Multi-Network Access via Concurrent Gatekeeper Sessions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current secure remote access technologies, such as IPSEC and SSL VPNs, face challenges in allowing IT administrators to access multiple geographically dispersed networks while maintaining security and efficiency, as bridging multiple networks increases security risks and requires significant overhead in logging in and out of networks.
Innovation Solution
The implementation of a system using gatekeepers that allow administrators to maintain concurrent sessions across multiple networks, providing authorized access to specific resources while preventing access to unauthorized ones, using agent-assisted port forwarding and policy-based access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If IPSEC VPN gateway is used to bridge multiple networks, then administrators can access all networks through a single gateway, but security risks increase and full WAN access is granted to users
Solution Approach 1:
The patent segments network access by creating separate virtual networks (VNETs) for different administrative domains. Each VNET is isolated with its own gateway, preventing lateral movement between networks while maintaining individual accessibility. This resolves the contradiction by allowing multiple network accesses without granting full WAN access.
Solution Approach 2:
The patent introduces a gateway as an intermediary component between the administrator's client and the remote networks. The gateway establishes separate virtual networks for each destination network, mediating all traffic through controlled interfaces. This intermediary structure enables secure multi-network access while maintaining security boundaries.
2Reliability
If serial connections are used to access multiple networks, then networks can remain disjoint and secure, but administrators spend significant time logging in and out of each network
Solution Approach 1:
The patent merges multiple separate network connections into a single consolidated interface. The gateway creates virtual networks that can be accessed simultaneously through one connection point, combining what would otherwise require multiple sequential login operations into a unified access mechanism.
Solution Approach 2:
The gateway provides universal access functionality by establishing multiple virtual networks simultaneously through a single connection. One gateway instance serves multiple networks (VNET1, VNET2, VNET3) concurrently, eliminating the need for separate serial connection sessions for each network.
3Ease of operation
If multiple networks are bridged together, then administrators can see all networks through a single gateway, but networks that should remain segregated for regulatory reasons cannot be accessed
Solution Approach 1:
The patent implements segmentation through separate virtual networks (VNET1, VNET2, VNET3) that are logically isolated from each other. Each virtual network can be independently configured and accessed, allowing consolidated view capability while maintaining regulatory segmentation requirements.
Solution Approach 2:
The patent applies local quality by providing customized network views to different administrators based on their authorization. Each administrator receives access to specific virtual networks appropriate to their role, with the gateway presenting a consolidated view only for networks they are authorized to access.
Data Source
AI summary
Communicating with a plurality of networks is disclosed. One or more credentials is provided to a first gatekeeper of a first network. One or more credentials is provided to a second gatekeeper of a second network. A session is maintained with the first gatekeeper. A second session is simultaneously maintained with the second gatekeeper.


