Gateway-Mediated Remote Access for Secure Production Device Links

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems require network and information security knowledge to set up remote access to production devices, posing risks of intrusion and high man-hour verification needs.

Innovation Solution

A remote system that connects a local area network with a server device via a wide area network, using a gateway device to relay communication without altering existing network configurations, and employs device identification to establish secure sessions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If network setting changes are made to enable remote access, then remote connectivity is improved, but system security and complexity increase

Engineering Contradiction:
Improveremote access capabilityVSAvoidnetwork configuration complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a gateway device as an intermediary component between the production device and external terminal. The gateway device handles all network configuration, session establishment, and communication relay, allowing remote access without modifying the production device's network settings. This mediator approach resolves the contradiction by centralizing complexity in the gateway while keeping the production device simple and secure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If network settings are modified for remote access, then connectivity is improved, but security risks increase

Engineering Contradiction:
Improveremote access capabilityVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the system into distinct functional components: the production device (maintaining security), the gateway device (handling network communication), and the external terminal (providing access). By separating network configuration responsibilities from the production device and placing them in the gateway device, the system achieves remote access capability while maintaining security isolation. The production device remains unchanged and secure, while the gateway handles all external communications.

Inventive Principle:
Principle #1Segmentation

3Reliability

If manual verification of network settings is performed, then security is improved, but time consumption increases

Engineering Contradiction:
Improvesetting verification accuracyVSAvoidverification man-hours
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The gateway device performs self-service by automatically establishing sessions, managing device identification information, and relaying communications without requiring manual verification. The system autonomously handles session establishment between the external terminal and production device through device identification matching, eliminating the need for time-consuming manual verification while maintaining security through automated authentication mechanisms.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12572137B2Remote system, remote connection method and computer readable storage medium
Publication Date: 2026.03.10 MITSUBISHI ELECTRIC CORP
  • US12572137B2 patent drawing
  • US12572137B2 patent drawing
  • US12572137B2 patent drawing

AI summary

In a remote system, a local area network including a production device and a gateway device is connected to a server device via a wide area network. The remote system includes a network device that permits connection from an inside to an outside of the local area network and rejects connection from the outside to the inside. The gateway device requests the server device to establish a first session between the gateway device and the server device. The server device compares device identification information for identifying a target production device designated by the external terminal with device identification information set to the production device, establishes the first session in response to a request for establishment of the first session, establishes a second session between the server device and the external terminal when both of pieces of the device identification information matches, and links the first session and the second session.