Central Server VPN for Secure LAN Device Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for accessing and controlling networked devices within a secure LAN from outside the LAN, such as security cameras and monitoring devices, require complex port forwarding and VPN configurations, which are resource-intensive, increase security risks, and limit the number of devices that can be connected, making it difficult for smaller enterprises to manage their network security effectively.

Innovation Solution

A system utilizing a central server to establish a multi-pipe virtual private network (MVPN) that connects multiple web-enabled end-user devices inside a secure LAN to a monitor controller outside the LAN, eliminating the need for port forwarding and enabling secure, simultaneous access to multiple devices using a single address at the edge router, while acting as a facilitator for secure data transmission and system health monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If port forwarding is used to enable external access to devices inside the secure LAN, then connectivity to security devices is achieved, but security risks increase and device complexity increases

Engineering Contradiction:
Improveconnectivity to security devicesVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

A central server is introduced as an intermediary between external controllers and internal security devices. The central server receives control requests from external controllers, establishes secure VPN connections to the LAN, and forwards requests to the appropriate security devices. This eliminates the need for port forwarding on edge routers, maintaining firewall security while enabling external access to multiple devices through a single secured channel.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple devices are connected using port forwarding, then access to multiple security devices is enabled, but the number of required ports and configuration complexity increase

Engineering Contradiction:
Improvenumber of connected devicesVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The central server performs multiple functions: it acts as a VPN gateway to the secure LAN, a message router to direct control requests to appropriate security devices, and a connection manager to handle multiple external controllers simultaneously. This single multi-functional server replaces the need for multiple port forwarding rules and complex router configurations, enabling access to numerous devices through a unified interface.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If VPN connections are established for secure access, then security is improved, but resource consumption and connection establishment complexity increase

Engineering Contradiction:
Improveconnection securityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Instead of establishing separate VPN connections from each external controller to each security device, the system merges all external connections through a single central server that maintains one VPN connection to the secure LAN. This consolidation reduces the total number of VPN connections required, lowering computational resources and processing overhead while maintaining secure access for multiple controllers to multiple devices.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9021573B2Control of security application in a LAN from outside the LAN
Publication Date: 2015.04.28 CRADLE TECHNOLOGIES INC
  • US9021573B2 patent drawing
  • US9021573B2 patent drawing
  • US9021573B2 patent drawing

AI summary

A method and a system are disclosed that enable an address at the edge router to be used to establish a multi-pipe virtual private network (MVPN) connecting controllers to multiple web enabled end user devices (EUDs) inside a security protected local area network (LAN). The EUDs connect to a central server (CS) outside the LAN during configuration establishing registration and identity (ID) for each EUD. Once the EUDs establish connection from inside the LAN, the CS is enabled to communicate with the EUDs using the address and ID provided during registration. The CS then acts as a facilitator establishing secure VPN connection between controllers in the cloud and the EUDs inside the LAN. CS further acts as a pass through for those LANs that do not allow direct connections to controllers outside the LAN. The CS continues to monitor the health of the overall system once connectivity is established.