VPN Gateway Virtual Core Network Secure Data Center Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Establishing a secure connection between a data center and a terminal connected via a wireless LAN and a wide area network, such as the Internet, is challenging due to the interposition of a wide area network, which requires secure and reliable communication protocols to ensure data integrity and privacy.

Innovation Solution

A communication system utilizing a VPN apparatus to establish a Virtual Private Network (VPN) connection between the terminal and the data center through the wireless LAN and the wide area network, with a virtual core network virtualizing core network elements, enabling secure communication via the VPN and packet data networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a VPN connection is established through a wide area network and wireless LAN, then secure communication is achieved, but connection complexity and establishment time increase

Engineering Contradiction:
Improvesecure communicationVSAvoidconnection complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway as an intermediary component that simplifies VPN connection establishment. The gateway automatically performs authentication with the authentication server and establishes the VPN tunnel, shielding the terminal from complex connection procedures. This mediator approach resolves the contradiction by maintaining security through VPN while reducing connection complexity for end users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication and VPN establishment actions through the gateway before the terminal needs to access secure resources. By pre-establishing the VPN connection and authentication credentials through the gateway, the terminal can connect quickly without undergoing complex authentication procedures each time, thus maintaining security while reducing connection establishment time and complexity.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If VPN authentication and encryption are implemented, then data security is improved, but processing time and computational overhead increase

Engineering Contradiction:
Improvedata securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication and encryption key exchange are performed in advance through the gateway before actual data transmission. The terminal establishes security credentials once through the gateway, and subsequent communications use pre-established encryption parameters, reducing processing time for each data transmission while maintaining strong security through VPN encryption and authentication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The gateway acts as a mediator that handles computationally intensive authentication and encryption operations. By offloading these security-critical but time-consuming operations to the gateway infrastructure rather than the terminal device, the system maintains high data security through proper VPN encryption while reducing processing time and computational overhead on the terminal side.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If a virtual core network is introduced to manage VPN connections, then network management flexibility is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork management flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the network management functions by introducing a virtual core network that separates control plane functions from user plane functions. The virtual core network handles authentication, authorization, and VPN management independently from data transmission, providing flexible network management while keeping the terminal device simple. This segmentation allows complex management capabilities without increasing terminal complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtual core network acts as an intermediary layer between the terminal and the wide area network infrastructure. It manages VPN connections, authentication, and routing flexibly without requiring the terminal to understand or handle these complex functions directly. This mediator approach provides network management flexibility while maintaining terminal simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10764088B2Communication system, communication apparatus, communication method, terminal, non-transitory medium
Publication Date: 2020.09.01 NEC CORP
  • US10764088B2 patent drawing
  • US10764088B2 patent drawing
  • US10764088B2 patent drawing

AI summary

The present invention provides secure communication between a data center, in which a wide area network (WAN) is interposed between the data center and a wireless LAN to which a terminal connects to, comprises a VPN apparatus (GW) that connects with the terminal using a VPN through the wide area network and the wireless LAN; and a virtual core network virtualizing at least a part of constituent elements of a core network, wherein the VPN apparatus is connected to the virtual core network, and the terminal communicates with a connection destination, from the VPN via the VPN apparatus, via the virtual core network, and further via a packet data network to which the virtual core network connects.