Context-Based Path Selection for Secure Remote VPN Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing remote access solutions for VPN clients rely on simplistic destination IP address-based path selection, which is ineffective in terms of security and cost when accessing network-based applications across multiple service providers and clouds.
Innovation Solution
Implement a context-based path selection mechanism that uses attribute collection and policy rule creation to select optimal paths based on source and destination attributes, considering factors like security, risk, cost, availability, load, and business function, with the ability to adapt to location, date, and time variations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If destination IP address-based path selection is used, then path selection simplicity is improved, but security and cost optimization deteriorate
Solution Approach 1:
The patent changes the selection parameters from simple destination IP address to multiple context-based attributes including source IP address, destination port, application type, user identity, device type, location, and time of day. This allows the system to select from multiple paths based on comprehensive context rather than a single parameter, resolving the contradiction between simplicity and security.
Solution Approach 2:
The patent adds multiple dimensions to the path selection process by introducing context-based attributes beyond the traditional single dimension of destination IP address. The system evaluates traffic across multiple dimensions (source characteristics, destination characteristics, temporal factors, spatial factors) to make informed path selection decisions, thereby improving security without sacrificing operational simplicity.
2Ease of operation
If destination IP address-based path selection is used, then path selection simplicity is improved, but cost optimization deteriorates
Solution Approach 1:
The patent introduces cost as a selection parameter alongside security and performance metrics. The context-based path selection mechanism evaluates multiple paths using a scoring system that incorporates cost considerations, allowing the system to select cost-effective paths while maintaining security requirements. This resolves the contradiction by adding cost optimization capability without complicating the user interface.
Solution Approach 2:
The patent implements dynamic path selection that adapts to changing conditions including time of day, location, network load, and cost variations. The system can dynamically adjust path selection based on real-time context, optimizing for cost when appropriate while maintaining security. This dynamic approach allows cost optimization without requiring complex manual configuration from users.
3Reliability
If context-based path selection with multiple attributes is implemented, then security and cost optimization are improved, but system complexity increases
Solution Approach 1:
The patent introduces a policy server as an intermediary that centralizes the complex path selection logic. Instead of distributing complexity across multiple VPN gateways or client devices, the policy server consolidates attribute collection, context evaluation, and path selection algorithms in a single location. This resolves the contradiction by improving security through sophisticated context-based selection while managing system complexity through centralized architecture.
Solution Approach 2:
The patent segments the path selection system into distinct functional components: attribute collection modules at VPN gateways, context evaluation logic at the policy server, and path selection algorithms that consider multiple factors including security, cost, and performance. This segmentation allows each component to specialize in specific tasks, improving overall security and optimization capabilities while managing complexity through modular design.
4Reliability
If context-based path selection with multiple attributes is implemented, then security and cost optimization are improved, but implementation difficulty increases
Solution Approach 1:
The patent implements automatic attribute collection at VPN gateways that self-report relevant traffic characteristics to the policy server without requiring manual configuration. The system automatically gathers source IP addresses, destination ports, application types, and other context attributes, reducing implementation difficulty while maintaining sophisticated security capabilities. This self-service approach allows the system to implement complex context-based selection without burdening deployers with manual setup.
Solution Approach 2:
The patent incorporates feedback mechanisms where the policy server receives attribute information from VPN gateways, processes context-based path selection, and returns policy decisions that are implemented by the gateways. This feedback loop enables the system to adapt to changing conditions and optimize security and cost performance dynamically. The standardized feedback protocol simplifies implementation by providing a clear communication interface between components.
Data Source
AI summary
A server may receive, from a virtual private network (VPN) client of a client device, a message which indicates a request for a policy rule for communications with a network-based application (e.g. provided via a data center or cloud computing services). The server may obtain source attributes of the client device and a user thereof based on source identifiers, and destination attributes of the application based on a destination identifier, and select a policy rule associated with the attributes (e.g. indicative of security, risk, cost, load, and/or business function). The server may send a message which indicates a response and includes the policy rule for application at the VPN client. The policy rule may indicate a policy action for selecting a path, of a plurality of paths, identified by a path identifier, and specify conditions such as a location and/or a date, day, and/or time of the client device.


