Multi-Network Access via Concurrent Gatekeeper Sessions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure remote access technologies, such as IPSEC and SSL VPNs, face challenges in allowing IT administrators to access multiple geographically dispersed networks while maintaining security and efficiency, as bridging multiple networks increases security risks and requires significant overhead in logging in and out of networks.

Innovation Solution

The implementation of a system using gatekeepers that allow administrators to maintain concurrent sessions across multiple networks, providing authorized access to specific resources while preventing access to unauthorized ones, using agent-assisted port forwarding and policy-based access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If IPSEC VPN gateway is used to bridge multiple networks, then administrators can access all networks through a single gateway, but security risks increase and full WAN access is granted to users

Engineering Contradiction:
Improveaccess to multiple networksVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments network access by creating separate virtual networks (VNETs) for different administrative domains. Each VNET is isolated with its own gateway, preventing lateral movement between networks while maintaining individual accessibility. This resolves the contradiction by allowing multiple network accesses without granting full WAN access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a gateway as an intermediary component between the administrator's client and the remote networks. The gateway establishes separate virtual networks for each destination network, mediating all traffic through controlled interfaces. This intermediary structure enables secure multi-network access while maintaining security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If serial connections are used to access multiple networks, then networks can remain disjoint and secure, but administrators spend significant time logging in and out of each network

Engineering Contradiction:
ImprovesecurityVSAvoidadministrative overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges multiple separate network connections into a single consolidated interface. The gateway creates virtual networks that can be accessed simultaneously through one connection point, combining what would otherwise require multiple sequential login operations into a unified access mechanism.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The gateway provides universal access functionality by establishing multiple virtual networks simultaneously through a single connection. One gateway instance serves multiple networks (VNET1, VNET2, VNET3) concurrently, eliminating the need for separate serial connection sessions for each network.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If multiple networks are bridged together, then administrators can see all networks through a single gateway, but networks that should remain segregated for regulatory reasons cannot be accessed

Engineering Contradiction:
Improveconsolidated network viewVSAvoidnetwork segmentation capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements segmentation through separate virtual networks (VNET1, VNET2, VNET3) that are logically isolated from each other. Each virtual network can be independently configured and accessed, allowing consolidated view capability while maintaining regulatory segmentation requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by providing customized network views to different administrators based on their authorization. Each administrator receives access to specific virtual networks appropriate to their role, with the gateway presenting a consolidated view only for networks they are authorized to access.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8831011B1Point to multi-point connections
Publication Date: 2014.09.09 CA TECH INC
  • US8831011B1 patent drawing
  • US8831011B1 patent drawing
  • US8831011B1 patent drawing

AI summary

Communicating with a plurality of networks is disclosed. One or more credentials is provided to a first gatekeeper of a first network. One or more credentials is provided to a second gatekeeper of a second network. A session is maintained with the first gatekeeper. A second session is simultaneously maintained with the second gatekeeper.