Mesh Network Relay for Mobile VPN Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face challenges in accessing enterprise resources from multiple devices, especially when one device cannot establish a virtual private network connection, due to differing network capabilities, which complicates secure access and usage.

Innovation Solution

Implementing a method where devices form a mesh network using peer-to-peer connections, with one device establishing a virtual private network connection to an access gateway, allowing other devices to relay data through this connection, ensuring secure and seamless access to enterprise resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a device establishes a direct virtual private network connection to access enterprise resources, then secure access is achieved, but devices with incompatible network capabilities (e.g., tablet without cellular modem) cannot connect

Engineering Contradiction:
Improvedevice compatibilityVSAvoidnetwork architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a peer device as an intermediary that already has a VPN connection to the enterprise network. This intermediary device acts as a relay, allowing other devices (like tablets without cellular capability) to access enterprise resources indirectly through the peer's established connection, thereby resolving the compatibility issue without requiring each device to establish its own direct VPN connection

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds a new dimension to the network architecture by introducing peer-to-peer mesh networking capabilities. Instead of relying solely on direct device-to-gateway connections, the system creates indirect communication paths through intermediate peer devices, enabling access for devices that would otherwise be unable to connect directly

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of operation

If multiple devices connect directly to the enterprise network independently, then each device has direct access, but security risks increase and network management becomes complex

Engineering Contradiction:
Improveaccess convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent uses the enterprise network gateway as an intermediary that all peer devices must authenticate with and register. This centralized authentication mechanism maintains security by ensuring that even indirect access through peer-to-peer connections is controlled and monitored by the enterprise's security infrastructure, preventing unauthorized access while maintaining convenient access for authorized devices

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a device without cellular capability tries to access enterprise resources over cellular network, then direct connection fails, but mesh networking through peer devices enables access

Engineering Contradiction:
Improveconnection reliabilityVSAvoidcommunication protocol
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal mesh networking protocol that works across different device types and network configurations. The same peer-to-peer communication mechanism enables both direct peer connections and indirect relay connections, providing a unified solution that adapts to various device capabilities (or lack thereof) without requiring device-specific implementation variations

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3593510B1Virtual private networking based on peer-to-peer communication
Publication Date: 2021.05.12 CITRIX SYSTEMS INC
  • EP3593510B1 patent drawingFigure 1
  • EP3593510B1 patent drawingFigure 2
  • EP3593510B1 patent drawingFigure 3

AI summary

Methods and systems for enabling multiple mobile devices to access an access gateway when at least one of the multiple mobile devices is unable to establish a virtual private network connection with the access gateway are described herein. For example, in some embodiments, a mobile device may configure itself as a member of a mesh network. A virtual private network connection may be established between the mobile device and the access gateway. The mesh network may include one or more other member devices that are unable to establish a virtual private network with the access gateway. After completing its configuration, the mobile device may receive, over a peer-to-peer connection of the mesh network, data that is intended for the access gateway and that is from one of the other member devices. The mobile device may transmit the data to the access gateway via the virtual private network connection.