NIC-Brokered VPN for Global Server Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Deploying and configuring multiple servers in a globally distributed fashion is challenging due to varying local networking hardware configurations, making it difficult for IT staff or managed service providers to establish secure connections across networks.

Innovation Solution

Utilizing a network interface controller (NIC) to broker a secure connection across a network between a target information handling system and other entities, such as cloud services or private networks, without requiring tunneling into the host operating system, using a programmable integrated circuit within the NIC to establish a VPN that is independent of the host OS and local network configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional tunneling techniques are used to establish secure connections, then network connectivity can be achieved, but the system becomes vulnerable to attacks and requires complex network configurations that vary by location

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a NIC-based VPN client as an intermediary component that operates at the network interface level, separate from the host OS. This intermediary establishes secure VPN connections independently of traditional tunneling methods, eliminating the need for complex port forwarding and static IP configurations while providing hardware-level security that is transparent to the host system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the software-based conventional tunneling mechanism with a hardware-based NIC-level VPN implementation. By moving the VPN functionality from the software layer (host OS) to the hardware layer (NIC), the system achieves more reliable security without requiring complex network configurations, as the NIC automatically handles connection establishment and maintenance.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If servers are deployed globally with different local networking hardware, then geographic distribution is achieved, but IT staff face difficulty in deploying and configuring multiple servers

Engineering Contradiction:
Improvegeographic distributionVSAvoiddeployment ease
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent implements a universal NIC-based VPN solution that functions identically across all geographic locations regardless of local network hardware variations. The NIC automatically detects the network environment and establishes VPN connections without requiring location-specific configurations, making the deployment process consistent and simple across globally distributed servers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The NIC-based VPN client operates autonomously, automatically detecting network environments and establishing secure connections without requiring manual IT staff intervention. The system self-configures based on the local network conditions, eliminating the need for IT personnel to manually configure each server at different geographic locations.

Inventive Principle:
Principle #25Self-service

3Reliability

If host OS-based VPN solutions are used, then secure connections can be established, but the host OS and other logic must understand network configurations

Engineering Contradiction:
Improveconnection securityVSAvoidoperational simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the VPN functionality from the host OS by implementing it at the NIC level. This separation allows the NIC to handle all VPN-related operations independently, including connection establishment, encryption, and network configuration detection, while the host OS simply communicates through the established connection without needing to understand the underlying network complexities.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11546311B2Systems and methods using a network interface controller (NIC) to broker a secure remote connection at the hardware layer
Publication Date: 2023.01.03 DELL PROD LP
  • US11546311B2 patent drawing
  • US11546311B2 patent drawing
  • US11546311B2 patent drawing

AI summary

Systems and methods are provided that may be implemented to use compute capabilities of a network interface controller (NIC) to broker a secure connection across a network between a target information handling system (e.g., such as a server) and one or more other entities (e.g., such as other information handling systems implementing a cloud service or private network, and/or that are providing other remote service/s across the network). This secure connection may be brokered by the NIC at a hardware level in a manner that is separate from a host programmable integrated circuit of the same target information handling system, and in a way that is agnostic and independent of any host operating system or other logic that is executing on the host programmable integrated circuit of the target information handling system.