Dynamic VPN Bypassing Central Network for Direct Connectivity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional site-to-site VPN environments face resource constraints and additional failure points due to the need for VPN devices at remote and private networks to establish connections through a central network, which can lead to bandwidth issues and increased complexity.
Innovation Solution
Implementing a dynamic VPN environment where remote networks establish direct connections with private networks by exchanging and storing VPN information, allowing them to bypass the central network and maintain secure, encrypted tunnels using locally stored VPN information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If VPN connections are established through a central network, then centralized control and management are achieved, but resource constraints and additional failure points occur
Solution Approach 1:
The patent extracts the central network from the VPN connection path by enabling direct peer-to-peer connections between remote and private networks. The system obtains VPN information from the central network temporarily, then establishes direct connections that bypass the central network, thereby removing it as a failure point while maintaining centralized control for initial connection setup.
Solution Approach 2:
The patent segments the VPN connection establishment process into two phases: initial setup through the central network to obtain configuration information, and subsequent direct connection between remote and private networks. This segmentation allows centralized management during setup while enabling direct connections for data transmission, reducing overall network complexity.
2Productivity
If direct VPN connections are established between remote and private networks, then resource constraints and failure points are reduced, but centralized control is diminished
Solution Approach 1:
The patent applies preliminary action by having the system obtain VPN information from the central network before establishing direct connections. The central network performs preliminary configuration and authentication, providing necessary connection parameters. This preliminary centralized control enables subsequent direct connections to be established efficiently without ongoing central network involvement in data transmission.
3Productivity
If VPN information is exchanged and stored locally, then direct connections can be established, but security risks from information leakage increase
Solution Approach 1:
The patent changes the state of VPN information from constantly accessible to conditionally accessible. The system stores VPN information locally but implements access controls that determine when and how the information can be used. Connection parameters are dynamically adjusted based on authentication results and security policies, allowing direct connections while maintaining security through controlled parameter access rather than unrestricted information availability.
Data Source
AI summary
Various embodiments establish a virtual private network (VPN) between a remote network and a private network. In one embodiment, a first system in the remote network establishes a connection with a central system through a public network. The central system is situated between the first system and a second system in the private network. The first system receives, from the central system and based on establishing the connection, a set of VPN information associated with at least the second system. The first system disconnects from the central system and establishes a VPN directly with the second system through the public network based on the set of VPN information.


