Transparent VPN Mode Switching Without Session Termination

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VPN technologies require users to manually terminate and re-establish sessions when switching between different access modes, which is inconvenient and time-consuming, especially when transitioning from a limited capability mode to a more secure enterprise mode.

Innovation Solution

A method for dynamically switching between VPN modes without disconnecting the SSL VPN session, by verifying administrative privileges and reconfiguring the session to enhance security permissions transparently, allowing continued access without additional user authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a user switches from limited capability mode to full capability mode by terminating and manually initiating a second VPN session, then additional security permissions are obtained, but time is lost and user convenience deteriorates

Engineering Contradiction:
Improvesecurity permissionsVSAvoidsession termination and re-establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system dynamically adjusts VPN session parameters by allowing mode transitions within an active session. The connection manager enables users to switch between limited and full capability modes without terminating the session, making the session adaptable to changing security requirements while maintaining continuity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The invention changes the operational parameters of the VPN session by modifying access permissions and security levels dynamically. When a user requests a mode switch, the system adjusts the session parameters to grant appropriate permissions without requiring complete re-authentication, thus saving time while maintaining security integrity.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If manual re-authentication is required when switching VPN modes, then security is maintained, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidmode switching convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication during the initial VPN session establishment. This preliminary auth allows the user to switch between modes without repeating the full authentication process, as the initial credentials have already been verified and stored for permission adjustments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The connection manager automatically handles the permission adjustment process when a user requests a mode switch. The system self-services the authentication by verifying the user's identity against stored credentials and automatically granting appropriate permissions without requiring manual re-authentication intervention.

Inventive Principle:
Principle #25Self-service

3Reliability

If a VPN session is terminated to switch modes, then security permissions are reset, but session continuity is lost

Engineering Contradiction:
Improvesecurity permissionsVSAvoidsession continuity
Core Design Contradiction:
ReliabilityVSDuration of action of stationary object

Solution Approach 1:

The VPN session is designed to be dynamic rather than static, allowing permission levels to change during the session lifecycle. The connection manager monitors and adjusts session parameters in real-time based on user requests, enabling mode transitions without session termination and maintaining continuous connectivity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The invention maintains continuous VPN session connectivity throughout the mode switching process. By keeping the session active and only adjusting permission parameters, the system ensures uninterrupted network connectivity and eliminates the need to re-establish the tunnel, thus preserving session continuity while changing security levels.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS9077686B2Techniques for secure transparent switching between modes of a virtual private network (VPN)
Publication Date: 2015.07.07 ORACLE INT CORP
  • US9077686B2 patent drawing
  • US9077686B2 patent drawing
  • US9077686B2 patent drawing

AI summary

Techniques for secure transparent switching between modes of a virtual private network (VPN) are provided. A principal, via a client, establishes a VPN session in a first mode of operation with a server. The principal subsequently requests a second mode of operation during the same VPN session. The VPN session is transparently transitioned to the second mode of operation without any interaction being required on the part of the principal and without terminating the original VPN session.