Browser-Based Secure Equipment Access for Overlapping IP Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional remote access methods for IoT/IIoT devices are unsuitable due to shared IP addresses, limited access needs, and the complexity of configuring simultaneous access to multiple devices, especially in industrial settings where devices often share the same IP address and require fine-grained access control.

Innovation Solution

A web browser-based system that provides one-time passwords for secure remote access, allowing dynamic configuration of connections across networks with shared or overlapping IP addresses, using a remote access manager and networking devices to establish secure, fine-grained access without manual firewall reconfiguration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional remote access methods are used, then access to devices is possible, but the system becomes complex and insecure when devices share IP addresses

Engineering Contradiction:
Improveaccess reliabilityVSAvoidaccess configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a web browser-based intermediary interface that mediates between remote users and IoT devices. This intermediary handles the complexity of IP address resolution, connection routing, and authentication centrally, allowing users to access devices without manually configuring network paths or dealing with IP conflicts. The intermediary service resolves device identifiers to actual network addresses and establishes secure connections automatically.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical/manual remote access mechanisms (direct IP connection, manual firewall configuration, SSH clients) with a web-based graphical interface. This substitution eliminates the need for users to manually configure network connections, handle IP addresses directly, or manage firewall rules, thereby reducing operational complexity while maintaining reliable access.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If broad access is provided to all devices, then ease of access is improved, but security control deteriorates

Engineering Contradiction:
Improveaccess easeVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements local quality by providing customized access rights for each user based on their role and requirements. Instead of uniform broad access, the system assigns specific device access permissions, protocol access levels, and operational capabilities to different users. This allows technicians to access only the devices and functions they need, maintaining ease of operation for authorized users while minimizing security risks from over-access.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The access control system is dynamic rather than static. Permissions can be changed in real-time based on user roles, time of day, geographic location, and device status. The system can dynamically grant or revoke access rights without requiring reconfiguration, maintaining both ease of access for authorized users and strong security control through adaptive permission management.

Inventive Principle:
Principle #15Dynamics

3Manufacturing precision

If manual configuration of remote access is performed, then access control precision is improved, but operational overhead increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidconfiguration time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The system performs self-service configuration where the web interface automatically handles connection setup, IP address resolution, firewall rule creation, and authentication. When a user initiates access through the web interface, the system automatically resolves device identifiers, establishes secure connections, and configures routing without requiring manual intervention. This maintains precise access control through automated policy enforcement while eliminating the time-consuming manual configuration process.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-configuring device identifiers, pre-establishing authentication mechanisms, and pre-defining access policies. Before actual access is needed, the system is prepared with device catalogs, authentication credentials, and routing templates. This preliminary setup enables rapid, precise access control without requiring manual configuration at the time of access, significantly reducing operational overhead.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12615250B2Web browser-based secure equipment access
Publication Date: 2026.04.28 CISCO TECHNOLOGY INC
  • US12615250B2 patent drawing
  • US12615250B2 patent drawing
  • US12615250B2 patent drawing

AI summary

In some implementations, a device receives a login request from a web browser executed by a client endpoint in a first network. The device provides a one-time password to the web browser that causes the client endpoint to invoke a local handler process associated with an access service executed by the client endpoint or invoke access by the web browser to a particular uniform resource locator on the device. The device receives a remote connection request from the access service that includes the one-time password to access a target endpoint in a second network. The device configures, based on the remote connection request, a remote access connection between the client endpoint in the first network and the target endpoint in the second network.