Automatic VPN Establishment via Central Server Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing virtual private networks between remote local area networks requires complex and costly configuration, including prior setup of dedicated physical networks and manual port configuration, which limits scalability and flexibility.
Innovation Solution
A method and system for automatically establishing a virtual private network by sending connection messages to an infrastructure with an intermediate server, determining topology data, instancing a VPN server, creating encryption tunnels, and storing routing data, allowing for transparent gateway replacement and multi-access administration without additional configuration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MPLS protocol is used to establish private network, then data security is improved, but device complexity and cost increase due to requiring dedicated physical network
Solution Approach 1:
The patent introduces a central server as an intermediary that coordinates VPN establishment between remote networks. This server acts as a mediator that automatically manages the complex authentication and tunnel setup processes, eliminating the need for manual configuration at each site while maintaining security through centralized control of the VPN infrastructure
2Reliability
If VPN with manual configuration is used, then data security is improved through encryption, but ease of operation deteriorates due to requiring prior configuration of VPN servers, firewalls, and clients
Solution Approach 1:
The system enables self-service VPN establishment where the central server automatically performs authentication, tunnel creation, and routing configuration based on information provided by remote units. The server autonomously manages the entire VPN setup process without requiring manual intervention at remote sites, making the system as easy to deploy as simple plug-and-play devices while maintaining encrypted security
Solution Approach 2:
The central server pre-configures VPN parameters, authentication credentials, and routing information before remote connections are established. By preparing all necessary configuration elements in advance on the server side, the system eliminates the need for manual configuration at remote sites, allowing units to connect simply by powering on and sending connection requests
3Ease of operation
If automatic VPN establishment is implemented, then ease of operation is improved, but device complexity increases due to requiring central server infrastructure
Solution Approach 1:
The patent consolidates all complex VPN management functions including authentication, tunnel establishment, and routing configuration into a single central server. This merging of functions centralizes complexity in one location while leaving remote units simple and straightforward, achieving automatic setup ease without distributing complexity across multiple devices
4Reliability
If gateway-dependent VPN setup is used, then reliability is improved through controlled access, but adaptability deteriorates due to inability to replace gateways transparently
Solution Approach 1:
The central server acts as an intermediary that abstracts the gateway from the VPN establishment process. By mediating all authentication and connection requests through the server, the system maintains controlled access security while making gateway replacement transparent to the VPN functionality, as the server manages all gateway-related configuration and routing
Data Source
AI summary
The invention relates to a method for establishing a virtual private network between local area networks, each local area network comprising at least one access gateway to a public network and a unit comprising a VPN client, the method comprising the following steps carried out each time a unit is powered on: sending, by the unit, of at least one connection message to an infrastructure connected to the public network and comprising at least one intermediate server, each connection message passing through a respective gateway of the local area network; reception, by the infrastructure, of each connection message; and determination of topology data identifying each bridge of the local area network in which the unit is placed, the method further comprising the following steps carried out for a plurality of units: instancing, by a predetermined intermediate server of the infrastructure, of a VPN server associated with the plurality of units; establishing an encryption tunnel between the VPN server and the VPN client of each unit from the corresponding topology data; and creating and storing routing data representative of a data routing rule between the established encryption tunnels.


