmitting unit 4400 of the controller 4000 generates first new VR modification information corresponding to the received first new VR information, and performs a VR modification information transmitting step of transmitting the first new VR modification information to the service gateway 2000 and the corresponding terminal 1000 (S51.1 to S51.2, hereinafter referred to as S51). Here, as one embodiment of the present invention, the first new VR modification information includes scheduling information for the corresponding network.

[0054] When the first new VR change information is transmitted to the service gateway 2000 (S51), the VR hopping unit 2300 of the service gateway 2000 performs a VR hopping step of hopping a first existing VR that has been used in a network that satisfies the first condition to the first new VR based on the received first new VR change information. A more detailed description of the VR hopping step will be given later with reference to FIGS. 8 and 9.

[0055] FIG. 6 shows a schematic diagram of a process for receiving network information in a controller 4000 according to an embodiment of the present invention.

[0056] Figure 6(a) shows the process of deriving network information for the network between the terminal 1000 and the computing device 3000, and Figure 6(b) shows the process of the service gateway 2000 passing the network information to the controller 4000.

[0057] Specifically, with reference to the above, each of the plurality of terminals 1000 forms a respective network with one or more computing devices 3000 to communicate, where each network includes a VR corresponding to each of the plurality of terminals 1000. For convenience of explanation, (a) of Figure 6 shows a configuration in which one terminal #1 (1000.1) and one computing device 3000 communicate through network #1, and the network #1 includes a first VR #1 corresponding to the terminal #1 (1000.1).

[0058] 6 includes information about the network #1. In one embodiment of the present invention, the network information #1 includes one or more pieces of information about the network #1, such as the time when the network #1 was created, the IP information used, or the amount of communication traffic on the network #1.

[0059] 6(b), the service gateway 2000 transmits the network information #1 to the controller 4000 at predetermined intervals. That is, the network information #1 can be derived at predetermined intervals, and the service gateway 2000 transmits the network information #1 derived at predetermined intervals to the controller 4000.

[0060] Thereafter, the hopping determination unit 4200 of the controller 4000 determines whether the network #1 satisfies a predetermined first condition based on the received network information #1. If the network #1 satisfies the predetermined condition, the VR change request unit 4300 transmits a request to the service gateway 2000 to change the first VR #1 of the network #1 to another first new VR. If the network #1 does not satisfy the first condition, the VR change request unit 4300 does not perform any operation on the corresponding network, and the terminal #1 (1000.1) and the computing device 3000 communicate via the network #1 until the network #1 satisfies the first condition.

[0061] FIG. 7 shows a schematic diagram of the steps of performing a hopping decision step according to an embodiment of the present invention.

[0062] FIG. 7(a) shows the steps of executing the hopping determination step according to one embodiment of the present invention, and FIG. 7(b) shows the steps of executing the hopping determination step according to another embodiment of the present invention.

[0063] Specifically, in one embodiment of the present invention, the first condition relates to the amount of traffic in the network between the terminal 1000 and the computing device 3000, as shown in FIG. 7(a).

[0064] More specifically, when the hopping determination unit 4200 receives network information of a specific network from the service gateway 2000 (S22), it determines whether the traffic volume measured at a predetermined interval in the network between the corresponding terminal 1000 and the corresponding computing device 3000 exceeds a first criterion based on the received network information (S31.1), and if the traffic volume exceeds the first criterion, it determines that the corresponding network satisfies the first condition and transmits a request to change the first VR of the corresponding network to the service gateway 2000 (S32). If the traffic volume is equal to or less than the first criterion, the hopping determination unit 4200 does not perform any additional operation on the corresponding network, and the corresponding network is maintained.

[0065] Meanwhile, in another embodiment of the present invention, as shown in FIG. 7(b), the first condition relates to the creation time of the network between the terminal 1000 and the computing device 3000.

[0066] More specifically, when the hopping determination unit 4200 receives network information of a specific network from the service gateway 2000 (S22), it determines whether the generation time of the network between the corresponding terminal 1000 and the corresponding computing device 3000 exceeds a second criterion based on the received network information (S31.2), and if the generation time exceeds the second criterion, it determines that the corresponding network satisfies the first condition and sends a request to change the first VR of the corresponding network to the service gateway 2000 (S32).If the generation criterion is equal to or less than the second criterion, the hopping determination unit 4200 does not perform any additional operation on the corresponding network, and the corresponding network is maintained.

