Relay Server Virtual Address Allocation for Secure Inter-LAN Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In VPN communication systems, there is a security concern when different companies need to connect, as the IP addresses of devices within one LAN are typically shared, potentially compromising security if exposed to another LAN.
Innovation Solution
A relay server configuration that includes an address filter information storage unit, a virtual address allocation relationship storage unit, and a controller to allocate and manage virtual addresses, ensuring that actual IP addresses are not shared across LANs, thereby maintaining security by using virtual addresses for communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If VPN communication is established between different companies using actual IP addresses, then communication functionality is improved, but security deteriorates because IP addresses are exposed to the other LAN
Solution Approach 1:
The patent introduces a relay server as an intermediary between LANs. The relay server allocates virtual addresses to terminals and translates packets between virtual addresses and actual IP addresses. This mediator enables communication between different companies while preventing direct exposure of actual IP addresses, thus resolving the contradiction between communication functionality and security.
Solution Approach 2:
The patent creates virtual addresses as copies or representations of actual IP addresses. These virtual addresses serve as substitutes that can be exchanged between relay servers without revealing the real IP addresses. The copying mechanism allows communication to proceed using fictitious addresses while maintaining the security of actual network identifiers.
2Object-affected harmful factors
If virtual addresses are allocated and managed by relay servers, then security is improved by hiding actual IP addresses, but device complexity increases due to address translation mechanisms
Solution Approach 1:
The relay server automatically performs address translation without requiring manual configuration or intervention. The server maintains translation tables that map virtual addresses to actual IP addresses and automatically translates packets bidirectionally. This self-service approach centralizes the complexity within the relay server while keeping terminal devices simple, resolving the contradiction between security enhancement and device complexity.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
A first relay server stores a first routing target address and a second routing target address. The first relay server stores a first routing target address and a virtual address allocated to the first routing target address while correlated with each other. The first relay server allocates the virtual address to the first routing target address. The first relay server can set whether communication is conducted using the virtual address or the first routing target address with respect to each second relay server. The first relay server transmits the virtual address allocated to the first routing target address to the second relay server, and receives the second routing target address from the second relay server, thereby establishing a routing session with the second relay server. The first relay server performs routing control based on the exchanged routing target address.