Smart Virtual Private Network Dynamic Security Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional IPsec and similar security protocols in hub and spoke networks force all devices to use a single security level, lacking flexibility and efficiency, as they do not allow for dynamic selection of security algorithms or endpoint-specific security configurations, which can result in overutilization of resources and inadequate security.

Innovation Solution

A smart virtual private network (VPN) system that uses a policy server to dynamically configure security protocols based on client device capabilities and communication types, allowing for point-to-point secure communication with varying security levels by selecting appropriate encryption, hashing, and Diffie-Hellman algorithms for each connection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single common security level is used for all devices in hub and spoke networks, then security policy management is simplified, but security optimization for individual devices is lost and resource overutilization occurs

Engineering Contradiction:
Improvesecurity policy managementVSAvoidsecurity level adaptation
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by allowing each spoke device to have its own security configuration parameters (hashing algorithm, encryption algorithm, DH group) selected according to its specific capabilities and requirements, rather than forcing a uniform security level across all devices. The hub device can assign different security levels to different spokes based on their individual needs.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamics by enabling dynamic selection of security algorithms and parameters during connection establishment. The hub device can dynamically assign appropriate security levels to spoke devices based on their capabilities, and spoke devices can dynamically choose from multiple algorithm options (e.g., SHA-1, SHA-256, AES-128, AES-256, DH groups 14, 16, 18, 20) rather than being locked into a static configuration.

Inventive Principle:
Principle #15Dynamics

2Reliability

If high security levels are applied to all communications, then security protection is maximized, but resource consumption and overhead increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies parameter changes by allowing the security parameters (hashing algorithm, encryption algorithm, DH group) to be varied based on the specific communication needs and device capabilities. Lower-security communications can use less resource-intensive algorithms while maintaining adequate protection, and only high-security communications use stronger algorithms that consume more resources.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements partial action by applying security measures proportional to the actual risk and requirements of each communication. Not all communications require the highest level of security, so the system applies appropriate security levels selectively - using stronger encryption only when necessary and weaker encryption for less sensitive communications, thereby avoiding excessive resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of manufacture

If all spoke devices use the same hashing and encryption algorithms, then implementation is simplified, but optimal security for individual devices cannot be achieved

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity optimization
Core Design Contradiction:
Ease of manufactureVSManufacturing precision

Solution Approach 1:

The patent applies universality by designing the hub device and spoke devices to support multiple hashing algorithms (SHA-1, SHA-256, SHA-512), multiple encryption algorithms (AES-128, AES-256, 3DES, DES), and multiple DH groups (14, 16, 18, 20). This multi-functional capability allows the system to adapt to different device requirements while maintaining a unified architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements segmentation by separating the security configuration into independent selectable parameters (hashing algorithm, encryption algorithm, DH group) that can be individually chosen for each spoke device. This allows the hub to assign different combinations of algorithms to different spokes based on their capabilities, achieving customized security without requiring complete customization of each device.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9516061B2Smart virtual private network
Publication Date: 2016.12.06 CISCO TECHNOLOGY INC
  • US9516061B2 patent drawing
  • US9516061B2 patent drawing
  • US9516061B2 patent drawing

AI summary

In one implementation, a policy server establishes a smart virtual private network between two client devices. The smart virtual private network includes a secure communication session using a security level or security algorithm that is variable and defined as a function of the two client devices. A first client device may generate a registration request including a first security configuration including the security level. Based on the registration request, the policy server generates a routing message that defines routing for communication from the first client device to a second client device. The routing message may update a routing table to associate the policy server with the second client device.