[0067] Meanwhile, the two embodiments of the first condition described above are compatible embodiments, and the hopping determination unit 4200 can send a request to change the first VR of a specific network to the service gateway 2000 (S32) when the traffic volume of the specific network exceeds the first determination criterion or the generation time of the specific network exceeds the second determination criterion.

[0068] Furthermore, the first condition may be set based on various criteria, such as traffic volume or generation time, as well as irregularly measured traffic volume (random timing), whether a cyber attack has occurred inside or outside the system, or whether abnormal behavior has occurred, as described above. The first condition is not limited to these. Furthermore, the above embodiments are compatible. For example, the first condition may be a condition that takes into consideration both traffic volume and whether a cyber attack has occurred inside or outside the system.

[0069] FIG. 8 is a schematic diagram illustrating a process of performing a VR hopping step according to one embodiment of the present invention, and FIG. 9 is a schematic diagram illustrating a process of performing a VR hopping step according to another embodiment of the present invention.

[0070] As shown in Figures 8 and 9, for a terminal 1000 and a computing device 3000 connected to a network that satisfies the first condition, the VR hopping step includes the steps of generating a new network between the terminal 1000 and the computing device 3000 using a new VR, blocking communication of the network that previously mediated communication between the terminal 1000 and the computing device 3000, and deleting the existing VR included in the blocked network.

[0071] 8(a) shows a process in which terminal #1 (1000.1) and terminal #2 (1000.2) communicate with computing device 3000 via network #1 and network #2, respectively. Referring to the above, service gateway 2000 transmits network information #2 for network #2 to hopping determination unit 4200 at predetermined intervals, and if hopping determination unit 4200 determines that network #2 satisfies the predetermined first condition, VR change request unit 4300 of controller 4000 performs a VR change request step for network #2.

[0072] Thereafter, the service gateway 2000 generates a first new VR (first VR#3 in FIGS. 8 and 9) corresponding to the request of the VR change request step, as shown in (b) of FIG. 8. Preferably, a new network for communication between the terminal #2 (1000.2) and the computing device 3000 is generated, and the new network includes the first new VR (first VR#3).

[0073] In this way, when network #3 including the first new VR (first VR #3) is generated, as shown in (c) of Figure 8, terminal #2 (1000.2) and computing device 3000 will communicate via network #3, and the service gateway 2000 will perform a step of deleting the first VR #2 included in the previously used network #2.

[0074] Meanwhile, FIG. 9 shows a process in which a VR hopping step is performed as an embodiment different from the embodiment in FIG.

[0075] 9(a), in a state where terminal #1 (1000.1) and terminal #2 (1000.2) are communicating with computing device 3000 via network #1 and network #2, respectively, service gateway 2000 transmits network information #2 for network #2 to hopping determination unit 4200. If hopping determination unit 4200 determines that network #2 satisfies the predetermined first condition, VR change request unit 4300 of controller 4000 performs a VR change request step for network #2.

[0076] 9(b), the service gateway 2000 performs a step of deleting the first VR #2 included in the network #2 that satisfies the first condition, and generates a first new VR (first VR #3) for communication between the terminal #2 (1000.2) and the computing device 3000. In this way, when the network #3 including the first new VR (first VR #3) is generated, the terminal #2 (1000.2) and the computing device 3000 communicate via the network #3.

[0077] As described above, the present invention has a technical feature in that logically separated networks are generated between a plurality of terminals 1000 and one or more computing devices 3000 through a hopping determination step, a VR change request step, a VR change response step, a VR change information transmission step, and a VR hopping step, and each network uses a first VR, and the first VR used is changed according to specific network information such as traffic volume or generation time.With these technical features, a communication system that performs a logically separated multiple network communication method with high security at a relatively low cost can be constructed.

[0078] FIG. 10 schematically shows a connection configuration of a communication system including a point gateway 1100 according to one embodiment of the present invention, and FIG. 11 schematically shows a configuration in which multiple terminals 1000 and a single computing device 3000 according to one embodiment of the present invention are connected via the point gateway 1100 and the service gateway 2000.

[0079] As shown in Figures 10 and 11, the multiple terminals 1000 include a point gateway 1100 that generates one or more VRs, and after generating one or more VRs, the point gateway 1100 uses the one or more VRs to generate networks between one or more edge terminals 1200 and the service gateway 2000, and the VRs used in each generated network are different so that each network is logically separated, and a network switch unit 5000 is provided between the point gateway 1100 and the service gateway 2000.

