Gateway Remote Access Authentication for VoIP

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network architectures complicate remote access to voice-over-IP services, requiring complex management of terminal registration and authentication across multiple servers, making it difficult to provide seamless access to home networks from remote locations.

Innovation Solution

A method for managing remote access to a network using access information comprising a terminal's physical address and a gateway's secret key, allowing authorized terminals to access registered networks via a second network, with the network equipment providing the necessary access information and managing authentication, enabling secure and simplified remote access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If complex multi-server registration and authentication architecture is used for remote VoIP access, then security and service management are improved, but system complexity and difficulty of operation increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication and service management functions into a single gateway device. The gateway stores both the terminal's physical address and secret key, and performs both authentication verification and service provisioning in one location, eliminating the need for multiple servers and complex inter-server communication while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The gateway is designed as a universal device that handles multiple functions: it acts as an authentication server, a service manager, and a network interface. By making the gateway multi-functional, the system eliminates the need for separate specialized servers, thereby reducing overall system complexity while maintaining robust security and service management capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If terminal must link with multiple servers for remote access, then service management capability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveservice management capabilityVSAvoidease of access
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent extracts the essential authentication data (physical address and secret key) from the complex multi-server architecture and consolidates it into a single gateway. This extraction simplifies the access process for terminals, which now only need to communicate with one gateway instead of multiple servers, while the gateway retains full service management capability.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If conventional registration data is used for remote access authorization, then simplicity of access is improved, but security may be compromised

Engineering Contradiction:
Improvesimplicity of accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-configuring the gateway with both the terminal's physical address and secret key during the initial registration phase. This pre-preparation allows the terminal to access services simply using its physical address without complex authentication sequences, while the gateway uses the pre-stored secret key to verify security, thus achieving both simplicity and security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9008056B2Remote network access via a visited network
Publication Date: 2015.04.14 ORANGE SA
  • US9008056B2 patent drawing
  • US9008056B2 patent drawing
  • US9008056B2 patent drawing

AI summary

Remote access for a terminal to a first network via a second network is managed; the first network being linked to the second network via a network apparatus. At the level of the network apparatus, there is received, from the terminal via the second network, a request for remote access to the first network indicating access information comprising a first parameter corresponding to a physical address of the terminal and a second parameter corresponding to a secret key of the gateway. The network apparatus thereafter decides whether the terminal is authorized to remotely access the first network on the basis of said access information. This network apparatus subsequently emits, bound for the terminal via the second network, a message indicating whether the terminal is authorized to remotely access the first network.