Hardware VPN Pairing for Secure Remote LAN Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication networks face challenges in securely transmitting data from remote users over wide area networks (WAN) to designated sites within local area networks (LAN), particularly in ensuring secure access and authentication while minimizing infrastructure investment and protecting against attacks like ARP spoofing.

Innovation Solution

A hardware-based virtual private network (VPN) system using preshared encryption/decryption keys and port isolation to securely route data from remote access nodes to designated workstations within LANs, incorporating key management and authentication protocols to ensure secure, efficient, and reliable access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If traditional software-based VPN solutions are used, then ease of implementation is improved, but security and performance deteriorate due to CPU-intensive encryption and vulnerability to attacks like ARP spoofing

Engineering Contradiction:
Improveease of implementationVSAvoidsecurity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent replaces software-based encryption mechanisms with dedicated hardware encryption/decryption modules. These hardware modules perform cryptographic operations at the hardware level rather than relying on CPU software routines, thereby eliminating the security vulnerabilities and performance limitations of software-based VPN solutions while maintaining ease of deployment through modular hardware units.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If hardware-based VPN modules are deployed at every access point, then security is improved, but device complexity and infrastructure cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs universal hardware VPN modules that can function in multiple roles within the network infrastructure. Each access point contains a hardware VPN module that can operate as either a client transceiver or an enterprise transceiver depending on the operational mode, allowing the same hardware component to provide secure VPN functionality across different network positions without requiring specialized equipment at each location.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the VPN encryption/decryption functionality directly into the access point hardware itself rather than requiring separate dedicated VPN devices. By integrating the hardware VPN modules into the access points and combining client and enterprise transceiver capabilities within the same device, the system reduces overall infrastructure complexity while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If authentication and encryption keys are managed centrally, then security is improved, but system complexity and key management overhead increase

Engineering Contradiction:
Improveauthentication securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service key management where hardware VPN modules automatically generate, store, and manage their own encryption/decryption keys. The modules perform autonomous authentication operations and key operations without requiring manual intervention or complex centralized key management systems, thereby maintaining high security while minimizing key management overhead through automated self-service mechanisms.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12470523B1Systems, and methods for secure remote multi-user LAN access
Publication Date: 2025.11.11 MOBULUSNET LTD
  • US12470523B1 patent drawing
  • US12470523B1 patent drawing
  • US12470523B1 patent drawing

AI summary

The disclosure relates to systems, methods and computer readable media for enabling distributed secure remote access from a device via a wide area network (WAN), to a designated physical site covered by local area network (LAN). Specifically, the disclosure relates to a computerized systems, methods and computer-readable media using hardware-based, virtual private network pairs having preshared encryption/decryption keys, operable to transmit data over WAN from a physical computing device to an exclusively designated site in a physical area covered by a LAN.