Remote Access Point for Secure Enterprise Network Extension
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Remote employees face decreased productivity due to non-uniform and less intuitive VPN client applications, leading to less frequent access to enterprise network resources and increased IT resource usage.
Innovation Solution
A method for securely extending a private network by establishing a secure communication path using Layer 3 encryption for control information and optional Layer 2 encryption for data, allowing seamless remote access through a remote access point configured with OSI Layer 3 security protocols like IPsec, and providing alternative wired connectivity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If VPN client applications are used for remote access, then employees can access enterprise network resources remotely, but the access procedure becomes non-intuitive and less efficient
Solution Approach 1:
The patent introduces a remote access point as an intermediary device that mediates between the remote employee's device and the enterprise network. This intermediary provides a simplified, intuitive interface for remote access while maintaining secure connection to the enterprise network resources, eliminating the need for employees to directly configure complex VPN client applications.
2Ease of operation
If VPN client applications are used for remote access, then employees can access enterprise network resources remotely, but IT resource usage increases
Solution Approach 1:
The remote access point serves as a centralized intermediary that handles authentication, encryption, and network management functions. By consolidating these IT resources at the access point rather than distributing them across multiple employee devices, the system reduces overall IT resource consumption while maintaining secure remote access capabilities.
3Reliability
If Layer 3 encryption is applied to all information, then security is enhanced, but computational complexity increases
Solution Approach 1:
The patent applies different encryption approaches to different types of information traffic. Control information undergoes Layer 3 encryption for enhanced security, while data traffic uses Layer 2 encryption or other optimization techniques. This localized differentiation of security measures ensures that critical control information is highly protected while reducing unnecessary computational overhead on data traffic.
Solution Approach 2:
The system dynamically adjusts encryption parameters based on the type of information being transmitted. By changing the encryption layer and intensity according to information classification (control vs. data), the system optimizes the balance between security requirements and computational complexity, applying stronger encryption only where necessary.
Data Source
AI summary
According to one embodiment of the invention, a method for securely extending a private network to include one or more remote access points (APs) comprises a first operation of establishing a secure communication path with a destination device. Then, the information received from a source device is prepared for transmission to the destination device. This involves the received information undergoing Layer 3 (L3) encryption prior to encapsulation into a message for transmission to the destination device if the received information constitutes control information. If the received information constitutes data, the received information optionally undergoes L3 encryption, since the payload data might be already L2 encrypted by the source device, prior to encapsulation into the message.


