Intelligent N-Way Split VPN Tunnel Traffic Sorting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current VPN tunnel solutions either burden central locations with unnecessary traffic or require expensive devices at remote locations for filtering and scrubbing, exposing clients to threats and inefficiencies.

Innovation Solution

Intelligent sorting of datagrams through N-way split VPN tunnels, where traffic is routed based on latency, network failures, energy usage, and policies to ensure secure and efficient routing, using computer programs at remote locations to direct traffic through appropriate branches for filtering and scrubbing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If split tunnel is used to offload traffic from central location, then central location load is reduced, but client security is compromised due to lack of filtering and scrubbing

Engineering Contradiction:
Improvecentral location loadVSAvoidclient exposure to threats
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the VPN tunnel into multiple branches: a first branch for unfiltered traffic to reduce central location load, and a second branch for filtered and scrubbed traffic to ensure client security. The networking device intelligently routes traffic through appropriate branches based on security requirements and traffic characteristics.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary filtering and scrubbing service that processes traffic through the second branch of the VPN tunnel. This intermediary component provides security filtering and scrubbing capabilities without requiring expensive local devices at remote locations, thus maintaining client security while reducing central location burden.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If expensive networking devices are deployed at remote location for filtering and scrubbing, then client security is improved, but device cost and complexity increase

Engineering Contradiction:
Improveclient exposure to threatsVSAvoidremote location device complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

Instead of deploying expensive filtering and scrubbing devices at remote locations, the patent uses an intermediary filtering service accessible through the VPN tunnel. This service provides the same security functions remotely, eliminating the need for complex local devices while maintaining client security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent effectively copies the filtering and scrubbing functionality from what would traditionally be local devices to a remote service. The same security functions are performed by the intermediary service through the second branch of the VPN tunnel, achieving identical security outcomes without local hardware complexity.

Inventive Principle:
Principle #26Copying

3Object-affected harmful factors

If all traffic is routed through central location for security filtering, then client security is improved, but network latency and energy consumption increase

Engineering Contradiction:
Improveclient exposure to threatsVSAvoidnetwork latency
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent segments traffic routing into two paths: critical traffic requiring security filtering is routed through the second branch via the intermediary service, while non-critical traffic can use the first branch for faster direct routing. This segmentation reduces latency for traffic that doesn't require intensive filtering while maintaining security for necessary traffic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different quality levels of filtering to different traffic types. The intermediary filtering service provides comprehensive filtering for traffic that needs it, while allowing other traffic to bypass the filtering process. This local quality approach ensures security where needed while minimizing latency for traffic that doesn't require filtering.

Inventive Principle:
Principle #3Local quality

4Productivity

If N-way split tunnel with intelligent sorting is implemented, then traffic routing efficiency is improved, but system complexity increases

Engineering Contradiction:
Improvetraffic routing efficiencyVSAvoidsmartphone system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a universal sorting mechanism that handles multiple traffic types and routing scenarios through a single intelligent sorting component. The sorting component can direct traffic to different VPN tunnel branches based on various criteria (security requirements, traffic type, destination), providing multi-functional routing capabilities without requiring separate mechanisms for each scenario.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10701034B2Intelligent sorting for N-way secure split tunnel
Publication Date: 2020.06.30 EXTREME NETWORKS INC
  • US10701034B2 patent drawing

AI summary

A method of intelligently sorting packets/datagrams for sending through appropriate branches of a N-way split VPN tunnel according to embodiments of the present invention allow for efficient movement of network traffic to and from a remote network location. Intelligent sorting may be based on a wide range of criteria in order to implement different policies. For example, datagrams may be sorted for sending through the branches of a 3-way split tunnel so that all traffic from a remote network location ultimately destined to servers at a central location may be sent via a secure VPN tunnel, all traffic that matches a “white-list” of trusted external sites may be sent directly to and from these sites to the remote network location, and all other traffic may be redirected through a Web service that scrubs and filters the traffic to/from questionable sites. Furthermore, the VPN tunnel may be chosen to minimize latency, to detour around network failures, or to conserve energy by minimizing the number of routers a datagram passes through.