Gateway Intermediary for Dynamic IP VPN Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional VPN solutions face limitations in providing secure remote access to enterprise networks over public data communication networks like the Internet, particularly due to administrative complexities, firewall restrictions, and inability to handle dynamically assigned IP addresses or changing ports, which restrict access to essential resources.
Innovation Solution
A system and method that establishes a VPN by creating an encrypted data communication session between a client and a private network using a gateway, where a program is dynamically installed on the client to intercept and redirect communications, allowing access to resources with dynamic IP addresses and ports, and providing additional processing capabilities like load balancing and encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If pre-installed thick client software (IPSec or SSL) is used for VPN access, then network security and encryption are improved, but device complexity and administrative burden increase due to software installation and management requirements
Solution Approach 1:
The patent introduces a gateway device as an intermediary between the client and the private network. The gateway handles all VPN functions including encryption, decryption, and network address translation, eliminating the need for complex client software installation and management on user devices while maintaining security through centralized control
Solution Approach 2:
The system enables self-service VPN access by allowing clients to connect using standard web browsers without requiring administrative installation of specialized software. The gateway automatically manages authentication, encryption, and network routing, reducing administrative burden while maintaining security protocols
2Reliability
If thick client software is pre-installed for VPN access, then encrypted communication is achieved, but ease of operation deteriorates because users cannot access resources from alternate endpoints without installing software
Solution Approach 1:
The gateway device provides universal access by handling multiple functions including SSL termination, network address translation, and encryption/decryption in a single centralized location. This allows any client with a standard web browser to access the private network without installing specialized software, while the gateway maintains encrypted communication channels
Solution Approach 2:
The gateway acts as a mediator that enables clients to access resources from any endpoint without pre-installed software. It translates and routes traffic between the public network and private network resources, maintaining security while providing universal access capability
3Ease of operation
If dynamic port proxy approach is used, then firewall traversal capability is improved, but adaptability deteriorates because it only works with named addresses and cannot handle dynamic IP addresses or changing ports
Solution Approach 1:
The gateway serves as an intermediary that performs network address translation and port mapping functions. It maintains translation tables that map private network addresses and ports to public network addresses and ports, enabling the system to handle dynamic IP addresses and changing ports while traversing firewalls effectively
Solution Approach 2:
The system implements dynamic port proxy capabilities where the gateway can dynamically allocate and map ports based on client requests and network conditions. The translation tables are updated in real-time to reflect changing IP addresses and port assignments, providing both firewall traversal and adaptability to dynamic network configurations
4Reliability
If SSL encryption is used for remote access, then network security is improved, but adaptability deteriorates because SSL clients cannot directly access Domain Name Servers, WINS Servers, or other essential private network resources
Solution Approach 1:
The gateway acts as an intermediary that terminates SSL connections from clients and then establishes separate connections to private network resources including Domain Name Servers and WINS Servers. This allows SSL-encrypted clients to access essential network resources that would otherwise be inaccessible, while maintaining security through the gateway's mediation
Solution Approach 2:
The system segments the connection path by separating the SSL encryption layer from the network resource access layer. The gateway handles SSL termination and then manages separate connections to various private network resources, allowing clients to access essential services like DNS and WINS while maintaining encrypted communication channels
Data Source
AI summary
A system and method for establishing a virtual private network (VPN) between a client and a private data communication network. An encrypted data communication session, such as a Secure Sockets Layer (SSL) data communication session, is established between a gateway and the client over a public data communication network. The gateway then sends a programming component to the client for automatic installation and execution thereon. The programming component operates to intercept communications from client applications destined for resources on the private data communication network and to send the intercepted communications to the gateway via the encrypted data communication session instead of to the resources on the private data communication network.


