VPN Control Device Automates Gateway IP Assignment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The configuration of IP addresses for VPN gateways in IP camera terminals is labor-intensive and prone to errors, especially when managing thousands of terminals across different areas, leading to potential security vulnerabilities and operational inefficiencies.

Innovation Solution

A method and system where a VPN control device receives handshake messages from router gateways to authenticate terminals and determine the appropriate VPN gateway IP addresses, reducing the workload by centralizing the configuration of VPN gateways and enhancing security through SSL session management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IP addresses of VPN gateways are manually configured for each terminal, then connection management is straightforward, but workload is heavy and errors are easy to occur when managing thousands of terminals

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidconfiguration efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The terminal automatically obtains the VPN gateway IP address through authentication with the VPN control device, eliminating the need for manual configuration. The system self-services by having terminals dynamically acquire configuration parameters through the authentication process, thereby reducing both workload and errors in managing thousands of terminals

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The VPN control device acts as an intermediary between terminals and VPN gateways. It receives authentication requests from terminals, determines the appropriate VPN gateway based on terminal location and authentication results, and returns the corresponding IP address. This intermediary mechanism automates the configuration process while ensuring accurate matching between terminals and their designated gateways

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If VPN gateway is deployed on router gateway in bypass mode, then network security is improved, but configuration complexity increases due to independent subnet management

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The VPN control device performs multiple functions: it authenticates terminals, determines appropriate VPN gateways, and provides configuration parameters. This multi-functional approach consolidates what would otherwise be separate configuration tasks, reducing overall system complexity while maintaining the security benefits of bypass mode deployment

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If different IP addresses are configured for VPN gateways managing different areas, then area-specific management is enabled, but workload increases during terminal deployment

Engineering Contradiction:
Improvearea management capabilityVSAvoiddeployment efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system incorporates feedback mechanisms where the VPN control device receives terminal identification information, determines the terminal's location area, and based on this feedback, automatically selects the appropriate VPN gateway IP address. This feedback loop enables area-specific management without manual intervention, as the system automatically adapts its configuration based on terminal location

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11165604B2Method and system used by terminal to connect to virtual private network, and related device
Publication Date: 2021.11.02 HUAWEI TECH CO LTD
  • US11165604B2 patent drawing
  • US11165604B2 patent drawing
  • US11165604B2 patent drawing

AI summary

A method and a system used by a terminal to connect to a virtual private network (VPN), and a related device to resolve a problem that workload is heavy and an error is easy to occur currently during configuration of an Internet Protocol (IP) address of a VPN gateway for a terminal. A VPN control device is responsible for authenticating access of the terminal, and determining a VPN gateway to which the terminal is allowed to connect. When an IP address of the VPN control device is configured for all terminals in a system, terminal security authentication can be implemented.