Smart Virtual Private Network Dynamic Security Configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional IPsec and similar security protocols in hub and spoke networks force all devices to use a single security level, lacking flexibility and efficiency, as they do not allow for dynamic selection of security algorithms or endpoint-specific security configurations, which can result in overutilization of resources and inadequate security.
Innovation Solution
A smart virtual private network (VPN) system that uses a policy server to dynamically configure security protocols based on client device capabilities and communication types, allowing for point-to-point secure communication with varying security levels by selecting appropriate encryption, hashing, and Diffie-Hellman algorithms for each connection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single common security level is used for all devices in hub and spoke networks, then security policy management is simplified, but security optimization for individual devices is lost and resource overutilization occurs
Solution Approach 1:
The patent applies local quality by allowing each spoke device to have its own security configuration parameters (hashing algorithm, encryption algorithm, DH group) selected according to its specific capabilities and requirements, rather than forcing a uniform security level across all devices. The hub device can assign different security levels to different spokes based on their individual needs.
Solution Approach 2:
The patent implements dynamics by enabling dynamic selection of security algorithms and parameters during connection establishment. The hub device can dynamically assign appropriate security levels to spoke devices based on their capabilities, and spoke devices can dynamically choose from multiple algorithm options (e.g., SHA-1, SHA-256, AES-128, AES-256, DH groups 14, 16, 18, 20) rather than being locked into a static configuration.
2Reliability
If high security levels are applied to all communications, then security protection is maximized, but resource consumption and overhead increase
Solution Approach 1:
The patent applies parameter changes by allowing the security parameters (hashing algorithm, encryption algorithm, DH group) to be varied based on the specific communication needs and device capabilities. Lower-security communications can use less resource-intensive algorithms while maintaining adequate protection, and only high-security communications use stronger algorithms that consume more resources.
Solution Approach 2:
The patent implements partial action by applying security measures proportional to the actual risk and requirements of each communication. Not all communications require the highest level of security, so the system applies appropriate security levels selectively - using stronger encryption only when necessary and weaker encryption for less sensitive communications, thereby avoiding excessive resource consumption.
3Ease of manufacture
If all spoke devices use the same hashing and encryption algorithms, then implementation is simplified, but optimal security for individual devices cannot be achieved
Solution Approach 1:
The patent applies universality by designing the hub device and spoke devices to support multiple hashing algorithms (SHA-1, SHA-256, SHA-512), multiple encryption algorithms (AES-128, AES-256, 3DES, DES), and multiple DH groups (14, 16, 18, 20). This multi-functional capability allows the system to adapt to different device requirements while maintaining a unified architecture.
Solution Approach 2:
The patent implements segmentation by separating the security configuration into independent selectable parameters (hashing algorithm, encryption algorithm, DH group) that can be individually chosen for each spoke device. This allows the hub to assign different combinations of algorithms to different spokes based on their capabilities, achieving customized security without requiring complete customization of each device.
Data Source
AI summary
In one implementation, a policy server establishes a smart virtual private network between two client devices. The smart virtual private network includes a secure communication session using a security level or security algorithm that is variable and defined as a function of the two client devices. A first client device may generate a registration request including a first security configuration including the security level. Based on the registration request, the policy server generates a routing message that defines routing for communication from the first client device to a second client device. The routing message may update a routing table to associate the policy server with the second client device.


