Prefix Discovery Server for Dynamic VPN Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In dynamic networks, such as military tactical networks, existing VPN gateways face challenges in discovering peer VPN gateways, detecting failed peers, and adapting security associations due to changing network topology, which complicates robust routing and management.

Innovation Solution

Implementing a VPN-based Prefix Discovery Server (PDS) that maps Plain Text networks to secure gateways, maintains current routing information, and assists VPN gateways in determining routes and connections, enabling efficient peer discovery, adaptive security associations, and minimizing management resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VPN gateways are used to provide security and privacy for IP data traffic in dynamic networks, then security and privacy are improved, but peer discovery and routing adaptation become complex and difficult to manage

Engineering Contradiction:
Improvesecurity and privacyVSAvoidrouting management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Prefix Discovery Server (PDS) as an intermediary component that mediates between VPN gateways and the unsecured network. The PDS maintains routing information and assists VPN gateways in determining routes to remote protected enclaves, thereby reducing the complexity of peer discovery and routing management while maintaining security associations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements feedback mechanisms where VPN gateways periodically exchange routing information and security association status with the PDS and each other. This feedback enables automatic detection of failed peers and dynamic adaptation of routing paths without manual intervention, reducing management complexity while maintaining reliable secure connections.

Inventive Principle:
Principle #23Feedback

2Ease of manufacture

If static routing configurations are used for VPN gateways, then implementation and deployment are straightforward, but adaptability to network topology changes is poor

Engineering Contradiction:
Improveimplementation easeVSAvoidnetwork topology adaptability
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent transforms static routing configurations into dynamic systems where VPN gateways and the PDS continuously exchange routing information and security association data. This enables automatic adaptation to network topology changes while maintaining ease of initial deployment through standardized protocols and automated configuration processes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent enables VPN gateways to automatically discover peer gateways, detect failed connections, and adapt security associations without manual reconfiguration. The PDS provides self-service routing information and the system automatically adjusts to network changes, maintaining implementation simplicity while achieving high adaptability.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If manual configuration and management of VPN gateways is performed, then routing control is precise, but management resources and time requirements increase significantly

Engineering Contradiction:
Improverouting control precisionVSAvoidmanagement time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements self-service mechanisms where VPN gateways automatically perform peer discovery, route determination, and security association management with minimal human intervention. The PDS automatically maintains routing information and assists gateways in adapting to network changes, preserving routing control precision while dramatically reducing management time and resource requirements.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent establishes feedback loops where VPN gateways continuously monitor network conditions and automatically adjust routing decisions based on real-time information from the PDS and peer gateways. This automated feedback mechanism maintains precise routing control while eliminating the need for manual reconfiguration during network changes.

Inventive Principle:
Principle #23Feedback

4Reliability

If backup VPN gateways are deployed to ensure reliability, then network robustness is improved, but device complexity and management overhead increase

Engineering Contradiction:
Improvenetwork robustnessVSAvoidgateway infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses feedback mechanisms where VPN gateways periodically exchange status information and routing capabilities with the PDS and peer gateways. This enables automatic detection of failed gateways and dynamic selection of alternative routing paths without requiring pre-configured backup gateways, maintaining network robustness while reducing infrastructure complexity.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent transforms the static backup gateway model into a dynamic system where any available VPN gateway can serve as an alternative path based on real-time network conditions and gateway availability. This dynamic adaptation maintains reliability while eliminating the need for dedicated backup infrastructure.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8296839B2VPN discovery server
Publication Date: 2012.10.23 THE MITRE CORPORATION
  • US8296839B2 patent drawing
  • US8296839B2 patent drawing
  • US8296839B2 patent drawing

AI summary

Methods and systems for enabling robust routing between protected enclaves over an unsecured network are provided herein. In one aspect, the present invention provides methods and systems for enabling routing among a plurality of protected enclaves, each supported by one or more secure gateways, over an unsecured network. Methods and systems according to the present invention achieve key routing requirements while presenting solutions that can be readily scaled to large network environments. In another aspect, the present invention provides methods and systems for implementing a Prefix Discovery Server (PDS) that enables the mapping of Plain Text (PT) networks to secure gateways, maintains current network routing information, and assists VPN gateways in determining routes to remote protected enclaves.