Relay Server Automated VPN Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional VPN relay server configurations require manual settings to restrict access between devices, leading to security vulnerabilities due to user error and increased burden, as settings need to be adjusted each time the VPN is constructed.
Innovation Solution
A relay server with an address filter information storage unit, communication setting information storage unit, and controller that stores initial and current communication settings, allowing only permitted devices to communicate by establishing a routing session based on initial settings, thereby automating the restriction of access and reducing the need for manual adjustments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual settings are performed to restrict access between devices after VPN construction, then security control is achieved, but user burden increases and security vulnerabilities may occur due to user error or forgotten settings
Solution Approach 1:
The system performs preliminary actions by automatically extracting routing target addresses and establishing communication settings during VPN construction before actual communication begins. The relay server proactively configures address filters and communication permissions based on the VPN topology, eliminating the need for users to manually perform these settings afterward.
Solution Approach 2:
The relay server performs self-service by automatically managing its own communication settings and address filters. The system extracts routing target addresses from the VPN configuration and autonomously establishes permission settings, eliminating dependence on manual user configuration and reducing operational errors.
2Adaptability or versatility
If all registered devices are permitted to communicate with each other in VPN, then communication flexibility is improved, but security risks increase due to unintended access
Solution Approach 1:
The system applies local quality by implementing differentiated communication permissions for different devices. Instead of uniform permission settings, the relay server extracts specific routing target addresses and applies selective filtering, allowing each device to have customized access rights based on its role and requirements in the VPN network.
Solution Approach 2:
The relay server acts as an intermediary that mediates communication between devices. It receives packets, checks them against the address filter, and selectively forwards or blocks them. This intermediary function enables fine-grained security control while maintaining communication flexibility for authorized devices.
3Reliability
If manual access restriction settings are required each time VPN is constructed, then security control is achieved, but setup time and complexity increase
Solution Approach 1:
The system performs preliminary actions by automatically configuring address filters and communication permissions during the VPN construction phase. The relay server extracts routing target addresses from the VPN configuration data and establishes security settings before any actual communication occurs, eliminating post-setup configuration steps.
Solution Approach 2:
The system replaces manual mechanical configuration operations with automated electronic processes. The relay server automatically parses VPN configuration, extracts routing target addresses, and generates address filters through electronic processing, substituting the manual mechanical process of setting each permission individually.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
A relay server stores a first routing target address that is an address to which the own relay server can transfer a packet and a second routing target address to which another relay server located in another LAN can transfer a packet. The relay server stores an initial communication setting and a current communication setting. The relay server transmits only the first routing target address that is permitted in the initial communication setting to another relay server and receives the second routing target address from another relay server, to establish a routing session with another relay server. The relay server registers the initial communication setting as the current communication setting. The relay server performs routing control of the packet based on pieces of address filter information on the own relay server and another relay server.