Multi-Channel VPN Orchestration with Segmented Routing Tables
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current VPN technologies lack an intelligent mechanism to dynamically manage and prioritize traffic across multiple VPN gateways, leading to inefficiencies when multiple devices and applications connect to different VPN networks, especially when they share the same network prefix, resulting in suboptimal performance and potential subnet conflicts.
Innovation Solution
A client device maintains separate VPN routing tables for each VPN, allowing simultaneous active VPN tunnels to subnetworks sharing the same network prefix, with a VPN orchestration engine that dynamically manages and coordinates traffic across these tunnels based on quality of service (QoS) and application requirements, using a shared VPN profile for seamless connectivity across devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a static routing table is used to decide where outbound traffic should be sent, then the system is simple to implement, but the VPN traffic management becomes inefficient when multiple VPNs are active simultaneously
Solution Approach 1:
The patent divides the routing table into multiple separate VPN-specific routing tables, with each routing table dedicated to a specific VPN connection. This segmentation allows the system to efficiently manage traffic for each VPN independently while maintaining overall system performance, resolving the contradiction between productivity and complexity.
2Productivity
If multiple VPN tunnels are established simultaneously to subnetworks with the same network prefix, then bandwidth utilization and load balancing improve, but subnet conflicts may occur
Solution Approach 1:
The patent segments the routing information by creating distinct routing tables for each VPN, allowing simultaneous connections to subnetworks with identical network prefixes. Each routing table contains VPN-specific routes that prevent conflicts by ensuring traffic is directed through the correct VPN tunnel based on the destination and VPN association.
Solution Approach 2:
The system implements feedback mechanisms where the VPN orchestration engine monitors active VPN tunnels and dynamically adjusts routing decisions. When multiple VPNs are active, the system receives feedback about tunnel status and network conditions, then intelligently routes traffic to optimize bandwidth utilization while preventing subnet conflicts through real-time coordination.
3Ease of operation
If a single VPN gateway is used for all connections, then the system configuration is simple, but the user experience becomes slower and less seamless when multiple devices and applications need VPN access
Solution Approach 1:
The patent segments VPN gateway management by allowing multiple VPN gateways to be configured and managed independently. Each gateway can be optimized for specific purposes (e.g., work VPN, personal VPN, regional VPNs), enabling seamless switching and simultaneous connections. This segmentation improves user experience by allowing applications to automatically connect to the most appropriate gateway without requiring complex user configuration.
Solution Approach 2:
The system implements self-service capabilities where applications and the operating system automatically select and connect to appropriate VPN gateways based on pre-configured routing tables. Users do not need to manually manage which VPN to use for each application; the system autonomously makes routing decisions based on destination IP addresses and VPN associations, improving ease of operation while managing multiple gateways efficiently.
Data Source
AI summary
A respective VPN routing table for each of a plurality of VPNs can be stored on a client device. The client device can access a first VPN routing table and, using the first VPN routing table, establish a first VPN tunnel to a first VPN. The first VPN can be a first subnetwork assigned a particular network prefix. While the first VPN tunnel is currently active, the client device can access a second VPN routing table and, using the second VPN routing table, establish a second VPN tunnel to the second VPN. The second VPN can be a second subnetwork assigned the same particular network prefix as the first subnetwork. While the first VPN tunnel and the second VPN tunnel are simultaneously active, the client device can communicate data to remote devices in the first VPN and the second VPN using the particular network prefix for both.


