Cloud VPN Gateway for Secure Remote Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional VPN solutions face challenges in seamlessly connecting users across internal networks, private clouds, and public clouds, leading to increased bandwidth, administrative complexity, and security vulnerabilities, especially for nomadic users and branch offices, as they require hairpinning traffic through the corporate data center and installing VPN servers in every private cloud.

Innovation Solution

A cloud-based virtual private access system that creates secure tunnels between user devices and resources in public clouds and enterprise networks, using a central authority for policy lookup and connection determination, with lightweight connectors preventing inbound connections and eliminating the need for dedicated hardware, allowing on-demand dial-out connections from an on-premises redirection proxy to the cloud.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional VPN solutions are used to enable remote users to access enterprise networks and cloud resources, then network security is maintained through centralized control, but bandwidth consumption increases linearly with every new branch or nomadic user due to hairpinning traffic through the corporate data center

Engineering Contradiction:
Improvenetwork securityVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts the VPN termination function from the corporate data center and relocates it to cloud-based VPN servers. This allows remote users to establish direct VPN connections to cloud resources without hairpinning traffic through the data center, reducing bandwidth consumption while maintaining centralized security control through the cloud VPN gateway

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a cloud-based VPN gateway as an intermediary between remote users and enterprise networks. This gateway terminates VPN connections from remote users and establishes separate connections to enterprise resources, acting as a mediator that reduces direct traffic flow through the data center while maintaining security policies

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If VPN servers are installed in every private cloud to enable direct access, then connection speed and directivity improve, but administrative complexity and device complexity increase significantly

Engineering Contradiction:
Improveconnection speedVSAvoidadministrative complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent implements a universal cloud-based VPN gateway that serves multiple functions: terminating VPN connections from remote users, enforcing security policies, routing traffic to multiple enterprise resources, and managing authentication. This single multi-functional gateway replaces the need for multiple dedicated VPN servers in each private cloud, reducing administrative complexity while maintaining direct connectivity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If traditional VPN solutions extend network perimeter to remote users, then users can access enterprise applications, but security risks increase because users gain full network access rather than application-specific access

Engineering Contradiction:
Improveapplication accessibilityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements application-specific access policies at the cloud VPN gateway, where different users receive different levels of access to specific applications rather than blanket network access. This localizes security controls to the application level, allowing users to access only the specific applications they need while limiting their network perimeter exposure

Inventive Principle:
Principle #3Local quality

4Reliability

If multiple data centers and load balancers are deployed to increase reachability and performance, then application availability improves, but cost and device complexity increase

Engineering Contradiction:
Improveapplication availabilityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple data center functions into a cloud-based infrastructure, where the cloud VPN gateway and cloud-hosted applications replace the need for multiple distributed data centers and load balancers. This consolidation maintains application availability through cloud redundancy while reducing infrastructure complexity and cost

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3247082B1Cloud-based virtual private access systems and methods
Publication Date: 2021.06.16 ZSCALER INC
  • EP3247082B1 patent drawingFigure 1
  • EP3247082B1 patent drawingFigure 2~3
  • EP3247082B1 patent drawingFigure 4

AI summary

A virtual private access method implemented by a cloud system, includes receiving a request to access resources from a user device, wherein the resources are located in one of a public cloud and an enterprise network and the user device is remote therefrom on the Internet; forwarding the request to a central authority for a policy look up and for a determination of connection information to make an associated secure connection through the cloud system to the resources; receiving the connection information from the central authority responsive to an authorized policy look up; and creating secure tunnels between the user device and the resources based on the connection information.