Dynamic VPN Tunnel Management in Hybrid Clouds

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In hybrid cloud environments, traditional VPNs create large communication channels that are not granularly tuned to application requirements, leading to security risks and inefficiencies, as they often require wide communication channels for small data transmissions and lack flexibility to adapt to changing demands.

Innovation Solution

A method and system for dynamically creating, modifying, and managing VPN tunnels based on application requirements and topology, using a VPN Manager to optimize VPN infrastructure by merging or splitting tunnels in response to changing demands, ensuring only necessary traffic is allowed between cloud environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a dedicated VPN tunnel is established between two cloud environments, then secure communication is provided, but the communication channel becomes too broad and not granularly tuned to application requirements

Engineering Contradiction:
Improvesecure communicationVSAvoidgranularity of communication channel
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments a single broad VPN tunnel into multiple application-specific virtual tunnels, each tuned to specific application requirements. The system creates separate communication channels for different applications (e.g., web traffic, database traffic, file transfer) within the same physical VPN infrastructure, allowing granular control over security policies, bandwidth allocation, and traffic filtering for each application while maintaining secure communication.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If a wide communication channel is established for VPN, then various traffic types can be accommodated, but security risks increase and efficiency decreases

Engineering Contradiction:
Improvetraffic accommodation capabilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by assigning different security characteristics to different segments of the VPN infrastructure. Each application-specific virtual tunnel within the VPN can have customized security policies, encryption levels, and access controls tailored to its specific requirements. For example, database traffic may use stronger encryption and stricter access controls compared to web traffic, optimizing security for each local context rather than applying a uniform security model.

Inventive Principle:
Principle #3Local quality

3Reliability

If traditional VPN tunnels are used, then secure communication is established, but they lack flexibility to adapt to changing application demands

Engineering Contradiction:
Improvesecure communicationVSAvoidadaptability to changing demands
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The patent implements dynamics by making the VPN tunnel configuration adaptable and changeable over time. The system allows runtime modification of virtual tunnel parameters including bandwidth allocation, security policies, and active/inactive states based on changing application demands. New applications can dynamically request and receive dedicated virtual tunnels, and existing tunnels can be adjusted or terminated as application requirements evolve, providing continuous adaptability while maintaining secure communication.

Inventive Principle:
Principle #15Dynamics

4Adaptability or versatility

If multiple separate VPN tunnels are created for different applications, then granular control is achieved, but device complexity increases

Engineering Contradiction:
Improvegranular controlVSAvoidVPN infrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a multi-functional VPN management system that handles multiple applications, tunnel types, and configuration scenarios through a single unified platform. The system provides a common interface and control mechanism for creating, managing, and monitoring all application-specific virtual tunnels, rather than requiring separate management systems for each tunnel. This universal approach reduces operational complexity while maintaining granular control over each individual tunnel.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9571457B1Dynamically defined virtual private network tunnels in hybrid cloud environments
Publication Date: 2017.02.14 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9571457B1 patent drawing
  • US9571457B1 patent drawing
  • US9571457B1 patent drawing

AI summary

A plurality of virtual private network (VPN) tunnels between a first cloud and a second cloud in a hybrid cloud environment are managed by a VPN Manager. A request including a first set of requirements is received from a first cloud application resident in the first cloud for a first VPN tunnel. The request is sent to a system in a first cloud, wherein the first system creates the first VPN tunnel according to the first set of requirements. The VPN Manager receives an event pertaining to the first VPN tunnel. In response to the event, the VPN Manager sends a modification request to the first system containing a second set of requirements. The first system tunes the first VPN tunnel according to a second set of requirements.