[0080] Specifically, the multiple terminals 1000 described in Figures 1 to 9 include a point gateway 1100 and an edge terminal 1200, and the point gateway 1100 generates one or more second VRs that mediate communication between one or more edge terminals 1200 and the service gateway 2000.

[0081] 10, a network switch unit 5000 is preferably provided between the point gateway 1100 and the service gateway 2000, and in one embodiment of the present invention, an L2 switch and an L3 switch are included in the network switch unit 5000. Meanwhile, in another embodiment of the present invention, the L2 switch is included in the network switch unit 5000, and the L3 switch is included in the service gateway 2000.

[0082] For ease of explanation, Fig. 11 shows an embodiment of communication between three edge terminals 1200 (edge ​​terminal #1 (1200.1) to edge terminal #3 (1200.3)) and a computing device 3000, and the network switch unit 5000 is not shown. As shown in Fig. 11, each of the networks that perform communication between the multiple edge terminals 1200 and the computing device 3000 includes a first VR generated by the service gateway 2000 and a second VR generated by the point gateway 1100, and each of the first VRs generated by the service gateway 2000 has different VR information, and each of the second VRs generated by the point gateway 1100 also has different VR information.

[0083] 11, a second VR is connected to one edge terminal 1200, and a second VR is connected to multiple edge terminals 1200, such as edge terminals #2 to #3 (1200.2 to 1200.3) and second VR #2. More specifically, when the communication system of the present invention is installed in a multi-family home such as an apartment, the point gateway 1100 is preferably provided for each generation, and each of the point gateways 1100 provided for each generation can be connected to one or more edge terminals 1200, such as a wall pad, IoT phone, or smartphone, and the network between one or more edge terminals 1200 and the computing device 3000 is logically separated and operated.

[0084] In other words, the communication system of the present invention can achieve the effect of separating each network in various combinations by combining the first VR and the second VR implemented between the terminal 1000 (or the edge terminal 1200) and the computing device 3000, and can have improved security compared to a technology that separates networks using multiple VRs in one gateway.

[0085] FIG. 12 schematically illustrates a process in which VR hopping is performed in a point gateway 1100 according to one embodiment of the present invention, and FIG. 13 schematically illustrates a process in which VR hopping is performed in a point gateway 1100 according to another embodiment of the present invention.

[0086] As shown in Figures 12 and 13, the logical multiplexed network separation communication method of the present invention includes the steps of: in the controller 4000, determining whether there is a network between the edge terminal 1200 and the service gateway 2000 that satisfies a predetermined second condition; in the controller 4000, if a network that satisfies the second condition exists, requesting the point gateway 1100 to change the VR; in the point gateway 1100, sending information related to the VR that corresponds to the request of the controller 4000 to the controller 4000; in the controller 4000, passing information corresponding to the information related to the VR to the edge terminal 1200 and the point gateway 1100; and in the point gateway 1100, hopping the VR used in the network that satisfies the second condition to the generated VR.

[0087] Specifically, FIG. 12(a) shows a process in which edge terminal #1 (1200.1) and edge terminal #2 (1200.2) communicate with computing device 3000 via network #1 and network #2, respectively. Although FIGS. 12 and 13 show only the second VR, in reality, the first VR generated by service gateway 2000 is also included. In reference to the above, point gateway 1100 transmits network information #2 for network #2 to controller 4000 at predetermined intervals. If controller 4000 determines that network #2 satisfies a predetermined second condition, controller 4000 requests a change of the second VR for network #2. Meanwhile, the second condition may be the same as the first condition in one embodiment of the present invention, or may be a condition different from the first condition in another embodiment of the present invention. For example, with reference to the above, the first condition is related to traffic volume, and the second condition is set when abnormal behavior occurs.

[0088] Thereafter, the point gateway 1100 generates a second new VR (second VR #3 in FIGS. 8 and 9) corresponding to the second VR change request, as shown in FIG. 12(b). Preferably, a new network for communication between the edge terminal #2 (1200.2) and the computing device 3000 is generated, and the new network includes the second new VR (second VR #3). Meanwhile, in this case, generating a new network can be narrowly interpreted as newly generating the entire network that existed between the edge terminal 1200 and the computing device 3000, but from a broader perspective, it can also be interpreted as changing only the configuration related to the second VR within the network that was operating between the edge terminal 1200 and the computing device 3000. In this regard, it is preferable to interpret it in the broadest sense.

