Gateway Node for Secure Carrier Network Local LAN Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for ensuring communication safety between a terminal and a local network, such as an in-house LAN, require a dedicated line connection between the mobile carrier network and the local network, which is costly and not managed by the carrier, thus lacking an efficient and cost-effective solution for secure communication.

Innovation Solution

An information processing apparatus that uses a processor to transmit connection information for a relay apparatus associated with terminal unique information, allowing the terminal to connect to a virtual private network (VPN) on a public network connected to the mobile carrier network, ensuring secure authentication and connection to the local network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a dedicated line is used to connect the mobile carrier network and the local network, then communication safety is ensured, but the cost increases significantly

Engineering Contradiction:
Improvecommunication safetyVSAvoidcost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent introduces a gateway node as an intermediary component that enables secure communication between the mobile carrier network and the local network without requiring a dedicated physical connection. The gateway node performs authentication and establishes secure tunnel connections, acting as a mediator that eliminates the need for expensive dedicated lines while maintaining communication safety.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a virtual copy of the dedicated line connection through tunnel establishment. Instead of using a physical dedicated line, the system creates a virtual tunnel connection that replicates the security and isolation properties of a dedicated line over the public mobile carrier network, thereby reducing cost while maintaining reliability.

Inventive Principle:
Principle #26Copying

2Reliability

If a dedicated line is used to connect the mobile carrier network and the local network, then communication safety is ensured, but the device complexity and management burden increase

Engineering Contradiction:
Improvecommunication safetyVSAvoidnetwork management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway node serves as an intermediary that centralizes the management of secure connections. Instead of complex point-to-point dedicated line management, the gateway node handles authentication, tunnel establishment, and connection management, significantly reducing the complexity of network administration while ensuring communication safety.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If network authentication is performed by the carrier, then security is improved, but the need for additional authentication mechanisms increases complexity

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the carrier's network authentication with the gateway node's tunnel authentication into a unified authentication process. The terminal performs network authentication with the carrier first, then uses the same authentication credentials to establish the tunnel connection with the gateway node, eliminating the need for separate authentication mechanisms and reducing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11765132B2Information processing apparatus, non-transitory computer readable medium, and communication system
Publication Date: 2023.09.19 FUJIFILM BUSINESS INNOVATION CORP
  • US11765132B2 patent drawing
  • US11765132B2 patent drawing
  • US11765132B2 patent drawing

AI summary

An information processing apparatus includes a processor configured to transmit connection information regarding a repay apparatus to a terminal in a case where terminal unique information is received from the terminal subjected to network authentication performed by communication equipment of a carrier, and cause the terminal to connect to the relay apparatus using the connection information regarding the relay apparatus, where the relay apparatus is associated with the terminal unique information as an apparatus to be connected to a local network, and where the relay device is on a public network connected to a mobile carrier network provided by the carrier. If the relay apparatus successfully authenticates the terminal, the terminal and the relay apparatus are connected to each other over a virtual private network.