Gateway Intermediary for Dynamic IP VPN Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional VPN solutions face limitations in providing secure remote access to enterprise networks over public data communication networks like the Internet, particularly due to administrative complexities, firewall restrictions, and inability to handle dynamically assigned IP addresses or changing ports, which restrict access to essential resources.

Innovation Solution

A system and method that establishes a VPN by creating an encrypted data communication session between a client and a private network using a gateway, where a program is dynamically installed on the client to intercept and redirect communications, allowing access to resources with dynamic IP addresses and ports, and providing additional processing capabilities like load balancing and encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If pre-installed thick client software (IPSec or SSL) is used for VPN access, then network security and encryption are improved, but device complexity and administrative burden increase due to software installation and management requirements

Engineering Contradiction:
Improvenetwork securityVSAvoidsoftware installation and management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway device as an intermediary between the client and the private network. The gateway handles all VPN functions including encryption, decryption, and network address translation, eliminating the need for complex client software installation and management on user devices while maintaining security through centralized control

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service VPN access by allowing clients to connect using standard web browsers without requiring administrative installation of specialized software. The gateway automatically manages authentication, encryption, and network routing, reducing administrative burden while maintaining security protocols

Inventive Principle:
Principle #25Self-service

2Reliability

If thick client software is pre-installed for VPN access, then encrypted communication is achieved, but ease of operation deteriorates because users cannot access resources from alternate endpoints without installing software

Engineering Contradiction:
Improveencrypted communicationVSAvoidaccess from any client computer
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The gateway device provides universal access by handling multiple functions including SSL termination, network address translation, and encryption/decryption in a single centralized location. This allows any client with a standard web browser to access the private network without installing specialized software, while the gateway maintains encrypted communication channels

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The gateway acts as a mediator that enables clients to access resources from any endpoint without pre-installed software. It translates and routes traffic between the public network and private network resources, maintaining security while providing universal access capability

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If dynamic port proxy approach is used, then firewall traversal capability is improved, but adaptability deteriorates because it only works with named addresses and cannot handle dynamic IP addresses or changing ports

Engineering Contradiction:
Improvefirewall traversal capabilityVSAvoidhandling dynamic IP addresses and ports
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The gateway serves as an intermediary that performs network address translation and port mapping functions. It maintains translation tables that map private network addresses and ports to public network addresses and ports, enabling the system to handle dynamic IP addresses and changing ports while traversing firewalls effectively

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements dynamic port proxy capabilities where the gateway can dynamically allocate and map ports based on client requests and network conditions. The translation tables are updated in real-time to reflect changing IP addresses and port assignments, providing both firewall traversal and adaptability to dynamic network configurations

Inventive Principle:
Principle #15Dynamics

4Reliability

If SSL encryption is used for remote access, then network security is improved, but adaptability deteriorates because SSL clients cannot directly access Domain Name Servers, WINS Servers, or other essential private network resources

Engineering Contradiction:
ImproveSSL encryption securityVSAvoidaccess to essential private network resources
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The gateway acts as an intermediary that terminates SSL connections from clients and then establishes separate connections to private network resources including Domain Name Servers and WINS Servers. This allows SSL-encrypted clients to access essential network resources that would otherwise be inaccessible, while maintaining security through the gateway's mediation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the connection path by separating the SSL encryption layer from the network resource access layer. The gateway handles SSL termination and then manages separate connections to various private network resources, allowing clients to access essential services like DNS and WINS while maintaining encrypted communication channels

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7757074B2System and method for establishing a virtual private network
Publication Date: 2010.07.13 CITRIX SYSTEMS INC
  • US7757074B2 patent drawing
  • US7757074B2 patent drawing
  • US7757074B2 patent drawing

AI summary

A system and method for establishing a virtual private network (VPN) between a client and a private data communication network. An encrypted data communication session, such as a Secure Sockets Layer (SSL) data communication session, is established between a gateway and the client over a public data communication network. The gateway then sends a programming component to the client for automatic installation and execution thereon. The programming component operates to intercept communications from client applications destined for resources on the private data communication network and to send the intercepted communications to the gateway via the encrypted data communication session instead of to the resources on the private data communication network.