Firewall-Bypass Communication via Server Mediator
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing a communication connection between a mobile device and a computing device protected by a firewall is challenging due to firewall restrictions, and existing solutions like the 'push principle' result in high data traffic and complex configuration requirements.
Innovation Solution
A communication system where the mobile device sends a request to a server device, which converts it into a response sent back to the computing device, allowing the computing device to initiate a communication connection with the mobile device without direct access, thereby bypassing firewall restrictions and reducing data traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a firewall protection mechanism is implemented to restrict external access to the computing system, then security is improved, but communication connection from mobile devices is blocked
Solution Approach 1:
The patent introduces a server as an intermediary component between mobile devices and the computing system. The server receives connection requests from mobile devices, forwards them to the computing system through the firewall, and relays responses back. This mediator approach allows communication to occur without requiring direct access to the protected system, thus maintaining firewall security while enabling mobile device connectivity.
2Ease of operation
If the push principle is used to enable mobile devices to establish communication connections, then connection establishment is improved, but data traffic volume increases due to regular polling requests
Solution Approach 1:
The patent implements a polling mechanism where the computing system periodically sends requests to the server to check for new connection requests from mobile devices. This periodic action allows the system to maintain the ability to establish connections on demand while avoiding continuous data transmission. The server holds incoming connection requests until the computing system polls for them, thus reducing unnecessary data traffic compared to continuous push mechanisms.
3Reliability
If explicit security application configuration is required for each mobile device to enable access, then access control is improved, but configuration complexity increases and can overwhelm users
Solution Approach 1:
The patent implements a self-service mechanism where mobile devices can autonomously establish connections by sending requests to the server without requiring manual security application configuration. The server automatically manages the connection establishment process, including forwarding requests to the computing system and coordinating the connection setup. This eliminates the need for users to manually configure security applications on each device while maintaining access control through the server's automated authorization process.
Data Source
Figure 1
Figure 2
AI summary
The invention relates to a communication system (2) having at least one computation device (6) and at least one remotely arranged server device (16) which can be connected to the computation device (6) via a network (14), wherein the computation device (6) is set up to send at least one first request to the server device (16), wherein a mobile appliance (18) is set up to send a second request to the server device (16) in order to set up a communication link to the computation device (6), and the server device (16) is set up to send the received second request from the mobile device (18) to the computation device (6) in the form of a first response to the first request from the computation device (6).