Hierarchical-Context Area Network for Dynamic VPN Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtual private network (VPN) systems are inefficient, inflexible, and resource-intensive, with limited control over data transport pathways, leading to sub-optimal performance and high resource utilization.

Innovation Solution

Implementing a hierarchical-context area network as a virtual private network infrastructure system, which includes a hierarchy of context levels with shared IP addresses, enabling automatic egress randomization and equal-cost multi-path routing to optimize data transport pathways.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If traditional VPN systems are used with fixed routing paths, then system simplicity is maintained, but communication speed and resource utilization are sub-optimal

Engineering Contradiction:
Improvecommunication speedVSAvoidsystem complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent implements dynamic routing where the VPN infrastructure automatically selects and switches between multiple data transport pathways based on real-time network conditions. The system transitions from static fixed routing to dynamic adaptive routing, allowing data to flow through optimal paths that change according to current network state, thereby improving communication speed without requiring complex manual configuration

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The hierarchical-context area network implements self-service through automatic egress randomization and equal-cost multi-path routing protocols that autonomously select optimal transport pathways without human intervention. The system automatically monitors network conditions and reroutes data flows through the most efficient available paths, eliminating the need for manual route optimization while achieving superior performance

Inventive Principle:
Principle #25Self-service

2Productivity

If multiple data transport pathways are implemented with automatic egress randomization, then resource utilization is reduced and throughput is improved, but system complexity increases

Engineering Contradiction:
Improveend-to-end throughputVSAvoidrouting system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the VPN infrastructure into a hierarchical structure with multiple context levels (first VPNI context level, second VPNI context level, etc.), where each level contains multiple context areas with dedicated VPN servers. This segmentation allows independent optimization of each segment while maintaining overall system coordination, enabling high throughput through parallel processing across segments without overwhelming complexity at any single level

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components including the hierarchical-context area network structure and equal-cost multi-path routing protocols that mediate between multiple data transport pathways. These intermediaries automatically manage route selection and load distribution across the segmented infrastructure, coordinating complex multi-path routing operations while presenting a simplified interface to end users

Inventive Principle:
Principle #24Intermediary (Mediator)

3Quantity of substance

If shared IP addresses are allocated across multiple VPN servers in different context levels, then resource efficiency is improved, but routing control complexity increases

Engineering Contradiction:
ImproveIP address quantityVSAvoidrouting control complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent implements shared IP addresses that serve multiple functions across different VPN servers and context levels. A single IP address can be allocated to multiple VPN servers within the hierarchical structure, allowing the same address to be used for different data transport pathways and routing contexts. This multi-functionality maximizes IP address utilization while the hierarchical routing protocols automatically manage the complexity of address resolution and route selection

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12218822B2Hierarchical-context area network as a virtual private network infrastructure system
Publication Date: 2025.02.04 NETFLOW UAB
  • US12218822B2 patent drawing
  • US12218822B2 patent drawing
  • US12218822B2 patent drawing

AI summary

Operating a hierarchical-context area network includes receiving a first protocol data unit from an end user device via a virtual private network tunnel by a first virtual private network server, obtaining the first protocol data unit from the first virtual private network server, by a second virtual private network server as a current point of egress for transporting the first protocol data unit through the hierarchical-context area network, identifying, by the second virtual private network server, available data transport pathways for transporting the first protocol data unit through the hierarchical-context area network, pseudo-randomly identifying, by the second virtual private network server, an available data transport pathway from the available data transport pathways as a current data transport pathway, and sending, by the second VPN server, to the external device, via the data transport pathway, the first protocol data unit.