Cloud VPN Gateway for Secure Remote Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional VPN solutions face challenges in seamlessly connecting users across internal networks, private clouds, and public clouds, leading to increased bandwidth, administrative complexity, and security vulnerabilities, especially for nomadic users and branch offices, as they require hairpinning traffic through the corporate data center and installing VPN servers in every private cloud.
Innovation Solution
A cloud-based virtual private access system that creates secure tunnels between user devices and resources in public clouds and enterprise networks, using a central authority for policy lookup and connection determination, with lightweight connectors preventing inbound connections and eliminating the need for dedicated hardware, allowing on-demand dial-out connections from an on-premises redirection proxy to the cloud.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional VPN solutions are used to enable remote users to access enterprise networks and cloud resources, then network security is maintained through centralized control, but bandwidth consumption increases linearly with every new branch or nomadic user due to hairpinning traffic through the corporate data center
Solution Approach 1:
The patent extracts the VPN termination function from the corporate data center and relocates it to cloud-based VPN servers. This allows remote users to establish direct VPN connections to cloud resources without hairpinning traffic through the data center, reducing bandwidth consumption while maintaining centralized security control through the cloud VPN gateway
Solution Approach 2:
The patent introduces a cloud-based VPN gateway as an intermediary between remote users and enterprise networks. This gateway terminates VPN connections from remote users and establishes separate connections to enterprise resources, acting as a mediator that reduces direct traffic flow through the data center while maintaining security policies
2Speed
If VPN servers are installed in every private cloud to enable direct access, then connection speed and directivity improve, but administrative complexity and device complexity increase significantly
Solution Approach 1:
The patent implements a universal cloud-based VPN gateway that serves multiple functions: terminating VPN connections from remote users, enforcing security policies, routing traffic to multiple enterprise resources, and managing authentication. This single multi-functional gateway replaces the need for multiple dedicated VPN servers in each private cloud, reducing administrative complexity while maintaining direct connectivity
3Ease of operation
If traditional VPN solutions extend network perimeter to remote users, then users can access enterprise applications, but security risks increase because users gain full network access rather than application-specific access
Solution Approach 1:
The patent implements application-specific access policies at the cloud VPN gateway, where different users receive different levels of access to specific applications rather than blanket network access. This localizes security controls to the application level, allowing users to access only the specific applications they need while limiting their network perimeter exposure
4Reliability
If multiple data centers and load balancers are deployed to increase reachability and performance, then application availability improves, but cost and device complexity increase
Solution Approach 1:
The patent merges multiple data center functions into a cloud-based infrastructure, where the cloud VPN gateway and cloud-hosted applications replace the need for multiple distributed data centers and load balancers. This consolidation maintains application availability through cloud redundancy while reducing infrastructure complexity and cost
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
A virtual private access method implemented by a cloud system, includes receiving a request to access resources from a user device, wherein the resources are located in one of a public cloud and an enterprise network and the user device is remote therefrom on the Internet; forwarding the request to a central authority for a policy look up and for a determination of connection information to make an associated secure connection through the cloud system to the resources; receiving the connection information from the central authority responsive to an authorized policy look up; and creating secure tunnels between the user device and the resources based on the connection information.