Split VPN Tunnels for Enterprise Network Bandwidth Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large-scale enterprises with multiple VPN concentrators face challenges in managing VPN access efficiently, leading to increased bandwidth consumption and latency due to local VPN concentrators acting as proxies for inter-concentrator connections.
Innovation Solution
A VPN handler on a client device automatically creates multiple split VPN tunnels based on resource lists provided by local VPN concentrators, allowing direct access to different VPN concentrators, thereby reducing the burden on local VPN concentrators and minimizing latency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If local VPN concentrators operate as proxies for inter-concentrator connections, then connectivity between geographically separate networks is maintained, but bandwidth consumption and latency increase
Solution Approach 1:
The patent segments VPN traffic into different tunnels based on destination network. Instead of all traffic going through the local concentrator as a proxy, the system creates separate VPN tunnels to remote concentrators for traffic destined to remote networks. This segmentation allows local concentrators to forward only local traffic while remote traffic goes directly to remote concentrators, reducing bandwidth consumption on local links.
Solution Approach 2:
The patent introduces VPN tunnels as intermediary connections between client devices and remote VPN concentrators. These tunnels act as direct pathways that bypass the local concentrator proxy function for remote traffic, allowing traffic to be routed efficiently without unnecessary hops through the local concentrator for inter-concentrator communication.
2Reliability
If local VPN concentrators operate as proxies for inter-concentrator connections, then connectivity between geographically separate networks is maintained, but latency increases
Solution Approach 1:
The patent segments VPN traffic into different tunnels based on destination network. Instead of all traffic going through the local concentrator as a proxy, the system creates separate VPN tunnels to remote concentrators for traffic destined to remote networks. This segmentation allows local concentrators to forward only local traffic while remote traffic goes directly to remote concentrators, reducing bandwidth consumption on local links.
Solution Approach 2:
The patent extracts the proxy function from local VPN concentrators by implementing direct VPN tunnels to remote concentrators. The local concentrator no longer needs to proxy remote traffic, extracting this function from the local infrastructure and placing it directly in the remote concentrators, thereby eliminating unnecessary latency introduced by local proxy operations.
3Reliability
If multiple VPN concentrators are deployed for geographically separate networks, then secure access to enterprise resources is provided, but device complexity increases
Solution Approach 1:
The patent implements self-service by having client devices automatically manage multiple VPN connections based on resource location. The VPN handler on client devices automatically determines which concentrator to connect to based on the destination network, eliminating the need for complex manual configuration and reducing the operational burden on network administrators while maintaining secure multi-location access.
Solution Approach 2:
The patent introduces dynamic resource lists that are pushed from VPN concentrators to client devices. These lists automatically reflect the current network topology and resource locations, allowing the VPN system to adapt dynamically to network changes without requiring manual reconfiguration. This dynamic approach simplifies management while maintaining secure access across geographically distributed networks.
Data Source
AI summary
A VPN handler of a client device is described that provides VPN connectivity by automatically creating multiple split VPN tunnels that provide direct access to different VPN concentrators of an enterprise based on specific resources requested by the client device. A local VPN concentrator normally used by the client device may provide the VPN handler with a resource list that provides a mapping of the resources of the enterprise network to the multiple VPN concentrators that have been deployed to provide secure access to those resources. The local VPN concentrator may dynamically update the resource list on the client device so as to control the construction and use of the split VPN tunnels by the VPN handler based on changes to the enterprise network. The split tunnel approach may be transparent to applications executing on the client device and may be easily deployed to the client devices of the enterprise.


