Network Gateway Mediator for Secure Guest Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring and securing access to home network devices for guests is challenging for non-technical users, as traditional methods lack control and security, and exposing devices to the global Internet poses risks.

Innovation Solution

A system and method that uses identity assertion providers to obtain shared secrets and permissions, allowing secure access to local network devices by validating requests from guests based on these credentials, with support for social networking platforms to manage access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional approaches like UPnP are used for providing access to devices on a home network, then ease of operation is improved, but security and control are worsened

Engineering Contradiction:
Improveease of configuring accessVSAvoidsecurity and control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a gateway as an intermediary component between the home network devices and external networks. The gateway validates incoming access requests against stored credentials (shared secrets and permissions) before allowing communication to reach the devices. This mediator approach maintains ease of operation by centralizing configuration while significantly improving security and control through active validation of each access attempt.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If home devices are exposed to the global Internet, then accessibility is improved, but security is worsened

Engineering Contradiction:
Improveaccessibility to devicesVSAvoidvulnerability to attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements local quality by maintaining distinct security characteristics for different parts of the network. Internal devices retain their original security configurations and are not directly exposed to Internet threats. The gateway applies different security rules to internal versus external traffic, allowing controlled accessibility while protecting devices from direct Internet exposure and associated attack vectors.

Inventive Principle:
Principle #3Local quality

3Reliability

If traditional IP forwarding is used for controlling home network traffic, then security control is improved, but ease of operation is worsened

Engineering Contradiction:
Improvecontrol over network trafficVSAvoiddifficulty of configuration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables self-service by allowing the gateway to automatically validate access requests using pre-configured credentials stored locally. The system performs automated authentication and permission checking without requiring users to manually configure complex IP forwarding rules. This maintains security control through automated validation while dramatically improving ease of operation by eliminating the need for users to understand or configure advanced networking parameters.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3111615B1Systems and methods for providing secure access to local network devices
Publication Date: 2020.09.16 CA TECH INC
  • EP3111615B1 patent drawingFigure 1
  • EP3111615B1 patent drawingFigure 2
  • EP3111615B1 patent drawingFigure 3

AI summary

A computer-implemented method for providing secure access to local network devices may include (1) identifying a local area network that provides Internet connectivity to at least one device within the local area network, (2) obtaining, from an identity assertion provider, (i) a shared secret for authenticating the identity of a guest user of the device and (ii) a permission for the guest user to access the device from outside the local area network, (3) storing the shared secret and the permission within the local area network, (4) receiving, via the Internet connectivity, a request by the guest user from outside the local area network to access the device, and (5) providing access to the device in response to validating the request based on the shared secret and the permission. Various other methods and systems are also disclosed.