Multiplexing Software Component for Network Device Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy networking systems face challenges in securely and cost-effectively scaling Internet-connected devices due to limitations in Domain Name System (DNS) capability and Secure Sockets Layer (SSL) certificate deployment, particularly with wildcard handling, and lack effective methods for flexible and efficient mapping of multiple devices connected to the Internet, as well as inadequate security for device identification and authentication.

Innovation Solution

The implementation of a multiplexing and demultiplexing system using software components that enable connections between devices over a single TCP port, allowing for the multiplexing of multiple TCP and UDP ports, and a configuration mechanism to manage and secure these connections, thereby addressing the scalability and security issues in device deployment and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional DNS and SSL certificate deployment methods are used for each device, then device identification and authentication are established, but system complexity and deployment costs increase significantly when scaling to multiple devices

Engineering Contradiction:
Improvedevice authentication securityVSAvoidcertificate deployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple device connections through a single TCP port using multiplexing software components. Instead of requiring separate SSL certificates and DNS entries for each device, the system combines multiple device traffic streams through port 8443, reducing certificate deployment complexity while maintaining authentication security through the multiplexing architecture

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The multiplexing software component acts as a universal intermediary that handles authentication and connection management for multiple devices through a single port. This universal component replaces the need for device-specific certificate configurations, allowing the same port to securely manage multiple device connections with different authentication credentials

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate TCP ports are assigned to each device for secure connections, then device authentication is maintained, but the system becomes less scalable and more costly when deploying numerous devices

Engineering Contradiction:
Improveconnection securityVSAvoiddevice deployment scalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent combines multiple device connections into a single TCP port (8443) using multiplexing software. This merging approach maintains connection security through the multiplexing architecture while dramatically improving scalability, as the system can now handle numerous device connections through one port rather than requiring separate ports for each device

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a software-based multiplexing dimension that allows multiple logical device connections to coexist on a single physical port. This dimensional change from one-to-one port-device mapping to one-to-many multiplexed mapping enables scalable device deployment while maintaining security boundaries through the software layer

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Ease of manufacture

If wildcard SSL certificates are used to cover multiple devices, then certificate management is simplified, but security vulnerabilities increase and DNS capability limitations remain

Engineering Contradiction:
Improvecertificate management easeVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the certificate management function from the connection management function. Instead of using wildcard certificates that combine both functions (causing security issues), the system separates them by using the multiplexing software component to handle device-specific authentication while the SSL certificate provides general encryption for the port, reducing security vulnerabilities

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The multiplexing software component acts as an intermediary between the SSL certificate layer and individual device connections. This intermediary receives the encrypted traffic on the port and routes it to the appropriate device based on authentication credentials, allowing simplified certificate management without compromising security by maintaining device-specific authentication boundaries

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If multiple TCP ports are used to connect multiple devices, then device identification is straightforward, but the system loses flexibility and efficiency in managing device connections

Engineering Contradiction:
Improvedevice identification easeVSAvoidconnection management flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent inverts the traditional approach by not using separate ports for device identification. Instead, it uses a single port with the multiplexing software component that identifies and routes device connections based on authentication credentials and device-specific parameters, providing both ease of operation and management flexibility

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS11184224B2System, method and compute program product for accessing a device on a network
Publication Date: 2021.11.23 REMOT3 IT INC
  • US11184224B2 patent drawing
  • US11184224B2 patent drawing
  • US11184224B2 patent drawing

AI summary

A system, method, and computer program product are provided for accessing a device connected to a network. In operation, a device connected to a network is accessed by multiplexing and demultiplexing multiple connections.