VPN Relay Nodes for Wireless Access Without System Administration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing VPN technologies require system-level administration rights and configuration as access points for relaying, limiting accessibility and flexibility, especially in wireless networks.
Innovation Solution
A method utilizing a relay node connected to both a local network and a wireless access network to establish a VPN tunnel through encapsulation and relaying of traffic via UDP communication links, allowing client nodes to access remote networks without requiring configuration as access points and enabling multipath VPN tunnels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If existing VPN technologies are used to establish a VPN tunnel, then secure network access is achieved, but system-level administration rights and configuration as access points are required, limiting accessibility and flexibility
Solution Approach 1:
The patent introduces a relay node as an intermediary component that mediates between the client node and the VPN server. The relay node establishes separate transport layer communication links with both the client node and the VPN server, enabling the VPN tunnel to function without requiring the client node to have system-level administration rights or to be configured as an access point. This intermediary approach resolves the contradiction by maintaining security while improving accessibility.
2Adaptability or versatility
If a relay node is configured as an access point to provide VPN relaying, then network access is enabled, but system-level administration rights are required, reducing flexibility
Solution Approach 1:
The relay node serves as a mediator that performs VPN relaying functionality without requiring access point configuration or system-level administration rights. It establishes transport layer communication links using standard protocols that can be implemented at the application level, enabling flexible deployment in diverse network environments including wireless networks without complex configuration.
Solution Approach 2:
The relay node is designed with multi-functionality, capable of operating in various network environments (wired and wireless networks) without requiring specific access point configuration. It can function as a general-purpose relaying device that works across different network types and configurations, improving deployment flexibility while maintaining ease of operation through standardized protocols.
3Speed
If direct VPN tunnel establishment is used, then connection speed is maintained, but accessibility to remote networks via wireless access networks is limited
Solution Approach 1:
The relay node acts as an intermediary that enables client nodes to access remote networks via wireless access networks while maintaining connection speed. By establishing separate transport layer communication links between the client node-relay node and relay node-VPN server, the system achieves both wireless accessibility and efficient data transmission without the limitations of direct tunnel establishment.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method for providing a client node access to a remote network via a VPN tunnel to a VPN server; wherein the client node is connected to a local network; wherein a relay node is connected to the local network over a first communication interface, and to a wireless access network over a wireless communication interface; the method comprising: exchanging traffic between the client node and the first communication interface of the relay node, by encapsulating the traffic as VPN traffic of the VPN tunnel, and exchanging the VPN traffic as payload over a first transport layer communication link between the client node and the relay node; relaying the payload over a second transport layer communication link between the wireless communication interface and the VPN server; and exchanging, by the VPN server, the traffic between the VPN tunnel and the remote network.