Gateway Server Mediator for Secure Remote Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for providing data to a remote site often require opening a local port on the firewall/router, compromising security and being impractical for home or small business owners to implement sophisticated security solutions.

Innovation Solution

A system comprising a first server, a second server, and a gateway component, where the first server sends a request for data specifying the gateway and a predetermined port number, allowing the gateway to retrieve data from a data source and send it to the second server without opening a local port on the firewall/router.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a port is opened on the local firewall to allow remote monitoring requests, then remote data access is enabled, but local network security is compromised

Engineering Contradiction:
Improveremote data accessVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a server as an intermediary component between the remote monitoring system and the local network. The server receives monitoring requests from remote systems, retrieves data from the data source, and forwards it to the remote system without requiring any ports to be opened on the local firewall. This intermediary approach enables remote access while maintaining network security isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If sophisticated firewall solutions are implemented to maintain security, then network security is improved, but device complexity and cost increase

Engineering Contradiction:
Improvenetwork securityVSAvoidfirewall configuration
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The server acts as a simplified intermediary that replaces the need for complex firewall configurations. Instead of configuring sophisticated firewall rules and heuristic security solutions, the system uses a straightforward server-based architecture where the server handles all data retrieval and forwarding operations, maintaining security while reducing complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The server autonomously retrieves data from the data source and forwards it to remote systems without requiring manual firewall management or complex security configuration by the user. The system self-manages the data transfer process, eliminating the need for users to implement and maintain sophisticated firewall solutions.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If a port is opened on the local firewall for data source access, then remote monitoring is enabled, but security vulnerabilities are introduced

Engineering Contradiction:
Improveremote monitoring capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The server serves as a secure intermediary that completely eliminates the need to open ports on the local firewall. The server establishes its own secure connection to the data source and handles all remote monitoring requests through this intermediary channel, enabling remote access capability without creating any security vulnerabilities by keeping the local firewall closed.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3117582B1Method and systems for providing data to a remote site
Publication Date: 2020.05.27 ONCAM GLOBAL
  • EP3117582B1 patent drawingFigure 1
  • EP3117582B1 patent drawingFigure 2
  • EP3117582B1 patent drawingFigure 3

AI summary

A system including a first server, a second server operatively connected over a network to the first server and a gateway component operatively connected over the network to the first server and the second server. The first server is configured to receive a request for data, the request for data specifying the gateway component and including a predetermined port number at the second server, and send the request for data to the gateway component. The second server is configured to receive the data at the predetermined port number, the data being provided by the gateway component. The gateway component is configured to receive the request for data, retrieve the data from a data source, operatively connect, over the network, to a port at the second server, the port corresponding to the predetermined port number, and send the data to the second server. Methods for using the system are also disclosed.