Reverse Session-Origination Tunnel for Remote Network Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Small and medium-sized businesses (SMBs) face difficulties in remotely accessing and managing their on-premises computer networks due to the complexities and costs associated with setting up Virtual Private Networks (VPNs), which often result in address conflicts and limited remote management capabilities.

Innovation Solution

A Management-As-A-Service (MaaS) server communicates with client networks through a reverse session-origination (RSO) tunnel, allowing remote users to access and manage networks via a MaaS agent that creates and manages the tunnel, collects metrics, and provides alerts and recommendations, thereby reducing the burden of VPN setup and addressing address conflicts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VPN is used for remote access to on-premises network, then secure remote access is achieved, but address conflicts occur and setup becomes costly and cumbersome

Engineering Contradiction:
Improvesecure remote accessVSAvoidsetup complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud-based intermediary service that mediates between remote users and on-premises networks. Instead of direct VPN connections between user devices and network resources, all communications are routed through the cloud intermediary, which handles authentication, session management, and network address translation. This eliminates address conflicts while maintaining security through centralized control and isolated network paths for each user session.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent inverts the traditional VPN architecture by having the network come to the user instead of the user connecting to the network. The on-premises network initiates outbound connections to cloud-based virtual network interfaces, which then present the network resources to remote users. This reversal eliminates the need for inbound port forwarding and complex firewall configurations, simplifying setup while maintaining secure access.

Inventive Principle:
Principle #13The other way round (Inversion)

2Adaptability or versatility

If multiple VPN connections are established simultaneously, then remote access flexibility is improved, but address conflicts prevent contact with all devices

Engineering Contradiction:
Improveremote access flexibilityVSAvoiddevice accessibility
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the network address space by creating isolated virtual network interfaces in the cloud for each user session. Each user receives a dedicated virtual network segment with unique addressing, eliminating address conflicts that occur when multiple VPN connections share the same address space. This segmentation allows users to access multiple network resources simultaneously without interference, as each connection operates in its own isolated address domain.

Inventive Principle:
Principle #1Segmentation

3Reliability

If firewall restricts communications for security, then network security is improved, but legitimate remote access becomes difficult

Engineering Contradiction:
Improvenetwork securityVSAvoidremote access ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by pre-establishing outbound connections from the on-premises network to cloud-based virtual interfaces before any user access is needed. These pre-established connections are authorized by the firewall in advance, creating allowed communication paths. When users need access, they simply connect to the pre-configured cloud interfaces without requiring the firewall to dynamically open new inbound ports, thus maintaining security while enabling easy remote access.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10742480B2Network management as a service (MaaS) using reverse session-origination (RSO) tunnel
Publication Date: 2020.08.11 VMWARE INC
  • US10742480B2 patent drawing
  • US10742480B2 patent drawing
  • US10742480B2 patent drawing

AI summary

A Management-as-a-Service (MaaS) agent running on a client network creates a reverse session-origination (RSO) tunnel between the client network and a MaaS server. The MaaS agent collects client statistics at and regarding the client network and transmits the client statistics to the MaaS server. The MaaS server analyzes the client data and sends alerts or other messages to a user, who may be outside the client network, in the event certain conditions are met.