Adaptive Multipath Tunneling for Mobile Network Redundancy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional SSL and IPSec VPN solutions for mobile devices face performance and scalability challenges due to resource constraints and frequent network changes, leading to inefficient resource usage and user experience issues.

Innovation Solution

Adaptive multipath tunneling is implemented, allowing mobile devices to establish multiple VPN tunnels on available link-layer channels, intercepting and forwarding network traffic based on traffic forwarding rules, and managing tunnels during network changes to maximize resource usage and redundancy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional SSL and IPSec VPN solutions are used to steer all traffic through a centralized gateway, then security and policy compliance are improved, but performance and scalability deteriorate due to resource constraints and frequent network changes

Engineering Contradiction:
ImprovesecurityVSAvoidperformance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the single VPN tunnel into multiple parallel tunnels across different link-layer channels. Each tunnel handles a portion of the traffic, distributing the load and improving performance while maintaining security through centralized gateway access. This resolves the contradiction by dividing the traffic flow to reduce bottlenecks without compromising security requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic tunnel management that automatically adapts to network changes. When network conditions change or links fail, the system dynamically reroutes traffic through alternative tunnels and channels. This dynamic behavior maintains both security (by ensuring all traffic reaches the gateway) and performance (by optimizing path selection and avoiding bottlenecks).

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If mobile devices frequently hop between networks (cellular and Wi-Fi), then network flexibility and user mobility are improved, but VPN tunnel stability deteriorates due to repeated tunnel teardown and reestablishment

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidtunnel stability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent creates multiple VPN tunnels across different link-layer channels simultaneously. When a device hops between networks, not all tunnels are affected - some may remain active while others are disrupted. This segmentation provides redundancy and maintains tunnel stability while allowing network flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system establishes multiple backup tunnels in advance across different networks. When network hopping occurs, already-established tunnels provide immediate failover paths, cushioning against the instability that would otherwise result from complete tunnel teardown. This pre-positioning of alternative paths maintains both flexibility and stability.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Productivity

If multiple VPN tunnels are established on different link-layer channels, then throughput and redundancy are improved, but device complexity increases

Engineering Contradiction:
ImprovethroughputVSAvoidtunnel management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the system automatically manages multiple tunnels without requiring complex user configuration. The device autonomously establishes, monitors, and maintains multiple tunnels across different channels, handling routing decisions and failover automatically. This reduces the effective complexity for users while enabling high throughput through multiple parallel paths.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal tunnel management system that handles multiple link-layer channels through a single unified interface and control mechanism. Rather than requiring separate management for each tunnel, the system provides multi-functional capability to manage all tunnels collectively, reducing complexity while maintaining the throughput benefits of multiple channels.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If all network traffic is backhauled to a centralized gateway for security scanning and policy enforcement, then security compliance is improved, but resource efficiency deteriorates due to wasted processing power during tunnel reestablishment

Engineering Contradiction:
Improvesecurity complianceVSAvoidresource efficiency
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments traffic into multiple parallel tunnels, allowing simultaneous transmission through different paths to the centralized gateway. This maintains security compliance by ensuring all traffic is inspected while improving resource efficiency through parallel processing and reduced idle time during network transitions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system maintains continuous useful action by keeping multiple tunnels active simultaneously. When network changes occur, at least one tunnel remains functional, avoiding complete tunnel teardown and reestablishment cycles. This continuity eliminates the resource waste associated with repeated authentication and tunnel setup while maintaining uninterrupted security scanning at the gateway.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS12101318B2Adaptive multipath tunneling in cloud-based systems
Publication Date: 2024.09.24 ZSCALER INC
  • US12101318B2 patent drawing
  • US12101318B2 patent drawing
  • US12101318B2 patent drawing

AI summary

Systems and methods implemented by a mobile device include establishing a plurality of tunnels to a gateway, wherein each of the plurality of tunnels is on one of a plurality of link layer channels at the mobile device; intercepting network traffic on the mobile device; forwarding the network traffic to one of the plurality of tunnels based on a set of traffic forwarding rules; and responsive to a network change for the mobile device, managing the plurality of tunnels and continuing the forwarding based on the managing. The systems and methods can further include determining characteristics including bandwidth of each of the plurality of link layer channels; and utilizing the characteristics with the set of traffic forwarding rules for the forwarding.