Multi-Path VPN Resilience via Traffic Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VPN technologies lack resilience and automatic recovery mechanisms, particularly in multi-point-to-point link configurations, making them vulnerable to failures and attacks, and compromising user privacy due to lack of IP management functionality and traceless session logs.

Innovation Solution

Implementing a multi-path VPN solution that splits network traffic into multiple routes, establishing two active VPN tunnels between a user and a VPN service provider, ensuring continuous internet access without exposing unencrypted traffic, and utilizing VPN servers with dual roles for data and meta channels to manage connections and failover.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single VPN tunnel is used for connection, then the device complexity is reduced, but the reliability deteriorates due to lack of redundancy and vulnerability to failures

Engineering Contradiction:
Improveconnection reliabilityVSAvoidVPN configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments network traffic into multiple routes, each routed through separate VPN tunnels. This segmentation allows the system to distribute traffic across multiple connections, ensuring that if one tunnel fails, other tunnels maintain connectivity. The routing table is configured with multiple routes pointing to different VPN interfaces,实现ing automatic failover without requiring complex manual configuration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent combines multiple VPN tunnels into a unified connection framework where several encrypted tunnels work together to provide redundant paths. By merging multiple tunnels with different destination IPs but same destination network, the system creates a resilient network architecture that maintains connectivity through any single tunnel while keeping the overall configuration manageable through automated route management.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If multiple VPN tunnels are established for redundancy, then the reliability is improved, but the device complexity increases due to multiple configurations

Engineering Contradiction:
Improveconnection availabilityVSAvoidrouting configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service through automated route management where the routing table is automatically configured with multiple routes to different VPN tunnels based on destination networks. The system self-manages the complexity by automatically selecting appropriate routes and managing tunnel configurations, eliminating the need for manual intervention while maintaining multiple redundant connections for improved reliability.

Inventive Principle:
Principle #25Self-service

3Reliability

If traffic is routed through multiple VPN tunnels, then the resilience is enhanced, but the loss of time increases due to routing decisions and failover procedures

Engineering Contradiction:
Improveservice continuityVSAvoidconnection establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring the routing table with multiple routes to different VPN tunnels before failures occur. This allows the system to have ready-made alternative paths that can be activated immediately upon detecting a tunnel failure, eliminating the need for time-consuming route discovery and reconfiguration during failover scenarios.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses feedback mechanisms to monitor the status of VPN tunnels and automatically adjust routing based on real-time conditions. By continuously monitoring tunnel health and providing feedback to the routing system, the network can dynamically switch to alternative tunnels when failures are detected, maintaining service continuity without manual intervention while minimizing downtime through rapid response to status changes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20220210130A1Method and apparatus for maintaining a resilient VPN connection
Publication Date: 2022.06.30 NETFLOW UAB
  • US20220210130A1 patent drawing
  • US20220210130A1 patent drawing
  • US20220210130A1 patent drawing

AI summary

The present embodiment relates to method and system for establishing, by an individual VPN customer or a plurality of VPN customers, a multi-path failure-resistant connectivity to a VPN service while ensuring no unencrypted customer traffic is ever exposed in a public network. The additional aspects of the method and system disclosed is the constant connectivity assessment executed and the automatically triggered recovery mechanism incorporated.