Dynamic VPN Server Rotation for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Static VPN IP addresses make it easier for hackers to monitor and target corporate networks, increasing the likelihood of cyber-attacks, as they can correlate IP addresses with specific users and enterprises.

Innovation Solution

Implementing a system that dynamically changes VPN servers based on traffic type and predetermined conditions, using a computer-implemented method and system to manage web traffic, select VPN servers, create policies for routing traffic, and provision VPN servers for a limited time to enhance security and prevent cyber-attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If static VPN IP addresses are used, then ease of operation is improved, but network security deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic IP address assignment where VPN servers are automatically replaced after predetermined conditions are met (time-based or traffic-volume-based). This transforms the static IP configuration into a dynamic system that automatically changes addresses, maintaining ease of operation while significantly improving network security by preventing hackers from correlating IP addresses with specific users or enterprises over time.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the IP address parameter of the VPN server based on predetermined conditions. When a VPN server has been in use for a certain time period or has handled a certain volume of traffic, the system automatically assigns a new IP address to a different VPN server, thereby changing the network identity parameter to enhance security while maintaining operational simplicity.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If VPN servers are frequently replaced, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements an automated system where the network infrastructure itself manages the VPN server replacement process. The system automatically monitors usage conditions, selects appropriate VPN servers from the pool, assigns IP addresses, and handles the switching without requiring manual intervention or complex configuration management, thereby reducing operational complexity despite frequent server replacements.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-configures multiple VPN servers with different IP addresses in advance. When a VPN server needs to be replaced, the system can immediately switch to a pre-prepared server from the pool, avoiding the complexity of real-time server provisioning and configuration. This preliminary preparation simplifies the replacement process while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If VPN servers are provisioned for limited time, then network security is improved, but productivity decreases

Engineering Contradiction:
Improvenetwork securityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements periodic replacement of VPN servers based on time-based predetermined conditions. VPN servers are assigned to users for specific time periods and then automatically replaced with new servers. This periodic action maintains network security by preventing long-term correlation of IP addresses with users, while the automated nature of the process minimizes disruption to productivity.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11700281B2Methods and systems for enhancing cyber security in networks
Publication Date: 2023.07.11 CACI LGS INNOVATIONS LLC
  • US11700281B2 patent drawing
  • US11700281B2 patent drawing
  • US11700281B2 patent drawing

AI summary

The present application is directed a computer-implemented technique for enhancing security and preventing cyber-attacks on a network. The technique includes receiving information from user equipment, selecting a first VPN server from a VPN service provider based upon a traffic-type of the user equipment, creating a policy to prevent cyber-attacks such that traffic associated with the received information of the user equipment is routed to the first VPN server, provisioning the first VPN server to last a predetermined amount of time based on the policy, coordinating the policy with a router on the network, with the traffic being sent to the VPN server via the router, and sending, after a predetermined condition is met, a request to the VPN service provider to transmit a second VPN server, and where the first VPN server terminates.