VPN Gateway Virtual Core Network Secure Data Center Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing a secure connection between a data center and a terminal connected via a wireless LAN and a wide area network, such as the Internet, is challenging due to the interposition of a wide area network, which requires secure and reliable communication protocols to ensure data integrity and privacy.
Innovation Solution
A communication system utilizing a VPN apparatus to establish a Virtual Private Network (VPN) connection between the terminal and the data center through the wireless LAN and the wide area network, with a virtual core network virtualizing core network elements, enabling secure communication via the VPN and packet data networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a VPN connection is established through a wide area network and wireless LAN, then secure communication is achieved, but connection complexity and establishment time increase
Solution Approach 1:
The patent introduces a gateway as an intermediary component that simplifies VPN connection establishment. The gateway automatically performs authentication with the authentication server and establishes the VPN tunnel, shielding the terminal from complex connection procedures. This mediator approach resolves the contradiction by maintaining security through VPN while reducing connection complexity for end users.
Solution Approach 2:
The system performs preliminary authentication and VPN establishment actions through the gateway before the terminal needs to access secure resources. By pre-establishing the VPN connection and authentication credentials through the gateway, the terminal can connect quickly without undergoing complex authentication procedures each time, thus maintaining security while reducing connection establishment time and complexity.
2Reliability
If VPN authentication and encryption are implemented, then data security is improved, but processing time and computational overhead increase
Solution Approach 1:
Authentication and encryption key exchange are performed in advance through the gateway before actual data transmission. The terminal establishes security credentials once through the gateway, and subsequent communications use pre-established encryption parameters, reducing processing time for each data transmission while maintaining strong security through VPN encryption and authentication.
Solution Approach 2:
The gateway acts as a mediator that handles computationally intensive authentication and encryption operations. By offloading these security-critical but time-consuming operations to the gateway infrastructure rather than the terminal device, the system maintains high data security through proper VPN encryption while reducing processing time and computational overhead on the terminal side.
3Adaptability or versatility
If a virtual core network is introduced to manage VPN connections, then network management flexibility is improved, but system complexity increases
Solution Approach 1:
The patent segments the network management functions by introducing a virtual core network that separates control plane functions from user plane functions. The virtual core network handles authentication, authorization, and VPN management independently from data transmission, providing flexible network management while keeping the terminal device simple. This segmentation allows complex management capabilities without increasing terminal complexity.
Solution Approach 2:
The virtual core network acts as an intermediary layer between the terminal and the wide area network infrastructure. It manages VPN connections, authentication, and routing flexibly without requiring the terminal to understand or handle these complex functions directly. This mediator approach provides network management flexibility while maintaining terminal simplicity.
Data Source
AI summary
The present invention provides secure communication between a data center, in which a wide area network (WAN) is interposed between the data center and a wireless LAN to which a terminal connects to, comprises a VPN apparatus (GW) that connects with the terminal using a VPN through the wide area network and the wireless LAN; and a virtual core network virtualizing at least a part of constituent elements of a core network, wherein the VPN apparatus is connected to the virtual core network, and the terminal communicates with a connection destination, from the VPN via the VPN apparatus, via the virtual core network, and further via a packet data network to which the virtual core network connects.


