Dynamic VPN Setup via Cloud Intermediary and Whitelist
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current virtual private network (VPN) technologies are cumbersome and costly to set up, requiring complex network settings and professional procedures, which can lead to security loopholes and inefficiencies, especially when dealing with multiple terminal devices.
Innovation Solution
A dynamic VPN system with a main device and sub-device that uses a whitelist setting mode and third-party cloud network service for simplified and secure connection establishment, eliminating the need for Internet gateway settings and reducing operational costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If complex network communication parameter settings are performed for VPN server setup, then connection capability is achieved, but setup complexity and time consumption increase significantly
Solution Approach 1:
The system performs automatic network parameter detection and configuration without requiring manual user input. The terminal device automatically obtains network parameters from the current network environment and configures the VPN connection parameters, eliminating the need for users to manually set complex network communication parameters.
Solution Approach 2:
The system pre-configures VPN connection parameters by detecting network environment information before the actual VPN connection is established. The terminal device obtains network parameters in advance from the current network, performs preliminary configuration, and then uses these pre-configured parameters to establish the VPN connection, significantly reducing setup time.
2Adaptability or versatility
If VPN server is opened on Internet to enable remote access, then connectivity is improved, but security risks increase due to potential security loopholes
Solution Approach 1:
The system introduces a third-party cloud service as an intermediary to facilitate device discovery and connection establishment. Instead of opening the VPN server directly to the Internet, the terminal device communicates through the cloud service platform, which acts as a secure mediator for authentication and connection setup, reducing direct exposure to Internet security threats.
3Ease of operation
If network proxy server is created to simplify VPN connection settings, then ease of operation improves, but operational costs increase significantly
Solution Approach 1:
The system enables terminal devices to autonomously obtain network parameters and configure VPN connections without requiring a centralized network proxy server. Each device independently detects its network environment, obtains parameters, and configures connections, eliminating the need for expensive proxy server infrastructure and reducing operational costs.
Solution Approach 2:
The system uses a third-party cloud service as a lightweight intermediary for device discovery and parameter exchange, replacing the need for expensive self-hosted network proxy servers. The cloud service provides the necessary coordination functionality at lower operational cost, enabling simplified connection setup without maintaining expensive infrastructure.
Data Source
AI summary
The invention provides a method for a dynamical virtual a private network, which is suitable for a main device in a dynamic virtual private network. The method comprises: (a) before the main device establishes a tunneling connection, acquiring a request for adding a sub-device to a whitelist directly or through a third-party cloud service and sending an acceptance message or a rejection message to the sub-device accordingly thereto; (b) acquiring a request for connecting with the sub-device directly or through the third-party cloud service, and determining whether the tunneling connection with the sub-device is established or not accordingly thereto or sending a rejection message to the sub-device; (c) after the tunneling connection is established between the main device and the sub-device, receiving a connection code sent from the sub-device through the tunneling connection, and determining whether the connection code sent from the sub-device is correct or not.


