Security Proxy VPN Protocol Conversion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional VPNs do not support both IP VPN and SSL VPN protocols, requiring both endpoints to use the same type of VPN protocol to establish a tunnel, limiting compatibility and accessibility across different devices and networks.
Innovation Solution
The implementation of a security proxy system that converts mobile traffic between different VPN protocols, such as IP VPN and TCP VPN, using a tunnel plug-in and a security proxy that manages, encrypts, and secures traffic, allowing devices to use various VPN protocols for secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If both endpoints use the same type of VPN protocol (IP VPN or TCP VPN), then secure tunnel establishment is achieved, but compatibility across different devices and networks is limited
Solution Approach 1:
The patent introduces a gateway as an intermediary component that supports both IP VPN and TCP VPN protocols. The gateway acts as a protocol translator, receiving connections from clients using either protocol type and forwarding them to the backend network. This mediator approach allows endpoints with different protocol requirements to communicate securely without requiring both endpoints to use the same protocol, thus resolving the contradiction between reliable tunnel establishment and cross-device compatibility.
2Reliability
If a corporate intranet accommodates only Internet layer VPN, then IP VPN security is maintained, but Transport layer VPN access is blocked and vice versa
Solution Approach 1:
The gateway is designed with multi-functionality to support both IP VPN and TCP VPN protocols simultaneously. It can accept connections from clients using either protocol type, translate them appropriately, and forward to the backend network. This universal design allows the corporate intranet to maintain IP VPN security while also providing Transport layer VPN access, enabling diverse devices and networks to connect according to their capabilities without compromising security protocols.
Data Source
AI summary
Techniques described herein convert mobile traffic between different types of VPN protocols, including IP and Transport. In an embodiment, a security proxy associated with a server receives a packet associated with a client app on a device, the packet including a source identifier and a destination identifier. The security proxy reassigns a tunnel identifier as the source and a node identifier as the destination, then stores a correlation of the tunnel identifier, the source identifier, and the destination identifier. The security proxy forwards the packet to the node inside the security proxy, and determines the destination identifier based on the correlation. The node then forwards the packet to the destination. This allows for multiple devices to use a same source identifier, e.g., same IP address. In some embodiments, a secure connection is established and/or the device and server are mutually authenticated prior to the processing of the packets.


