Access Gateway Tunnel Provisioning for Flexible Private Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for connecting local Internet data centers or network devices to virtual private clouds require dedicated lines, which are costly and inconvenient for users who frequently move or need multi-location deployment, and are affected by operator construction timelines.

Innovation Solution

A network access control method that delivers tunnel creation instructions and configuration information to access devices, reducing reliance on dedicated lines by establishing transmission tunnels through access gateways and gateways, utilizing protocols like IPSec and VXLAN, and implementing equal-cost multi-path routing (ECMP) for redundancy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated lines are used to connect local data centers to virtual private clouds, then network connection stability is improved, but cost increases and deployment flexibility decreases

Engineering Contradiction:
Improvenetwork connection stabilityVSAvoiddeployment flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an access gateway as an intermediary device that enables connectivity between access devices and virtual private clouds through a transmission tunnel. This mediator allows users to access private networks via mobile networks instead of dedicated lines, maintaining connection stability while significantly improving deployment flexibility and eliminating the need for physical dedicated infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/physical dedicated line connection system with a virtual transmission tunnel system. Instead of requiring physical dedicated cables and infrastructure, the system uses virtualized network tunnels over existing mobile networks to achieve similar connectivity functions, thereby reducing cost and increasing adaptability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If dedicated lines are used for network access, then connection reliability is improved, but installation time increases due to operator construction requirements

Engineering Contradiction:
Improveconnection reliabilityVSAvoidinstallation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-establishing transmission tunnels between access gateways and virtual private clouds before users need to access the network. The access gateway proactively creates the necessary network pathways and configuration information, so when users connect, the infrastructure is already in place, eliminating delays caused by operator construction and installation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access gateway serves as an intermediary that handles all the complex network setup and tunnel establishment tasks automatically. This mediator device performs the preliminary actions of creating transmission tunnels and configuring network parameters, thereby eliminating the need for manual installation and reducing time loss associated with operator construction requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If transmission tunnels are established through access gateways, then network access speed is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork access speedVSAvoidsystem complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling access devices to automatically establish transmission tunnels with access gateways without requiring manual configuration. The access device receives configuration information from the access gateway and autonomously completes the tunnel setup process, which simplifies the user experience while maintaining fast network access speeds.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The access gateway acts as an intermediary that manages the complexity of transmission tunnel establishment and configuration. By centralizing these complex operations at the access gateway, the system achieves fast network access speeds while keeping the overall system complexity manageable through automated and centralized management.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If automatic configuration is implemented, then ease of operation is improved, but configuration management complexity increases

Engineering Contradiction:
Improveconfiguration easeVSAvoidconfiguration management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements self-service by allowing access devices to automatically receive and apply configuration information without manual intervention. The access device autonomously configures itself by receiving configuration information from the access gateway, which significantly improves ease of operation while the automated nature of the process actually reduces configuration management complexity compared to manual methods.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250385812A1Access control
Publication Date: 2025.12.18 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US20250385812A1 patent drawing
  • US20250385812A1 patent drawing
  • US20250385812A1 patent drawing

AI summary

According to a method for access control, device information of an access device and private network information of a private network to be accessed by the access device are acquired. A tunnel creation instruction is transmitted to an access gateway of the private network according to the private network information, the tunnel creation instruction instructs the access gateway to establish a transmission tunnel with the access device. Configuration information for instructing the access device to establish the transmission tunnel with the access gateway is generated. The configuration information is transmitted to the access device in response to a detection that the access device goes online, the configuration information causes the access device to establish the transmission tunnel with the access gateway, and causes the access device to access the private network based on the transmission tunnel. Apparatus and non-transitory computer-readable storage medium counterpart embodiments are also contemplated.