[0089] In this way, when network #3 including a second new VR (second VR #3) is generated, as shown in (c) of Figure 12, the edge terminal #2 (1200.2) and the computing device 3000 will communicate via network #3, and the point gateway 1100 will perform a step of deleting the second VR #2 included in the previously used network #2.

[0090] Meanwhile, FIG. 13 shows a process in which a step of hopping a VR is performed by a point gateway, as an embodiment different from the embodiment in FIG.

[0091] Specifically, as shown in (a) of Figure 13, when edge terminal #1 (1200.1) and edge terminal #2 (1200.2) are each communicating with computing device 3000 via network #1 and network #2, the point gateway 1100 sends network information #2 for network #2 to the controller 4000, and if the controller 4000 determines that network #2 satisfies the specified second condition, the controller 4000 requests a change of the second VR for network #2.

[0092] 13(b), the point gateway 1100 performs a step of deleting the second VR #2 included in the network #2 that satisfies the second condition, and generates a second new VR (second VR #3) that performs communication between the edge terminal #2 (1200.2) and the computing device 3000. In this way, when the network #3 including the second new VR (second VR #3) is generated, the edge terminal #2 (1200.2) and the computing device 3000 perform communication via the network #3.

[0093] As described above, the present invention provides higher security than a configuration in which VR is generated only in one gateway by periodically changing VR not only in the service gateway 2000 but also in the point gateway 1100, and allows networks to be configured in various combinations. Also, multiple edge terminals 1200 located in the same physical / logical location (e.g., the same generation) can communicate with the computing device 3000 in separate networks, so that even if one edge terminal 1200 is hacked, the other edge terminals 1200 can avoid the same hacking.

[0094] FIG. 14 is a diagram schematically illustrating differences between an embodiment of the present invention and the prior art.

[0095] Figure 14(a) shows a configuration in which an edge terminal 1200 communicates with multiple servers using conventional VPN technology, and Figure 14(b) shows a configuration in which the communication system of the present invention is applied and the edge terminal 1200 communicates with multiple servers. Here, the multiple servers (servers #1 to #3) in Figure 14 correspond to the computing device 3000 described above.

[0096] Specifically, as shown in Figure 14(a), when multiple servers are connected to one network (e.g., a corporate network) and the network is separated from the external Internet by one VPN server, the prior art regards the network as an implicit trusted area, and the multiple servers within the network are not separated from each other. In such a case, if a threat such as hacking infiltrates one of the multiple servers, it is highly likely that the other servers located on the same network will also be infiltrated by the same threat.

[0097] On the other hand, as shown in (b) of Figure 14, when the communication system of the present invention is applied, even if multiple servers are connected to the same network, the network through which each of the multiple servers communicates with the edge terminal 1200 is separated from each other, so even if a threat such as hacking penetrates one server, the other servers are safe from the same threat.

[0098] That is, the communication system of the present invention can improve the security of each network by transmitting and receiving data packets through a network tunnel formed separately between the point gateway 1100 and the service gateway 2000 and a network tunnel formed separately between the service gateway 2000 and the computing device 3000. Packets transmitted and received through the network tunnel are encapsulated packets, and when approaching a communication path corresponding to the network tunnel from the outside, only the encapsulated packets can be identified, providing stability against external hacking. In an embodiment of the present invention, the network tunnel can be applied with various known tunneling technologies such as IPIP Tunnel, SIT Tunnel, GRE, FOU, GUE FENEVE, etc.

[0099] According to the present invention, by configuring independent networks for media, customers, and servers, it is possible to control and manage network access, thereby enhancing security.

[0100] According to the present invention, by forming a logically separated network, security can be improved and costs can be reduced compared to constructing physically independent networks.

[0101] According to the present invention, by using the VPN hopping technology, it is possible to have higher security than the conventional VPN technology.

[0102] According to the present invention, since each of the multiple terminals is operated on an independent network, even if one terminal is hacked, damage to the remaining terminals can be minimized.

[0103] According to the present invention, even in an environment where an existing network has been constructed, a new network can be constructed with minimal physical configuration changes, thereby achieving the effect of wide scalability.

[0104] Although the embodiments have been described above with reference to limited embodiments and drawings, those skilled in the art will appreciate that various modifications and variations may be made from the above description. For example, the described techniques may be performed in a different order than described, and / or the components of the described systems, structures, devices, circuits, etc. may be combined in a different manner than described, or may be replaced or substituted with other components or equivalents, while still achieving suitable results.

