Cloud-Based Global VPN System for Dynamic Tunnel Orchestration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current VPN solutions require IT administrators to manage complex and insecure setups, increasing bandwidth and administrative complexity, especially when connecting nomadic users or branch offices to internal and cloud-based data assets, as they often necessitate hairpinning traffic through the corporate data center and installing VPN servers in every private cloud.

Innovation Solution

A cloud-based global VPN system that uses a topology controller, on-premises redirection proxy, and distributed security cloud to establish secure tunnels dynamically, allowing clients to connect directly to cloud-based VPN devices without traversing the corporate data center, thus reducing administrative complexity and security vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional VPN solutions are used to connect nomadic users to enterprise assets, then security is maintained, but bandwidth requirements increase linearly with every new branch or user

Engineering Contradiction:
ImprovesecurityVSAvoidbandwidth
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts the VPN termination function from the enterprise data center and places it in the cloud. Cloud-based VPN devices terminate secure tunnels for nomadic users, while enterprise assets remain in place. This extraction eliminates the need for all user traffic to traverse the data center, reducing bandwidth requirements while maintaining security through centralized cloud-based VPN management.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces cloud-based VPN devices as intermediary components between nomadic users and enterprise assets. These cloud VPN devices establish secure tunnels with users and route traffic efficiently, acting as mediators that eliminate the need for direct data center traversal and reduce overall bandwidth consumption while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If VPN servers are installed in every private cloud to enable direct connections, then connectivity is improved, but administrative complexity increases

Engineering Contradiction:
ImproveconnectivityVSAvoidadministrative complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent employs a universal cloud-based VPN device that serves multiple functions: it provides VPN termination for nomadic users, enables connections to both private cloud and on-premises assets, and centralizes security management. This single multi-functional platform replaces the need for multiple distributed VPN servers, reducing administrative complexity while maintaining connectivity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the functions of multiple distributed VPN servers into a single cloud-based VPN platform. By combining VPN termination, traffic routing, and security management in one centralized location, the system eliminates the need for administrators to manage separate VPN infrastructure at each private cloud, thereby reducing administrative complexity.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If point-to-point dedicated VPNs are used to connect to private cloud, then secure access is achieved, but traffic must hairpin back to corporate data center increasing bandwidth

Engineering Contradiction:
Improvesecure accessVSAvoidtraffic volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts the VPN termination function from the enterprise data center and places it in the cloud. Cloud-based VPN devices terminate secure tunnels for nomadic users, while enterprise assets remain in place. This extraction eliminates the need for all user traffic to traverse the data center, reducing bandwidth requirements while maintaining security through centralized cloud-based VPN management.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9350710B2Intelligent, cloud-based global virtual private network systems and methods
Publication Date: 2016.05.24 ZSCALER INC
  • US9350710B2 patent drawing
  • US9350710B2 patent drawing
  • US9350710B2 patent drawing

AI summary

A method includes connecting to a client at a Virtual Private Network (VPN) device in a cloud system; forwarding requests from the client for the Internet or public clouds accordingly; and, for requests for an enterprise associated with the client, contacting a topology controller to fetch a topology of the enterprise, causing a tunnel to be established from the enterprise to the VPN device, and forwarding the requests for the enterprise through the tunnel. A cloud system and VPN system are also described. Advantageously, connections between the cloud and on-premises proxy are dynamic, on-demand and orchestrated by the cloud. Security is provided at the edge—there is no need to punch any holes in the existing on-premises firewalls.