Dynamic IPsec VPN Tunnel Setup for Wireless Mesh Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Establishing an IPsec VPN tunnel in a wireless mesh network is complex for users, as they need to identify router interfaces and IP addresses, especially when dealing with non-IP traffic or specific VLANs, requiring knowledge of router internals and available network interfaces.

Innovation Solution

A method and system for a wireless mesh network access node to dynamically determine and select internal interfaces based on traffic type, either physical or logical, and establish an IPsec VPN tunnel using a user configuration, encapsulating non-IP packets within IP packets, and determining local endpoint addresses to facilitate secure and efficient tunnel setup.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration of IPsec VPN tunnel is implemented, then security and encryption are ensured, but user complexity and difficulty of operation increase

Engineering Contradiction:
ImprovesecurityVSAvoiduser complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs self-configuration by automatically detecting available interfaces, selecting appropriate internal interfaces based on traffic type, and determining local endpoint addresses without requiring user intervention. The access node autonomously completes the IPsec tunnel setup process while maintaining security requirements.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-configures interface selection criteria and endpoint address determination logic before the actual tunnel establishment. By preparing the interface selection framework in advance and automatically matching traffic types to appropriate interfaces, the system eliminates the need for users to perform complex manual configuration steps.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If automatic interface selection is implemented, then ease of operation improves, but device complexity increases

Engineering Contradiction:
ImproveautomationVSAvoidcontrol logic
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The automatic interface selection process is divided into distinct segments: traffic type identification, interface type determination (physical or logical), and endpoint address selection. Each segment handles a specific aspect of the configuration, making the overall complex process manageable through modular organization of control logic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary layer that sits between the user configuration input and the actual tunnel establishment. This intermediary automatically interprets traffic types, selects appropriate interfaces, and determines endpoint addresses, thereby shielding users from complexity while managing the necessary control logic within the system.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If support for non-IP traffic is added, then adaptability improves, but interface selection complexity increases

Engineering Contradiction:
Improvetraffic type supportVSAvoidinterface management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements a universal interface selection mechanism that handles multiple traffic types (IP and non-IP) through a single unified process. The same control logic automatically adapts to different traffic types by identifying them and selecting appropriate interfaces, eliminating the need for separate configuration procedures for each traffic type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The interface selection process is made dynamic by automatically adapting to the type of traffic being configured. The system dynamically determines whether to select a physical or logical interface based on the traffic type, and dynamically selects appropriate endpoint addresses, allowing the configuration process to flexibly respond to different scenarios without requiring static pre-configuration for each case.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9088546B2Establishing an IPSEC (internet protocol security) VPN (virtual private network) tunnel and encapsulating non-IP packets
Publication Date: 2015.07.21 HITACHI ENERGY LTD
  • US9088546B2 patent drawing
  • US9088546B2 patent drawing
  • US9088546B2 patent drawing

AI summary

Systems, methods and apparatuses of establishing an IPsec (Internet Protocol Security) VPN (Virtual Private Network) tunnel are disclosed. One method includes receiving, by a wireless mesh network access point, a user configuration, wherein the user configuration includes a type of traffic, determining an internal interface of the wireless mesh network access node based on the type of traffic, dynamically determining a local endpoint address for the IPsec VPN tunnel based on the selected internal interface, establishing the IPsec VPN tunnel through the selected internal interface of the wireless mesh network access node, and encapsulating non-IP packets of non-IP traffic within IP packets.