Security Proxy VPN Protocol Conversion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional VPNs do not support both IP VPN and SSL VPN protocols, requiring both endpoints to use the same type of VPN protocol to establish a tunnel, limiting compatibility and accessibility across different devices and networks.

Innovation Solution

The implementation of a security proxy system that converts mobile traffic between different VPN protocols, such as IP VPN and TCP VPN, using a tunnel plug-in and a security proxy that manages, encrypts, and secures traffic, allowing devices to use various VPN protocols for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If both endpoints use the same type of VPN protocol (IP VPN or TCP VPN), then secure tunnel establishment is achieved, but compatibility across different devices and networks is limited

Engineering Contradiction:
Improvesecure tunnel establishmentVSAvoidcompatibility across different devices and networks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a gateway as an intermediary component that supports both IP VPN and TCP VPN protocols. The gateway acts as a protocol translator, receiving connections from clients using either protocol type and forwarding them to the backend network. This mediator approach allows endpoints with different protocol requirements to communicate securely without requiring both endpoints to use the same protocol, thus resolving the contradiction between reliable tunnel establishment and cross-device compatibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a corporate intranet accommodates only Internet layer VPN, then IP VPN security is maintained, but Transport layer VPN access is blocked and vice versa

Engineering Contradiction:
ImproveIP VPN securityVSAvoidTransport layer VPN access
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The gateway is designed with multi-functionality to support both IP VPN and TCP VPN protocols simultaneously. It can accept connections from clients using either protocol type, translate them appropriately, and forward to the backend network. This universal design allows the corporate intranet to maintain IP VPN security while also providing Transport layer VPN access, enabling diverse devices and networks to connect according to their capabilities without compromising security protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10193865B2Converting mobile traffic between IP VPN and transport level VPN
Publication Date: 2019.01.29 IVANTI INC
  • US10193865B2 patent drawing
  • US10193865B2 patent drawing
  • US10193865B2 patent drawing

AI summary

Techniques described herein convert mobile traffic between different types of VPN protocols, including IP and Transport. In an embodiment, a security proxy associated with a server receives a packet associated with a client app on a device, the packet including a source identifier and a destination identifier. The security proxy reassigns a tunnel identifier as the source and a node identifier as the destination, then stores a correlation of the tunnel identifier, the source identifier, and the destination identifier. The security proxy forwards the packet to the node inside the security proxy, and determines the destination identifier based on the correlation. The node then forwards the packet to the destination. This allows for multiple devices to use a same source identifier, e.g., same IP address. In some embodiments, a secure connection is established and/or the device and server are mutually authenticated prior to the processing of the packets.