Dynamic VPN Dual-Proxy Routing for Network Topology Hiding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional VPN solutions expose the internal network topologies of end nodes, compromising security and privacy by requiring manual configuration and direct communication using local IP addresses.

Innovation Solution

The Dynamic VPN (DVPN) dual-proxy method enables application-level content routing by providing a secure tunnel between VPN nodes without disclosing actual IP addresses, using DVPN proxy servers to route requests and responses as if they were local, maintaining network opacity and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional VPN solutions are used to connect remote sites, then secure communication can be established, but the internal network topologies of end nodes are exposed

Engineering Contradiction:
Improvesecure communicationVSAvoidnetwork topology exposure
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a central VPN gateway as an intermediary between client nodes and resource nodes. This gateway acts as a mediator that knows the topology of both networks but keeps this information hidden from the end nodes themselves. The gateway performs translation and routing functions while maintaining network opacity, thus enabling secure communication without exposing internal topologies to the nodes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the VPN architecture into distinct functional components: client nodes, resource nodes, and a central VPN gateway. This segmentation separates the topology knowledge (held by the gateway) from the end nodes, allowing secure communication to be established while preventing topology exposure at the node level. The gateway handles all topology-related operations independently.

Inventive Principle:
Principle #1Segmentation

2Reliability

If manual configuration is required for VPN connectivity, then secure tunnels can be established, but operational complexity and costs increase

Engineering Contradiction:
Improvesecure tunnel establishmentVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service capabilities where client nodes automatically discover and connect to resource nodes through the VPN gateway without manual configuration. The gateway maintains automatic translation tables and routing information, allowing nodes to communicate autonomously. This eliminates the need for manual topology configuration at node levels while maintaining secure tunnel establishment.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces dynamic translation tables at the VPN gateway that automatically adapt to changing network conditions. Rather than static manual configurations, the system dynamically updates routing information and translation mappings based on real-time connectivity status, reducing operational complexity while maintaining reliable secure connections.

Inventive Principle:
Principle #15Dynamics

3Productivity

If direct IP address communication is used between nodes, then routing is simple, but network security and privacy are compromised

Engineering Contradiction:
Improverouting simplicityVSAvoidsecurity and privacy risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The VPN gateway serves as an intermediary that translates between private IP addresses used by nodes and public routing addresses used on the network. This translation mechanism maintains routing simplicity at the node level (nodes only need their private IPs) while implementing security and privacy through the gateway's controlled translation and routing functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates virtual copies of network addresses through the translation mechanism. Private IP addresses are mapped to virtual representations that the gateway manages, allowing nodes to communicate using simplified local addresses while the gateway handles the complex address translation and security functions, thus maintaining simplicity without compromising security.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS7852861B2Dynamic system and method for virtual private network (VPN) application level content routing using dual-proxy method
Publication Date: 2010.12.14 ARRAY NETWORKS
  • US7852861B2 patent drawing
  • US7852861B2 patent drawing
  • US7852861B2 patent drawing

AI summary

A method of application level content routing using a (Dynamic VPN) dual-proxy mechanism that provides a client access to resources on a remote network without exposing each other's actual IP addresses and network topologies. The method includes providing a client a list of available resources on a remote network; initiating a request by the client for at least one resource from the list of available resources hosted on the remote network as though the at least one resource is local to the client; routing the request to the at least remote resource through a secure connection between the client and the remote network; responding to the request by the at least remote resource as though the request is initiated locally on the remote network; and routing the response from the remote network back to the client through the secure connection.