VPN Access Point Management for Simultaneous Connections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional VPN clients face a burden in establishing and managing multiple VPN connections, requiring separate communication with each Internet access point, loading/unloading VPN policies, and terminating connections, which becomes cumbersome as the number of simultaneous connections increases.

Innovation Solution

A terminal capable of defining and managing VPN access points, allowing it to establish and maintain multiple VPN connections without requiring separate communication with each physical network, loading/unloading VPN policies, and terminating connections, by using a VPN client that can download, install, and manage VPN policies from a Security Policy Database (SPD) associated with a physical access point.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a terminal establishes multiple separate VPN connections through conventional methods, then multiple VPN access capabilities are achieved, but the operational complexity and user burden increase significantly

Engineering Contradiction:
ImproveVPN connection capabilityVSAvoidConnection management complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent combines multiple separate VPN connection operations into a single integrated access point. The terminal establishes one connection to the IAP that provides access to multiple VPNs simultaneously, merging what would otherwise be separate connection management tasks into a unified process. This resolves the contradiction by maintaining multi-VPN capability while eliminating the operational burden of managing each connection separately.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The integrated access point serves multiple functions simultaneously - it provides access to multiple different VPNs through a single connection interface. This multi-functional design allows the terminal to access various VPN networks without establishing separate physical connections for each, thereby maintaining versatility while simplifying operation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a terminal loads and manages multiple VPN policies separately, then comprehensive security coverage is achieved, but the time and computational resources required increase

Engineering Contradiction:
ImproveSecurity coverageVSAvoidPolicy management time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring and storing multiple VPN policies in the terminal before they are needed. When the terminal connects to the integrated access point, the appropriate policies are already available for immediate activation without requiring separate loading operations. This resolves the contradiction by ensuring comprehensive security coverage is ready in advance, eliminating the time required to load policies on-demand.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If conventional VPN clients terminate each connection separately, then proper connection cleanup is achieved, but the number of operations required increases with each additional VPN

Engineering Contradiction:
ImproveConnection termination integrityVSAvoidTermination procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple separate connection termination operations into a single unified termination process. When the user disconnects from the integrated access point, all associated VPN connections are terminated simultaneously through one operation rather than requiring individual termination for each VPN. This maintains connection termination integrity while dramatically reducing the complexity and number of operations required.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10375023B2System, method and computer program product for accessing at least one virtual private network
Publication Date: 2019.08.06 NOKIA TECHNOLOGIES OY
  • US10375023B2 patent drawing
  • US10375023B2 patent drawing
  • US10375023B2 patent drawing

AI summary

A system for accessing at least one Virtual Private Network (VPN) includes a terminal, and can include at least one Security Policy Database (SPD). The terminal is capable of communicating with a VPN client and at least one application. The VPN client, in turn, is capable of defining at least one VPN access point, each VPN access point including an associated physical access point and VPN policy. Thereafter, the VPN client can access at least one VPN based upon the VPN access point(s) to thereby establish at least one data connection from at least one application across the at least one VPN. In addition, the VPN client can be capable of downloading at least one VPN policy from the SPD. A system for managing at least one Virtual Private Network (VPN) policy is also provided, where the VPN polic(ies) are for use in accessing at least one VPN.