TCP Tunnel Gateway for Network Failover Redundancy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing server cluster communication technologies, such as VPNs, are complex, expensive, and lack self-healing capabilities, leading to security gaps and single points of failure when transmitting data across public networks.

Innovation Solution

Implementing redundant Transmission Control Protocol (TCP) tunnels using UDP datagram-oriented communication channels with gateway applications that monitor and reroute data through local loopback endpoints, providing automatic failover and redundancy without the need for Virtual Private Networks (VPNs).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VPNs are used to span clusters across multiple LANs via the public Internet, then security is improved and an unrestricted layer-3 network path is provided, but device complexity and cost increase, and single points of failure are introduced at router level

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces TCP tunnel gateway applications as intermediary components that establish direct TCP-based communication channels between cluster nodes across the public Internet. These gateways act as mediators that encapsulate and transmit cluster communication traffic without requiring traditional VPN infrastructure, thereby maintaining security while reducing device complexity and eliminating router-level single points of failure

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical VPN tunneling mechanism with a software-based TCP tunneling approach. Instead of relying on hardware VPN concentrators and complex tunneling protocols, the system uses application-layer TCP connections with embedded tunneling logic, substituting complex mechanical/network-layer infrastructure with simpler software-based communication pathways

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If multiple VPN tunnels are established to network servers across LANs, then connectivity is improved, but the process becomes expensive and complex

Engineering Contradiction:
ImproveconnectivityVSAvoidcomplexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal TCP tunnel gateway application that can serve multiple functions: establishing secure connections, providing failover capabilities, and enabling communication across any network topology. This single multi-functional gateway replaces the need for multiple specialized VPN tunnels, achieving versatile connectivity while reducing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the communication parameter from traditional VPN protocol to TCP-based tunneling with embedded channel identification. This parameter change allows the system to use existing TCP infrastructure and port-based multiplexing instead of requiring multiple separate VPN tunnel protocols, thereby achieving versatile connectivity with reduced complexity

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If VPN tunnels traverse each LAN's router, then network path is established, but the router becomes a single point of failure

Engineering Contradiction:
Improvenetwork path establishmentVSAvoidsingle point of failure
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the communication path by establishing direct TCP connections between gateway applications on different servers, bypassing the need for centralized router-based VPN tunneling. Each TCP connection is an independent segment that can fail without affecting other connections, thereby eliminating the router as a single point of failure while maintaining ease of operation through automated gateway coordination

Inventive Principle:
Principle #1Segmentation

4Reliability

If traditional clustering software is deployed on LANs, then security is maintained and layer-4 communication channels are easier to manage, but the system cannot communicate freely across the public Internet

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces dynamic TCP tunnel gateways that can adapt their behavior based on network conditions and security requirements. The gateways dynamically establish connections, manage channel lifecycles, and provide configurable security policies, allowing the system to maintain LAN-like security management while achieving Internet-wide communication capability

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11165891B2Highly available transmission control protocol tunnels
Publication Date: 2021.11.02 DH2I CO
  • US11165891B2 patent drawing
  • US11165891B2 patent drawing
  • US11165891B2 patent drawing

AI summary

Redundant transmission control protocol tunneling of the present invention channels client application data through the public Internet via a secure UDP channel. By integrating one or more gateway applications interposed between an endpoint and the public Internet using local loopback addresses, the present invention provides network path failover redundancy.