Automated VPN Access via Virtual Machine Host Servers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for accessing a data management server via a virtual private network (VPN) are inefficient and costly, requiring multiple physical machines for scaling and disrupting real-time access, with existing solutions failing to provide seamless and automated connectivity and performance auditing.

Innovation Solution

The implementation of host virtual machine servers capable of running multiple virtual machines, which establish and manage VPN tunnels dynamically, using open-source and proprietary software to automate VPN connections, retry failed connections, and migrate to reliable hardware without user intervention, ensuring continuous access and efficient troubleshooting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple physical machines are used to establish VPN connections to scale access to data management servers, then the number of concurrent connections increases, but hardware cost and system complexity increase proportionally

Engineering Contradiction:
Improveconcurrent connection capacityVSAvoidhardware requirements
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

Multiple virtual machine instances are merged onto a single physical host server, allowing multiple VPN connections to be established concurrently from one physical machine. The virtualization platform enables multiple isolated virtual operating systems to share the physical hardware resources, thereby increasing concurrent connection capacity without proportionally increasing hardware requirements.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The host virtual machine server is designed to perform multiple functions simultaneously - it can host multiple different virtual machine instances, each capable of establishing VPN connections to different data management servers. This multi-functionality allows a single physical machine to replace what would traditionally require multiple dedicated physical machines.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If manual configuration and monitoring of VPN connections is performed, then connection establishment is straightforward, but automation and real-time performance auditing are lacking

Engineering Contradiction:
Improveconnection setup simplicityVSAvoidVPN connection automation
Core Design Contradiction:
Ease of operationVSExtent of automation

Solution Approach 1:

The system implements automated self-service capabilities where the virtual machine instances automatically establish, maintain, and monitor their own VPN connections. The host server provides automated provisioning and the system includes self-diagnostic features that monitor connection health and performance without requiring manual intervention, thereby achieving both ease of operation and high automation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates real-time feedback mechanisms that automatically monitor VPN connection performance, detect issues, and trigger appropriate responses. Performance metrics are continuously collected and analyzed, enabling automated troubleshooting and maintaining optimal connection states without manual configuration while preserving operational simplicity.

Inventive Principle:
Principle #23Feedback

3Reliability

If VPN connections are established without automated retry logic, then connection establishment is faster when successful, but connection reliability decreases when failures occur

Engineering Contradiction:
ImproveVPN connection reliabilityVSAvoidconnection establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system pre-configures retry logic and connection parameters before VPN connection attempts are made. When connection failures occur, the automated retry mechanism immediately attempts reconnection using pre-established parameters, minimizing the time loss while ensuring high reliability through persistent retry attempts until successful connection is achieved.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7801154B2System and method for automated access of a data management server through a virtual private network
Publication Date: 2010.09.21 CDK GLOBAL LLC
  • US7801154B2 patent drawing
  • US7801154B2 patent drawing
  • US7801154B2 patent drawing

AI summary

A provider system connects through a virtual private network to a site having various possible virtual private network variants. A virtual private network connection is established to site data management server through a network interface. A virtual machine server, including virtual machines, communicates with the provider system. Each virtual machine is capable of building a virtual private network tunnel connection, over a network, to a site data management server. In establishing a connection, a connection script is executed, a virtual private network is determined, and a virtual private network protocol is executed.