Socket-Level VPN Apparatus for IPv4-IPv6 Protocol Conversion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

VPN communication apparatuses using IPSec and SSL technologies face limitations in mixed IPv4/IPv6 networks due to lack of conversion technology between IPv4 and IPv6, and are restricted by fixed cryptographic algorithms, failing to provide adequate security for diverse applications.

Innovation Solution

A VPN communication apparatus and method that processes data at the socket level, incorporating a VPN database for connection and security information, a packet analyzing module, a key exchange engine, and a socket data processing engine to encode/decode data, enabling secure communication across IPv4/IPv6 networks and supporting various cryptographic algorithms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IPSec protocol is used for VPN communication, then network layer security is provided, but it cannot be applied in mixed IPv4/IPv6 networks due to lack of conversion technology

Engineering Contradiction:
Improvenetwork layer securityVSAvoidcompatibility with mixed IPv4/IPv6 networks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a VPN communication apparatus as an intermediary device that includes protocol conversion functionality. This apparatus acts as a mediator between IPv4 and IPv6 networks, converting packets between the two protocols to enable IPSec-based VPN communication in mixed network environments. The apparatus includes packet analyzing modules for both IPv4 and IPv6, and protocol conversion modules that translate between the protocols, thus resolving the incompatibility issue.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If SSL technology is used for VPN communication, then web security is provided, but it is restricted to fixed standard cryptographic algorithms and cannot provide adequate security for diverse applications

Engineering Contradiction:
Improveweb securityVSAvoidsupport for diverse cryptographic algorithms
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic cryptographic algorithm selection mechanism in the VPN communication apparatus. The system includes a key exchange engine that can dynamically choose between multiple cryptographic algorithms (DES, 3DES, AES, RC4, MD5, SHA-1, SHA-256) based on the specific application requirements and security needs. This dynamic adaptability allows the system to provide appropriate security levels for different applications rather than being restricted to fixed algorithms.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the cryptographic parameters by supporting multiple cryptographic algorithms with different security strengths and characteristics. The system can adjust the cryptographic algorithm parameter based on the application requirements, allowing users to select from various encryption standards and hash functions. This parameter flexibility enables the VPN apparatus to provide adequate security for diverse applications beyond standard web security requirements.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If VPN communication apparatus is implemented as software in client-side, then flexibility is provided, but it frequently conflicts with various types of applications

Engineering Contradiction:
Improveclient-side flexibilityVSAvoidapplication conflicts
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The patent positions the VPN communication apparatus as an intermediary component that can be implemented as a kernel module or standalone service rather than pure client-side software. This intermediary position allows it to intercept and process network packets at a lower level, preventing conflicts with higher-level applications. The apparatus includes packet analyzing modules that work at the network layer, isolating VPN functionality from application-layer conflicts while maintaining flexibility through configurable connection management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8011004B2Apparatus and method for VPN communication in socket-level
Publication Date: 2011.08.30 ELECTRONICS & TELECOMM RES INST
  • US8011004B2 patent drawing
  • US8011004B2 patent drawing
  • US8011004B2 patent drawing

AI summary

Provided is an apparatus and method for virtual private network (VPN) communication in a socket level that can be applied in an Internet Protocol version 4(IPv4)/IPv6 complex network, and can process data in a socket level to make a VPN communication apparatus available in many applications requiring more security, as well as a web application, wherein the data is transmitted to and received from any one of the internal device and the external device.