Virtual Private Gateway Traffic Routing for Mobile Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication network solutions, such as IP Sec based VPNs, face inefficiencies in bandwidth utilization and scalability when managing secure communication traffic for mobile workers accessing enterprise networks from diverse devices.

Innovation Solution

A Virtual Private Gateway (VPG) system that applies traffic policies and cryptographic techniques to manage communication traffic, decrypting and encrypting data using public-key methods, and routing traffic efficiently between user devices and secure networks, thereby relieving the secure network of unnecessary processing burdens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IP Sec based VPN solutions are used to secure traffic between employees and enterprise network, then security protection is improved, but bandwidth utilization efficiency deteriorates and scalability problems occur

Engineering Contradiction:
Improvesecurity protectionVSAvoidbandwidth utilization efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a Virtual Private Gateway (VPG) as an intermediary component between user devices and the secure network. The VPG is deployed at the service provider network edge and handles VPN tunnel establishment, packet encryption/decryption, and traffic routing. This mediator approach allows the secure network to remain separate from direct user connections, improving scalability while maintaining security. The VPG assumes the burden of processing security protocols, preventing the secure network from being overburdened.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the VPN functionality by separating the secure network from the access network. Instead of having the secure network directly handle all security processing for diverse user devices, the system divides responsibilities: user devices establish VPN tunnels through the VPG, which then routes traffic to the secure network. This segmentation allows each component to be optimized independently and improves overall system scalability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If IP Sec based VPN solutions are used to secure traffic between employees and enterprise network, then security protection is improved, but system scalability deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem scalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The VPG acts as a scalable intermediary that handles the complexity of VPN tunnel management. As the number of user devices increases, the VPG can process additional security protocols without requiring changes to the secure network architecture. The service provider can deploy multiple VPGs across different locations to handle traffic from diverse user devices, improving system scalability while maintaining consistent security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If traffic is routed through secure network for all communications, then security coverage is improved, but network efficiency deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoidnetwork efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by differentiating the treatment of different traffic types. Traffic destined for the secure network undergoes full security processing through the VPG, while traffic for other destinations is routed efficiently without passing through the secure network. This selective approach ensures comprehensive security coverage for critical traffic while maintaining overall network efficiency.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The VPG serves as an intermediary that selectively routes traffic. It decrypts incoming traffic, applies security policies, and only encrypts and routes traffic that needs to access the secure network. This mediator approach prevents unnecessary security processing for all traffic, improving network efficiency while maintaining security coverage for relevant communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9021251B2Methods, systems, and computer program products for providing a virtual private gateway between user devices and various networks
Publication Date: 2015.04.28 AT&T INTELLECTUAL PROPERTY I L P
  • US9021251B2 patent drawing
  • US9021251B2 patent drawing
  • US9021251B2 patent drawing

AI summary

A communication network is operated by receiving traffic from a user device at a gateway device associated with a gateway service provider, which manages gateways to both secure and insecure networks. The gateway uses security policies to determine if traffic is destined to the secure or insecure network and applies appropriate policies which cause the traffic to be routed, dropped, or analyzed.