Context-Based Path Selection for Secure Remote VPN Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote access solutions for VPN clients rely on simplistic destination IP address-based path selection, which is ineffective in terms of security and cost when accessing network-based applications across multiple service providers and clouds.

Innovation Solution

Implement a context-based path selection mechanism that uses attribute collection and policy rule creation to select optimal paths based on source and destination attributes, considering factors like security, risk, cost, availability, load, and business function, with the ability to adapt to location, date, and time variations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If destination IP address-based path selection is used, then path selection simplicity is improved, but security and cost optimization deteriorate

Engineering Contradiction:
Improvepath selection simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent changes the selection parameters from simple destination IP address to multiple context-based attributes including source IP address, destination port, application type, user identity, device type, location, and time of day. This allows the system to select from multiple paths based on comprehensive context rather than a single parameter, resolving the contradiction between simplicity and security.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent adds multiple dimensions to the path selection process by introducing context-based attributes beyond the traditional single dimension of destination IP address. The system evaluates traffic across multiple dimensions (source characteristics, destination characteristics, temporal factors, spatial factors) to make informed path selection decisions, thereby improving security without sacrificing operational simplicity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of operation

If destination IP address-based path selection is used, then path selection simplicity is improved, but cost optimization deteriorates

Engineering Contradiction:
Improvepath selection simplicityVSAvoidcost
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The patent introduces cost as a selection parameter alongside security and performance metrics. The context-based path selection mechanism evaluates multiple paths using a scoring system that incorporates cost considerations, allowing the system to select cost-effective paths while maintaining security requirements. This resolves the contradiction by adding cost optimization capability without complicating the user interface.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements dynamic path selection that adapts to changing conditions including time of day, location, network load, and cost variations. The system can dynamically adjust path selection based on real-time context, optimizing for cost when appropriate while maintaining security. This dynamic approach allows cost optimization without requiring complex manual configuration from users.

Inventive Principle:
Principle #15Dynamics

3Reliability

If context-based path selection with multiple attributes is implemented, then security and cost optimization are improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a policy server as an intermediary that centralizes the complex path selection logic. Instead of distributing complexity across multiple VPN gateways or client devices, the policy server consolidates attribute collection, context evaluation, and path selection algorithms in a single location. This resolves the contradiction by improving security through sophisticated context-based selection while managing system complexity through centralized architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the path selection system into distinct functional components: attribute collection modules at VPN gateways, context evaluation logic at the policy server, and path selection algorithms that consider multiple factors including security, cost, and performance. This segmentation allows each component to specialize in specific tasks, improving overall security and optimization capabilities while managing complexity through modular design.

Inventive Principle:
Principle #1Segmentation

4Reliability

If context-based path selection with multiple attributes is implemented, then security and cost optimization are improved, but implementation difficulty increases

Engineering Contradiction:
ImprovesecurityVSAvoidimplementation difficulty
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements automatic attribute collection at VPN gateways that self-report relevant traffic characteristics to the policy server without requiring manual configuration. The system automatically gathers source IP addresses, destination ports, application types, and other context attributes, reducing implementation difficulty while maintaining sophisticated security capabilities. This self-service approach allows the system to implement complex context-based selection without burdening deployers with manual setup.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms where the policy server receives attribute information from VPN gateways, processes context-based path selection, and returns policy decisions that are implemented by the gateways. This feedback loop enables the system to adapt to changing conditions and optimize security and cost performance dynamically. The standardized feedback protocol simplifies implementation by providing a clear communication interface between components.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11818101B2Context-based path selection for VPN clients to facilitate remote access to network-based applications
Publication Date: 2023.11.14 CISCO TECHNOLOGY INC
  • US11818101B2 patent drawing
  • US11818101B2 patent drawing
  • US11818101B2 patent drawing

AI summary

A server may receive, from a virtual private network (VPN) client of a client device, a message which indicates a request for a policy rule for communications with a network-based application (e.g. provided via a data center or cloud computing services). The server may obtain source attributes of the client device and a user thereof based on source identifiers, and destination attributes of the application based on a destination identifier, and select a policy rule associated with the attributes (e.g. indicative of security, risk, cost, load, and/or business function). The server may send a message which indicates a response and includes the policy rule for application at the VPN client. The policy rule may indicate a policy action for selecting a path, of a plurality of paths, identified by a path identifier, and specify conditions such as a location and/or a date, day, and/or time of the client device.