Network Gateway Wake-on-LAN Security via Remote Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for waking up equipment connected to a local area network from a remote terminal not connected to the network pose security risks, as they require transmitting wake-up commands through the local network, compromising its security.

Innovation Solution

A method utilizing an access device with a remote management platform to transmit wake-up requests via a secure communication link, such as the TR-069 protocol, ensuring only authorized devices can establish connections through a predefined communication port, thus maintaining network security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If wake-up commands are transmitted through the local network to wake up equipment, then remote waking capability is achieved, but network security is compromised

Engineering Contradiction:
Improveremote waking capabilityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a gateway device as an intermediary between the remote terminal and the local network equipment. The gateway receives wake-up requests from remote terminals and forwards them to the target equipment through the local network. This mediator approach allows remote waking capability while maintaining network security, as the gateway controls and filters all incoming wake-up requests rather than allowing direct access from external terminals.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the wake-up command transmission path into multiple stages: remote terminal → gateway device → local network → target equipment. This segmentation isolates the local network from direct external access, creating security zones where each segment has controlled access to the next, thereby enabling remote functionality while protecting network integrity.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If the access device accepts wake-up requests from any terminal, then remote access flexibility is improved, but unauthorized access risk increases

Engineering Contradiction:
Improveremote access flexibilityVSAvoidunauthorized access prevention
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The gateway device performs preliminary authentication and validation of wake-up requests before forwarding them to the local network. It pre-establishes trusted relationships with authorized remote terminals and validates incoming requests against these pre-configured credentials. This preliminary action ensures that only authenticated requests proceed further, maintaining reliability while preserving access flexibility for authorized users.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The gateway device implements different access policies and validation rules for different remote terminals. Each authorized terminal can be configured with specific permissions, target equipment lists, and access conditions. This local quality approach allows the system to maintain high flexibility for authorized users while simultaneously enforcing strict security controls, creating differentiated access patterns based on terminal identity and authorization level.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2229751B1Method and device for the wake-on-lan of a device connected to a network
Publication Date: 2012.06.27 ORANGE SA
  • EP2229751B1 patent drawingFigure 1
  • EP2229751B1 patent drawingFigure 2
  • EP2229751B1 patent drawingFigure 3~4

AI summary

The invention relates to a method for the wake-on of a device (PC11) connected to a first network (RL) that comprises the step of receiving (367) and processing a wake-on request of said device via an access device (GW1) of the first network through which a device of the first network can access a second network (RW), the step of transmitting (375), via the access device and through the first network, a device wake-on control, wherein said transmission step is to be carried out after the reception of said request, said request being received from a remote management platform (PF2) of at least one access device via a communication link established through said second network and used for the management of said access device by said platform.