[0105] Therefore, other implementations, other embodiments, and equivalents of the claims are within the scope of the following claims.

Claims

1. A method for logically separating multiple networks through VPN hopping in a communication system including a plurality of terminals, a service gateway, a controller, and one or more computing devices, comprising: a hopping determination step in the controller for determining whether there is a network between the terminal and each of the computing devices that satisfies a predetermined first condition; a VR change request step of requesting a service gateway that mediates communication between the terminal and the computing device to change a VR when a network that satisfies the first condition exists in the controller; a VR change response step of transmitting new VR information related to the new VR corresponding to the request to the controller in the service gateway; a VR change information transmission step in which, in a controller, new VR change information corresponding to the new VR information is transferred to the terminal and the service gateway; and a VR hopping step in which, in a service gateway, an existing VR that has already been used in a network that satisfies the first condition is hopped to the new VR based on the new VR change information.

2. The service gateway 2. The logically multiplexed network separation communication method of claim 1, wherein one of a plurality of VRs generated by the service gateway is assigned to each network connecting the plurality of terminals and the one or more computing devices, and the VRs used in different networks are different, so that each network is logically separated.

3. The logical multiplexed network separation communication method comprises: The method further includes a terminal authentication step of authenticating a terminal that performs communication in the controller, The terminal authentication step includes: an identification information receiving step of receiving identification information for the corresponding terminal from the terminal; an identification information verification step of verifying the identification information; a verification result transmission step of transmitting a verification result of the identification information to the service gateway; 2. The method of claim 1, wherein the service gateway generates a network that allows only authenticated terminals to communicate with the computing device.

4. The VR change response step includes: generating a new VR corresponding to the request; sending new VR information related to the new VR to the controller; 2. The logically multiplexed network separation communication method according to claim 1, wherein the new VR has VR information different from other VRs that are generated and in operation by the service gateway.

5. For terminals and computing devices connected to a network that satisfies the first condition, The VR hopping step includes: generating a new network between the corresponding terminal and the corresponding computing device using the new VR; Cutting off communication of a network that previously mediated communication between the corresponding terminal and the corresponding computing device; 2. The logically multiplexed network separation communication method according to claim 1, further comprising the step of deleting an existing VR included in the blocked network.

6. The plurality of terminals include a point gateway that generates one or more VRs, The point gateway After generating one or more VRs, use the one or more VRs to generate networks between one or more edge terminals and the service gateway, and use different VRs in each generated network so that each network is logically separated; 2. The logically multiplexed network separation communication method according to claim 1, wherein a network switch unit is provided between the point gateway and the service gateway.

7. The logical multiplexed network separation communication method comprises: determining, in the controller, whether there is a network between the edge terminal and the service gateway that satisfies a predetermined second condition; In the controller, when a network that satisfies the second condition exists, a step of requesting the point gateway to change the VR; In the point gateway, information related to the VR corresponding to the request of the controller is transmitted to the controller; In a controller, transmitting information corresponding to the VR-related information to the edge terminal and the point gateway; 7. The logical multiplexed network separation communication method according to claim 6, further comprising a step of hopping, in a point gateway, a VR used in a network that satisfies the second condition to the generated VR.

8. the first condition relates to the amount of traffic on a network between the terminal and the computing device; The hopping determination step includes:

2. The logical multiplexed network separation communication method according to claim 1, wherein if the traffic volume measured at each predetermined period in the network between the terminal and the computing device exceeds a first judgment criterion, the corresponding network is determined to satisfy the first condition.

9. A communication system that performs a logical multiplexed network separation communication method through VPN hopping, comprising a plurality of terminals, a service gateway, a controller, and one or more computing devices, a hopping determination unit in the controller that determines whether a network between the terminal and each of the computing devices satisfies a predetermined first condition; a VR change request unit in the controller that requests a VR change to a service gateway that mediates communication between the terminal and the computing device when a network that satisfies the first condition exists; a VR change response unit in the service gateway that transmits new VR information related to the new VR corresponding to the request to the controller; a VR change information transmission unit in the controller that transfers new VR change information corresponding to the new VR information to the terminal and the service gateway; A communication system characterized by including a VR hopping unit in a service gateway that hops an existing VR that has already been used in a network that satisfies the first condition to the new VR based on the VR change information.