VPN Management Server Dynamic Topology Configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing VPN solutions with full-mesh topologies consume excessive resources and are inflexible, requiring more licenses and struggling to adapt to changing network conditions, especially in mobile networks.
Innovation Solution
A VPN management server determines VPN connection topologies among multiple VPN gateways, configuring them to establish connections efficiently based on available licenses and priorities, allowing for hub-and-spoke, partial-mesh, or full-mesh topologies, and dynamically updates configurations based on network status and resource availability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If full-mesh topology is implemented for VPN connections among all VPN gateways, then redundancy and availability are improved, but computing resources and network resources are excessively consumed
Solution Approach 1:
The patent implements dynamic topology selection where the VPN management server determines the optimal VPN connection topology based on real-time network conditions and gateway capabilities. The system can switch between different topologies (full-mesh, partial-mesh, hub-and-spoke) depending on factors like network status, gateway resources, and licensing constraints, thereby resolving the contradiction between maintaining high reliability and reducing resource consumption.
Solution Approach 2:
The system changes the topology parameter dynamically by selecting different connection configurations based on network conditions. When network conditions are stable and resources are available, full-mesh topology may be used for maximum reliability. When resources are constrained or network conditions change, the system transitions to partial-mesh or hub-and-spoke topologies, adjusting the connectivity parameters to balance reliability with resource efficiency.
2Reliability
If full-mesh topology is implemented to increase redundancy and availability, then VPN connection reliability is improved, but the number of VPN licenses required increases
Solution Approach 1:
The patent applies partial action by implementing partial-mesh topology where not all VPN gateways establish connections with every other gateway. Instead of full-mesh connectivity, the system creates a subset of necessary connections that provide sufficient availability without requiring licenses for all possible connections. This partial connectivity approach reduces the total number of licenses needed while maintaining acceptable service levels.
Solution Approach 2:
The VPN management server dynamically determines the optimal topology based on current network conditions and gateway licensing status. When licenses are abundant, full-mesh may be implemented. When licenses are constrained, the system dynamically adjusts to partial-mesh or hub-and-spoke configurations, optimizing the balance between availability and license consumption in real-time.
3Device complexity
If static VPN connection topology is used, then configuration simplicity is maintained, but adaptability to changing network conditions is reduced
Solution Approach 1:
The patent implements a dynamic configuration management system where the VPN management server continuously monitors network conditions and gateway status. Based on this real-time information, the server automatically adjusts VPN connection topologies and configurations. This dynamic approach maintains configuration simplicity from the user perspective while providing high adaptability to changing network conditions, resolving the contradiction between simplicity and adaptability.
Solution Approach 2:
The system incorporates feedback mechanisms where status information from VPN gateways is received and processed by the VPN management server. This feedback loop enables the system to detect network condition changes and automatically update configurations accordingly. The feedback-driven approach maintains simple user configuration while achieving high adaptability through automated responses to changing conditions.
Data Source
AI summary
The present invention discloses methods for establishing Virtual Private Network (VPN) connections among a plurality of VPN gateways at a VPN management server. The VPN management server determines VPN gateways belonging to a first VPN gateway group and also determines the number of possible VPN connections for each VPN gateway of the first VPN gateway group. Configuration for each VPN gateway of the first VPN gateway group is determined based on, at least in part, a VPN connection topology and the number of VPN connection license(s). Each VPN gateway of the first VPN gateway group is configured according to the configuration and a plurality of VPN connections is established based on, at least in part, the configurations.


