Prefix Discovery Server for Dynamic VPN Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In dynamic networks, such as military tactical networks, existing VPN gateways face challenges in discovering peer VPN gateways, detecting failed peers, and adapting security associations due to changing network topology, which complicates robust routing and management.
Innovation Solution
Implementing a VPN-based Prefix Discovery Server (PDS) that maps Plain Text networks to secure gateways, maintains current routing information, and assists VPN gateways in determining routes and connections, enabling efficient peer discovery, adaptive security associations, and minimizing management resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If VPN gateways are used to provide security and privacy for IP data traffic in dynamic networks, then security and privacy are improved, but peer discovery and routing adaptation become complex and difficult to manage
Solution Approach 1:
The patent introduces a Prefix Discovery Server (PDS) as an intermediary component that mediates between VPN gateways and the unsecured network. The PDS maintains routing information and assists VPN gateways in determining routes to remote protected enclaves, thereby reducing the complexity of peer discovery and routing management while maintaining security associations.
Solution Approach 2:
The patent implements feedback mechanisms where VPN gateways periodically exchange routing information and security association status with the PDS and each other. This feedback enables automatic detection of failed peers and dynamic adaptation of routing paths without manual intervention, reducing management complexity while maintaining reliable secure connections.
2Ease of manufacture
If static routing configurations are used for VPN gateways, then implementation and deployment are straightforward, but adaptability to network topology changes is poor
Solution Approach 1:
The patent transforms static routing configurations into dynamic systems where VPN gateways and the PDS continuously exchange routing information and security association data. This enables automatic adaptation to network topology changes while maintaining ease of initial deployment through standardized protocols and automated configuration processes.
Solution Approach 2:
The patent enables VPN gateways to automatically discover peer gateways, detect failed connections, and adapt security associations without manual reconfiguration. The PDS provides self-service routing information and the system automatically adjusts to network changes, maintaining implementation simplicity while achieving high adaptability.
3Measurement precision
If manual configuration and management of VPN gateways is performed, then routing control is precise, but management resources and time requirements increase significantly
Solution Approach 1:
The patent implements self-service mechanisms where VPN gateways automatically perform peer discovery, route determination, and security association management with minimal human intervention. The PDS automatically maintains routing information and assists gateways in adapting to network changes, preserving routing control precision while dramatically reducing management time and resource requirements.
Solution Approach 2:
The patent establishes feedback loops where VPN gateways continuously monitor network conditions and automatically adjust routing decisions based on real-time information from the PDS and peer gateways. This automated feedback mechanism maintains precise routing control while eliminating the need for manual reconfiguration during network changes.
4Reliability
If backup VPN gateways are deployed to ensure reliability, then network robustness is improved, but device complexity and management overhead increase
Solution Approach 1:
The patent uses feedback mechanisms where VPN gateways periodically exchange status information and routing capabilities with the PDS and peer gateways. This enables automatic detection of failed gateways and dynamic selection of alternative routing paths without requiring pre-configured backup gateways, maintaining network robustness while reducing infrastructure complexity.
Solution Approach 2:
The patent transforms the static backup gateway model into a dynamic system where any available VPN gateway can serve as an alternative path based on real-time network conditions and gateway availability. This dynamic adaptation maintains reliability while eliminating the need for dedicated backup infrastructure.
Data Source
AI summary
Methods and systems for enabling robust routing between protected enclaves over an unsecured network are provided herein. In one aspect, the present invention provides methods and systems for enabling routing among a plurality of protected enclaves, each supported by one or more secure gateways, over an unsecured network. Methods and systems according to the present invention achieve key routing requirements while presenting solutions that can be readily scaled to large network environments. In another aspect, the present invention provides methods and systems for implementing a Prefix Discovery Server (PDS) that enables the mapping of Plain Text (PT) networks to secure gateways, maintains current network routing information, and assists VPN gateways in determining routes to remote protected enclaves.


