Browser-Based Secure Equipment Access for Overlapping IP Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional remote access methods for IoT/IIoT devices are unsuitable due to shared IP addresses, limited access needs, and the complexity of configuring simultaneous access to multiple devices, especially in industrial settings where devices often share the same IP address and require fine-grained access control.
Innovation Solution
A web browser-based system that provides one-time passwords for secure remote access, allowing dynamic configuration of connections across networks with shared or overlapping IP addresses, using a remote access manager and networking devices to establish secure, fine-grained access without manual firewall reconfiguration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional remote access methods are used, then access to devices is possible, but the system becomes complex and insecure when devices share IP addresses
Solution Approach 1:
The patent introduces a web browser-based intermediary interface that mediates between remote users and IoT devices. This intermediary handles the complexity of IP address resolution, connection routing, and authentication centrally, allowing users to access devices without manually configuring network paths or dealing with IP conflicts. The intermediary service resolves device identifiers to actual network addresses and establishes secure connections automatically.
Solution Approach 2:
The patent replaces traditional mechanical/manual remote access mechanisms (direct IP connection, manual firewall configuration, SSH clients) with a web-based graphical interface. This substitution eliminates the need for users to manually configure network connections, handle IP addresses directly, or manage firewall rules, thereby reducing operational complexity while maintaining reliable access.
2Ease of operation
If broad access is provided to all devices, then ease of access is improved, but security control deteriorates
Solution Approach 1:
The patent implements local quality by providing customized access rights for each user based on their role and requirements. Instead of uniform broad access, the system assigns specific device access permissions, protocol access levels, and operational capabilities to different users. This allows technicians to access only the devices and functions they need, maintaining ease of operation for authorized users while minimizing security risks from over-access.
Solution Approach 2:
The access control system is dynamic rather than static. Permissions can be changed in real-time based on user roles, time of day, geographic location, and device status. The system can dynamically grant or revoke access rights without requiring reconfiguration, maintaining both ease of access for authorized users and strong security control through adaptive permission management.
3Manufacturing precision
If manual configuration of remote access is performed, then access control precision is improved, but operational overhead increases
Solution Approach 1:
The system performs self-service configuration where the web interface automatically handles connection setup, IP address resolution, firewall rule creation, and authentication. When a user initiates access through the web interface, the system automatically resolves device identifiers, establishes secure connections, and configures routing without requiring manual intervention. This maintains precise access control through automated policy enforcement while eliminating the time-consuming manual configuration process.
Solution Approach 2:
The system performs preliminary actions by pre-configuring device identifiers, pre-establishing authentication mechanisms, and pre-defining access policies. Before actual access is needed, the system is prepared with device catalogs, authentication credentials, and routing templates. This preliminary setup enables rapid, precise access control without requiring manual configuration at the time of access, significantly reducing operational overhead.
Data Source
AI summary
In some implementations, a device receives a login request from a web browser executed by a client endpoint in a first network. The device provides a one-time password to the web browser that causes the client endpoint to invoke a local handler process associated with an access service executed by the client endpoint or invoke access by the web browser to a particular uniform resource locator on the device. The device receives a remote connection request from the access service that includes the one-time password to access a target endpoint in a second network. The device configures, based on the remote connection request, a remote access connection between the client endpoint in the first network and the target endpoint in the second network.


