MPLS L3VPN Segmentation for User Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

MPLS technology, widely used in enterprise networks for secure data transport, faces challenges in isolating high-risk users while providing access to network resources, as it lacks effective measures for segregating users and ensuring cybersecurity.

Innovation Solution

Implementing an MPLS Layer-3 virtual private network (L3VPN) with a remote and mobile enterprise access (RMEA) gateway, client-based SSL-VPN capability, and a two-factor authentication system, along with a de-militarized zone (DMZ) to securely isolate and authenticate users, ensuring secure access to the enterprise network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MPLS technology is used for secure data transport, then data transport security is improved, but user isolation capability deteriorates

Engineering Contradiction:
Improvedata transport securityVSAvoiduser isolation capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the network into multiple L3VPN instances, each providing isolated virtual networks for different user groups. This segmentation allows high-risk users to be separated into dedicated VPN instances while maintaining secure MPLS transport, thus resolving the contradiction between transport security and user isolation capability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an SSL-VPN gateway as an intermediary component that sits between users and the MPLS network. This gateway provides additional authentication layers and access control, enabling fine-grained user isolation while preserving the security benefits of MPLS transport

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If network access is provided to users, then network resource accessibility is improved, but security risk increases

Engineering Contradiction:
Improvenetwork resource accessibilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication actions through SSL-VPN gateway authentication and two-factor authentication before users can access the MPLS network. This preliminary security verification ensures that only authenticated users gain access, maintaining resource accessibility while mitigating security risks

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent nests multiple security layers within the network architecture: SSL-VPN authentication nested within L3VPN instances, which are nested within the MPLS network. This nested structure provides progressive security validation while maintaining ease of access for authorized users

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS11888869B2System and method for securing network users in an enterprise network through cybersecurity controls
Publication Date: 2024.01.30 SAUDI ARABIAN OIL CO
  • US11888869B2 patent drawing
  • US11888869B2 patent drawing
  • US11888869B2 patent drawing

AI summary

A system, a method, and a computer program are provided for securely isolating access by one or more users in a group of network users to an enterprise network implementing Multi-Protocol Label Switching (MPLS). The security system includes an MPLS Layer-3 VPN (L3VPN) instance created for a group of users to be isolated, and a remote and mobile enterprise access (RMEA) gateway with secure socket layer virtual private network (SSL-VPN) and two-factor user authentication capabilities. A de-militarized zone (DMZ) is positioned in the network to security scan data traffic between the L3VPN and RMEA gateway. The security protocol involves two-factor user authentication and establishing, on top of the L3VPN instance, an SSL-VPN session between the user and the RMEA gateway, which provides the authorized user access to the network. Additionally, data traffic to/from the user is routed through the RMEA and the DMZ.