Firewall Relay Device for Secure MFP Cloud Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in allowing secure and authorized communication between devices inside a firewall and cloud servers outside the firewall, particularly for multi-function peripherals (MFPs) connected to a local area network (LAN) via a firewall, where user authorization management is complex and often requires separate settings for each group and user, leading to inefficiencies and limitations in shared resource access.
Innovation Solution
A connection control system comprising a management server outside the firewall and a relay device inside the firewall, which establishes always-on sessions and relays communications between MFPs and cloud servers, using association information to facilitate secure and authorized connections by establishing first and second communication sessions, enabling authorized users to access MFPs and cloud services while maintaining firewall security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a firewall is used to protect devices inside the LAN, then security is improved, but communication between cloud servers and devices inside the firewall is blocked
Solution Approach 1:
The patent introduces a gateway device as an intermediary component that sits between the firewall and internal devices. This gateway establishes a tunnel through the firewall, enabling cloud servers to communicate with internal devices (MFPs) without compromising firewall security. The gateway acts as a mediator that translates and forwards communication protocols, allowing external access while maintaining internal network protection.
2Reliability
If user authorization is managed separately for each group and user in a user manager server, then access control is improved, but system complexity and configuration effort increase
Solution Approach 1:
The patent merges the authorization management function into the gateway device, combining multiple responsibilities (tunnel establishment, device registration, and user authorization) into a single centralized component. This eliminates the need for a separate user manager server and reduces configuration complexity by providing unified management of all authorization requests across multiple devices and users through a single interface.
Data Source
AI summary
A connection control system includes a management server outside firewall, supporting connection of communications between a control target device inside firewall and a cloud server outside firewall, and a relay device communicating with the control target device inside firewall. A processor included in the management server registers association information associating the cloud server and the relay device with the control target device, establishes an always-on session with the relay device, and upon reception of a connection request, transmits to the relay device via the always-on session a connection instruction to relay communications with the cloud server associated with the control target device by the association information. A processor included in the relay device, upon reception of the connection instruction, establishes a first communication session with the cloud server, establishes a second communication session with the control target device, and relays communications between the cloud server and the control target device.


