Virtual Private Hosts for Peer-to-Peer VPN Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current virtual private networks (VPNs) do not provide connectivity to individuals outside an enterprise environment, limiting secure group communication over the internet to only enterprise-affiliated users.

Innovation Solution

A method and apparatus enabling peer-to-peer virtual private network (P2P-VPN) services through a virtual internet protocol (IP) service agent (VISA) that allocates subnet and host addresses for user devices, forming secure tunnels for communication, allowing secure communication among individuals over the internet.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional enterprise VPN tunneling protocols are used, then secure communication is achieved within enterprise boundaries, but connectivity to individuals outside enterprise environment is not provided

Engineering Contradiction:
ImproveVPN connectivity availabilityVSAvoidsecure communication capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces Virtual Private Hosts (VPHs) as intermediary entities that mediate between individual users and the VPN network. VPHs act as proxies that enable consumers to establish secure VPN connections without requiring direct enterprise infrastructure access, thus extending VPN capabilities beyond traditional enterprise boundaries while maintaining security through controlled intermediary access points

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables a single VPN infrastructure to serve multiple functions: traditional enterprise VPN connectivity for organizational users and new peer-to-peer VPN services for individual consumers. The VPH mechanism provides universal access points that can handle both enterprise and consumer connections, making the VPN system multi-functional without requiring separate infrastructure

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If VPN services are extended to peer-to-peer individual users, then connectivity beyond enterprise boundaries is enabled, but network address management complexity increases

Engineering Contradiction:
Improvepeer-to-peer connectivityVSAvoidaddress allocation system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Virtual Private Hosts automatically perform address allocation and tunnel establishment without requiring manual configuration by individual users. The VPHs self-manage the complex address allocation process by receiving requests from consumers, automatically assigning appropriate network addresses, and establishing encrypted tunnels, thereby hiding the complexity from end users while enabling peer-to-peer connectivity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

VPHs serve as intermediary address management entities that abstract the complexity of network address allocation from individual users. Instead of users directly managing complex VPN address assignments, they interact with VPHs that handle all address allocation, tunnel configuration, and network routing automatically

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple virtual private hosts are created for user devices, then secure tunnels can be established for each user, but system resource consumption increases

Engineering Contradiction:
Improvesecure tunnel establishmentVSAvoidnumber of virtual private hosts
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

Multiple user connections are merged and routed through shared Virtual Private Host infrastructure. Instead of creating completely separate VPN systems for each user, the patent combines multiple user tunnels under a unified VPH management framework, allowing resource sharing while maintaining individual secure connections through the common VPH layer

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7421736B2Method and apparatus for enabling peer-to-peer virtual private network (P2P-VPN) services in VPN-enabled network
Publication Date: 2008.09.02 LUCENT TECH INC
  • US7421736B2 patent drawing
  • US7421736B2 patent drawing
  • US7421736B2 patent drawing

AI summary

A method for providing peer-to-peer virtual private network (P2P-VPN) services over a network. The method includes identifying subnet and host addresses for each user device requesting participation in a virtual private network (VPN) session. Once the subnet and host addresses are identified, a virtual private host (VPH) is initiated for each user device, where each VPH communicates with each user device via a respective tunnel through the network, thereby enabling secure communications between the user devices.