Dynamic VPN Routing with Seamless Path Switching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing VPN technologies have static ingress and egress points, making them detectable and requiring significant network overhead and time to change, leading to inconsistent latencies and lack of user control over routing paths, which compromises security and anonymity.
Innovation Solution
Implementing a dynamic VPN routing system using a virtualization platform that allows users to define their own network paths across multiple clouds, with a decision engine and controller to instantiate and reconfigure virtual switches and nodes, enabling seamless path changes and end-to-end encryption without disrupting communications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a traditional VPN with static ingress and egress points is used, then the VPN connection is stable and easy to establish, but the VPN link is easily detectable and requires significant time and network overhead to change the egress point
Solution Approach 1:
The patent implements dynamic VPN routing that allows the egress point to be changed without tearing down the existing VPN connection. The system can dynamically select different egress points from multiple available options while maintaining the VPN tunnel, enabling adaptability without the time penalty of reestablishing connections.
Solution Approach 2:
The patent segments the VPN routing into multiple independent paths with different egress points. By pre-establishing multiple VPN connections to different egress points and using a routing decision engine to select among them, the system can switch paths without disrupting the overall VPN connection, resolving the contradiction between adaptability and time loss.
2Ease of operation
If a traditional VPN with static routing is used, then the VPN connection is simple to manage, but the latency is inconsistent and users have no control over the routing path
Solution Approach 1:
The patent introduces a routing decision engine as an intermediary component that manages the complexity of dynamic routing. This engine receives routing policies from users or administrators and automatically makes routing decisions, selecting optimal paths based on current network conditions while users retain control through policy configuration without needing to manage the underlying complexity.
Solution Approach 2:
The patent implements feedback mechanisms where the routing decision engine continuously monitors network conditions such as latency and path availability, then adjusts routing decisions in real-time. This feedback loop enables consistent latency performance and user control over routing paths while the system automatically manages the complexity of multiple routing options.
3Adaptability or versatility
If a VPN traverses multiple physical servers and switches in a cloud, then the VPN can provide flexible routing options, but intermediate hops are outside the control of the VPN provider and users
Solution Approach 1:
The patent applies preliminary action by pre-establishing multiple VPN connections to different egress points before needing to switch paths. The routing decision engine is also pre-configured with routing policies and path information, enabling it to make reliable routing decisions without needing to dynamically discover or control intermediate hops during active connections.
Data Source
AI summary
Some embodiments described herein relate managing communications between an origin and a destination using end-user and/or administrator configurable virtual private network(s) (VPN(s)). A first VPN that defines a first data path between an origin and a destination can be defined at a first time. A second VPN that defines a second, different data path between the origin and the destination can defined at a second time. Each packet sent across the first VPN and each packet sent across the second VPN can follow the same data path for that VPN, such each packet can be sent across the first VPN or the second VPN in the order it was received, and the transition between the first VPN and the second VPN can be “seamless,” and communications between the origin and the destination are not disrupted between the first time period and the second time period.


