Dynamic VPN Bypassing Central Network for Direct Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional site-to-site VPN environments face resource constraints and additional failure points due to the need for VPN devices at remote and private networks to establish connections through a central network, which can lead to bandwidth issues and increased complexity.

Innovation Solution

Implementing a dynamic VPN environment where remote networks establish direct connections with private networks by exchanging and storing VPN information, allowing them to bypass the central network and maintain secure, encrypted tunnels using locally stored VPN information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VPN connections are established through a central network, then centralized control and management are achieved, but resource constraints and additional failure points occur

Engineering Contradiction:
Improveconnection reliabilityVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the central network from the VPN connection path by enabling direct peer-to-peer connections between remote and private networks. The system obtains VPN information from the central network temporarily, then establishes direct connections that bypass the central network, thereby removing it as a failure point while maintaining centralized control for initial connection setup.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the VPN connection establishment process into two phases: initial setup through the central network to obtain configuration information, and subsequent direct connection between remote and private networks. This segmentation allows centralized management during setup while enabling direct connections for data transmission, reducing overall network complexity.

Inventive Principle:
Principle #1Segmentation

2Productivity

If direct VPN connections are established between remote and private networks, then resource constraints and failure points are reduced, but centralized control is diminished

Engineering Contradiction:
Improveconnection efficiencyVSAvoidcentralized management
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by having the system obtain VPN information from the central network before establishing direct connections. The central network performs preliminary configuration and authentication, providing necessary connection parameters. This preliminary centralized control enables subsequent direct connections to be established efficiently without ongoing central network involvement in data transmission.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If VPN information is exchanged and stored locally, then direct connections can be established, but security risks from information leakage increase

Engineering Contradiction:
Improveconnection speedVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the state of VPN information from constantly accessible to conditionally accessible. The system stores VPN information locally but implements access controls that determine when and how the information can be used. Connection parameters are dynamically adjusted based on authentication results and security policies, allowing direct connections while maintaining security through controlled parameter access rather than unrestricted information availability.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9596271B2Dynamic virtual private network
Publication Date: 2017.03.14 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9596271B2 patent drawing
  • US9596271B2 patent drawing
  • US9596271B2 patent drawing

AI summary

Various embodiments establish a virtual private network (VPN) between a remote network and a private network. In one embodiment, a first system in the remote network establishes a connection with a central system through a public network. The central system is situated between the first system and a second system in the private network. The first system receives, from the central system and based on establishing the connection, a set of VPN information associated with at least the second system. The first system disconnects from the central system and establishes a VPN directly with the second system through the public network based on the set of VPN information.