Secure VPN Gateway Management via Three-Domain Separation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current virtual private network (VPN) management systems are insecure due to the risk of eavesdropping and interception, particularly when managing and configuring VPN devices across different entities, as they lack robust security measures to prevent leakage of sensitive information, and existing solutions are cumbersome and inflexible, making them unsuitable for dynamic environments.

Innovation Solution

Introducing a three-domain separation model for VPN management, where a third administrative domain is created for secure management and configuration, accessible only through a dedicated gateway, ensuring cryptographically separated and tunnelled communication to prevent unauthorized access and enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional VPN management is used, then device functionality is maintained, but security is compromised due to lack of separation between management and data domains

Engineering Contradiction:
ImprovesecurityVSAvoiddomain separation structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the network into three distinct domains: red network domain for user data, black network domain for transport, and administrative domain for management. This segmentation isolates management traffic from data traffic, preventing eavesdropping and interception while maintaining clear functional separation. The administrative domain can only access VPN devices through dedicated management channels, not through user data channels.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an administration gateway as an intermediary component that mediates between the administrative domain and the red/black network domains. This gateway handles all management communications, ensuring that administrators can configure and monitor VPN devices without gaining access to encrypted user data or the transport network, thus maintaining security while enabling management functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If VPN devices are made manageable through centralized administration, then ease of operation improves, but risk of information leakage increases if management access is not properly restricted

Engineering Contradiction:
Improvecentralized managementVSAvoiddata leakage risk
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The administrative domain is segmented from the red and black network domains, creating isolated management channels. This segmentation ensures that centralized administration can operate conveniently while the domain separation prevents any possibility of management personnel accessing or leaking user data, as management traffic is completely isolated from data traffic paths.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts management functionality into a separate administrative domain that is independent from the data handling domains. This extraction allows management operations to be centralized and simplified while removing the risk of information leakage by ensuring management personnel can only access what is necessary for device management, not user data.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If encryption is applied to data traffic, then security against eavesdropping improves, but complexity of implementation and resource requirements increase

Engineering Contradiction:
Improvedata protectionVSAvoidencryption implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments encryption into two distinct layers: data encryption for user traffic between red networks, and management encryption for administrative communications. This segmentation allows each encryption mechanism to be optimized independently, reducing overall complexity while maintaining strong protection for both data and management channels.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The administration gateway acts as an intermediary that handles encryption for management traffic separately from data encryption handled by VPN devices. This intermediary approach distributes encryption responsibilities, reducing the burden on individual devices while maintaining comprehensive data protection across all traffic types.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If access control is restricted to authorized personnel only, then security improves, but operational flexibility and adaptability decrease

Engineering Contradiction:
Improveaccess securityVSAvoidoperational flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments access control into domain-level permissions rather than individual user permissions. The administrative domain is segmented to allow authorized personnel to perform management functions without needing to access specific data or configure complex individual permissions. This domain-based segmentation maintains strong security while providing operational flexibility through clear role separation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The administration gateway provides universal access control for the administrative domain, allowing authorized personnel to perform multiple management functions through a single interface. This multi-functionality maintains security through centralized authentication while providing operational flexibility by consolidating access rights rather than dispersing them across multiple individual permissions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9015825B2Method and device for network communication management
Publication Date: 2015.04.21 BUSINESS SECURITY OL
  • US9015825B2 patent drawing
  • US9015825B2 patent drawing
  • US9015825B2 patent drawing

AI summary

Method and device for managing one or more secure gateway virtual private network, VPN, devices (104, 105) in a secure VPN for cryptographically separated and tunnelled VPN communication. VPN configuration data provided by a management system (110) is received (401); and the received VPN configuration data and a domain type encapsulating (402,403), wherein said domain type identifying an administrative network domain for cryptographically separated and tunnelled management communication with a hardware separated administrative controller (121) of said one or more secure gateway VPN devices (104, 105), exclusively for management of said one or more secure gateway VPN devices (104, 105).