IPv6 Tunneling Client for Secure Private Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Accessing private networks from outside while maintaining security and avoiding exposure to vulnerabilities, particularly when split tunneling configurations are used, is challenging due to the need for secure and authenticated connections.

Innovation Solution

An IPv6 tunneling client connects to an IPv6 tunneling router at the edge of the private network, establishing a secure and authenticated connection using encryption technologies like IPsec, allowing access to hosts within the private network while enabling access to the broader Internet, even over IPv4 connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If split tunneling is used to allow clients to connect to both private network and Internet simultaneously, then network usability and accessibility are improved, but security vulnerabilities increase and the private network becomes exposed to external threats

Engineering Contradiction:
Improvenetwork usabilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments network traffic into two distinct paths: IPv6 traffic for private network access through the tunnel, and IPv4 traffic for general Internet access. This segmentation allows split tunneling functionality while maintaining security by keeping private network traffic isolated in its own protocol space with dedicated routing rules.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The IPv6 tunnel acts as an intermediary mechanism between the client and the private network. By introducing this tunneling layer, the system enables secure private network access without directly exposing the network to external IPv4 connections, thus maintaining security while achieving versatility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If VPN connections are configured for split tunneling to enable Internet access without going through the VPN, then client flexibility and Internet accessibility are improved, but the private network gateway becomes exposed to security risks

Engineering Contradiction:
Improveclient flexibilityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies different security qualities to different protocol layers: IPv6 traffic receives full tunneling security protection when accessing private networks, while IPv4 traffic uses standard Internet routing. This local quality differentiation allows client flexibility for Internet access while maintaining strong security for private network communications.

Inventive Principle:
Principle #3Local quality

3Reliability

If a gateway and firewall are implemented to protect the private network from general Internet users, then network security is improved, but access difficulty for external users increases

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess difficulty
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The IPv6 tunnel serves as an intermediary that bypasses the need for direct gateway exposure. External users can access the private network through this tunneling mechanism without requiring the gateway to be directly accessible from the Internet, thus maintaining security while enabling access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8875237B2Private network access using IPv6 tunneling
Publication Date: 2014.10.28 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8875237B2 patent drawing
  • US8875237B2 patent drawing
  • US8875237B2 patent drawing

AI summary

A connection to a private network may use an IPv6 tunneling client to connect to a corresponding IPv6 tunneling router at the edge of the private network. The client may be configured to automatically establish a tunneling connection and may have a routing table for routing IPv6 addresses for hosts within the private network through the tunneling connection. The client may be connected to an IPv4 or IPv6 connection outside the private network. The connection between the IPv6 tunneling client and IPv6 tunneling router may be an authenticated and secure connection.