Multiplexing Software Component for Network Device Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Legacy networking systems face challenges in securely and cost-effectively scaling Internet-connected devices due to limitations in Domain Name System (DNS) capability and Secure Sockets Layer (SSL) certificate deployment, particularly with wildcard handling, and lack effective methods for flexible and efficient mapping of multiple devices connected to the Internet, as well as inadequate security for device identification and authentication.
Innovation Solution
The implementation of a multiplexing and demultiplexing system using software components that enable connections between devices over a single TCP port, allowing for the multiplexing of multiple TCP and UDP ports, and a configuration mechanism to manage and secure these connections, thereby addressing the scalability and security issues in device deployment and management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional DNS and SSL certificate deployment methods are used for each device, then device identification and authentication are established, but system complexity and deployment costs increase significantly when scaling to multiple devices
Solution Approach 1:
The patent merges multiple device connections through a single TCP port using multiplexing software components. Instead of requiring separate SSL certificates and DNS entries for each device, the system combines multiple device traffic streams through port 8443, reducing certificate deployment complexity while maintaining authentication security through the multiplexing architecture
Solution Approach 2:
The multiplexing software component acts as a universal intermediary that handles authentication and connection management for multiple devices through a single port. This universal component replaces the need for device-specific certificate configurations, allowing the same port to securely manage multiple device connections with different authentication credentials
2Reliability
If separate TCP ports are assigned to each device for secure connections, then device authentication is maintained, but the system becomes less scalable and more costly when deploying numerous devices
Solution Approach 1:
The patent combines multiple device connections into a single TCP port (8443) using multiplexing software. This merging approach maintains connection security through the multiplexing architecture while dramatically improving scalability, as the system can now handle numerous device connections through one port rather than requiring separate ports for each device
Solution Approach 2:
The patent introduces a software-based multiplexing dimension that allows multiple logical device connections to coexist on a single physical port. This dimensional change from one-to-one port-device mapping to one-to-many multiplexed mapping enables scalable device deployment while maintaining security boundaries through the software layer
3Ease of manufacture
If wildcard SSL certificates are used to cover multiple devices, then certificate management is simplified, but security vulnerabilities increase and DNS capability limitations remain
Solution Approach 1:
The patent extracts the certificate management function from the connection management function. Instead of using wildcard certificates that combine both functions (causing security issues), the system separates them by using the multiplexing software component to handle device-specific authentication while the SSL certificate provides general encryption for the port, reducing security vulnerabilities
Solution Approach 2:
The multiplexing software component acts as an intermediary between the SSL certificate layer and individual device connections. This intermediary receives the encrypted traffic on the port and routes it to the appropriate device based on authentication credentials, allowing simplified certificate management without compromising security by maintaining device-specific authentication boundaries
4Ease of operation
If multiple TCP ports are used to connect multiple devices, then device identification is straightforward, but the system loses flexibility and efficiency in managing device connections
Solution Approach 1:
The patent inverts the traditional approach by not using separate ports for device identification. Instead, it uses a single port with the multiplexing software component that identifies and routes device connections based on authentication credentials and device-specific parameters, providing both ease of operation and management flexibility
Data Source
AI summary
A system, method, and computer program product are provided for accessing a device connected to a network. In operation, a device connected to a network is accessed by multiplexing and demultiplexing multiple connections.


