Gateway Registration via Key-Address Matching for Secure Remote Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote management systems for home devices face challenges in authenticating gateway apparatuses, leading to potential malicious control and data leakage, as direct access from external management servers is often disabled for security and cost reasons.

Innovation Solution

A registration method where a computer generates and manages key information unique to each target device, associating it with a communication apparatus's address, allowing secure registration of relay apparatuses by matching addresses and key information, thereby authenticating the communication apparatus without complex cryptographic algorithms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If direct access from management server to home device is disabled for security reasons, then security is improved, but remote management capability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidremote management capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a gateway apparatus as an intermediary component that enables remote management while maintaining security. The gateway apparatus receives management commands from the external management server and forwards them to the home device, allowing indirect access that preserves security constraints while achieving management objectives. This mediator approach resolves the contradiction by providing a controlled access path through the gateway that authenticates and relays commands without exposing direct access pathways.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If gateway apparatus is used for relaying communication, then remote management capability is improved, but authentication security deteriorates

Engineering Contradiction:
Improveremote management capabilityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary authentication actions where the gateway apparatus and management server establish trusted relationships before actual management operations. The system performs pre-authentication of the gateway apparatus against the management server, and pre-registration of home devices through the gateway. This preliminary security establishment ensures that authentication credentials are verified in advance, preventing unauthorized access while enabling subsequent remote management operations.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If complex cryptographic algorithms are used for authentication, then authentication security is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts complex cryptographic authentication operations from the home device and concentrates them in the gateway apparatus and management server. The home device uses simpler authentication mechanisms while the gateway handles the computationally intensive cryptographic operations for establishing secure channels with the management server. This extraction approach maintains strong authentication security through sophisticated cryptography where needed, while keeping the home device architecture simple and manageable.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9100244B2Registration method and registration apparatus
Publication Date: 2015.08.04 FUJITSU LTD
  • US9100244B2 patent drawing
  • US9100244B2 patent drawing
  • US9100244B2 patent drawing

AI summary

A computer receives, from a target device via a communication apparatus that is capable of accessing the target device, an issuance request for issuing key information unique to the target device. The computer generates the key information upon reception of the issuance request. The computer stores an address allocated to the communication apparatus and the key information in association with each other. The computer transmits the key information to the target device via the communication apparatus. The computer receives, from the communication apparatus, the key information and a registration request for registering a relay apparatus for relaying communication between the computer and the target device. The computer registers the communication apparatus as the relay apparatus when the address allocated to the communication apparatus and the address stored in association with the received key information match each other.