VPN Server Memory Segmentation for Security and Stability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current VPN server configurations are vulnerable to unauthorized access and configuration drift due to the use of non-volatile memory for storing and executing the VPN operating system, which can lead to compromised sensitive information and operational disruptions.

Innovation Solution

The proposed solution involves retrieving an initial operating system from non-volatile memory, storing it in volatile memory, and executing it to obtain and store a VPN operating system, thereby eliminating the need for non-volatile memory storage and execution, enhancing security and preventing configuration drift.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the VPN operating system is stored and executed from non-volatile memory, then the server can maintain persistent storage and boot capability, but the system becomes vulnerable to unauthorized access and configuration drift

Engineering Contradiction:
ImprovesecurityVSAvoidmemory configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the memory system into non-volatile memory (for initial OS and configuration) and volatile memory (for VPN OS execution). This segmentation allows the system to maintain boot capability while isolating the VPN operating system in volatile memory, preventing unauthorized access and configuration drift by discarding data on reboot.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where the initial operating system loaded from non-volatile memory acts as a mediator to load and execute the VPN operating system in volatile memory. This intermediary layer enables the system to boot and operate the VPN service without storing the VPN OS in persistent storage, thereby enhancing security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the VPN operating system is stored in non-volatile memory, then the system can maintain configuration persistence, but configuration drift and unauthorized modifications occur

Engineering Contradiction:
Improveconfiguration stabilityVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent employs the principle of disposable short-living objects by using volatile memory for the VPN operating system. The VPN OS and its configuration exist only temporarily during operation and are automatically discarded upon reboot, preventing unauthorized access and configuration drift while maintaining operational functionality.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent applies preliminary action by pre-loading the initial operating system from non-volatile memory before executing the VPN operating system in volatile memory. This preliminary step ensures that the system can boot and establish secure memory management before the VPN service begins, preventing configuration drift from the outset.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If volatile memory is used for VPN operating system execution, then security is enhanced by discarding data on reboot, but memory resources are consumed during operation

Engineering Contradiction:
ImprovesecurityVSAvoidmemory resource utilization
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent changes the parameter of memory persistence from non-volatile to volatile for the VPN operating system. This parameter change enhances security by ensuring data is discarded on reboot, while the system manages memory resources efficiently by allocating volatile memory only during active VPN service operation.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11991151B2Configuration of a virtual private network server
Publication Date: 2024.05.21 UAB 360 IT
  • US11991151B2 patent drawing
  • US11991151B2 patent drawing
  • US11991151B2 patent drawing

AI summary

A method including configuring, by an infrastructure device, a virtual private network (VPN) server to receive, while executing an initial operating system, a primary VPN operating system; configuring, by the infrastructure device, the VPN server to receive, while executing the primary VPN operating system, custom parameters associated with the VPN server providing VPN services; configuring, by the infrastructure device, the VPN server to determine a VPN operating system based at least in part on configuring the primary VPN operating system with the custom parameters; and configuring, by the infrastructure device, the VPN server to execute the VPN operating system to provide the VPN services. Various other aspects are contemplated.