Private Matter Gateway P2P Cloud Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for accessing a Private Cloud Storage Server (PCSS) from Smart Device Clients are cumbersome and require technical expertise, especially in home or office environments, due to the need for complex router setups and reliance on public cloud-based routing servers, which compromise privacy and security.

Innovation Solution

A decentralized peer-to-peer (P2P) communication architecture is established using a Private Cloud VPN Server (PCVS) and a Private Metaverse (PM) with a Private Matter Gateway (PMG), allowing Smart Device Clients to access private cloud services securely and privately without relying on public cloud-based routing servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a fixed IP address and port opening are configured on the router to access PCSS from outside LAN, then the Smart Device Client can locate and authenticate with the PCSS, but the setup becomes complex and requires technical expertise

Engineering Contradiction:
Improveease of access to PCSSVSAvoidrouter setup complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a relay server as an intermediary component that mediates between the Smart Device Client and the PCSS. The relay server receives connection requests from clients, establishes secure tunnels to the PCSS, and forwards data traffic, thereby eliminating the need for complex router configurations and port forwarding while maintaining secure access

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If port forwarding is configured on the router to map dynamic IP addresses, then the PCSS becomes accessible via DDNS, but the configuration becomes more complex and requires additional services

Engineering Contradiction:
Improveaccessibility with dynamic IPVSAvoidrouter and DDNS configuration
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The relay server acts as a mediator that handles dynamic IP address mapping and connection management centrally. Instead of configuring DDNS and port forwarding on the router, the relay server maintains a registry of PCSS locations and automatically routes client connections, simplifying the client-side configuration while maintaining accessibility

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The relay server provides multiple functions including connection brokering, authentication, encryption key exchange, and traffic relaying in a single unified service. This multi-functional approach replaces the need for separate DDNS, port forwarding, and VPN configuration, reducing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If a public cloud-based routing server is used for VPN communication, then the Smart Device Client can penetrate the firewall and establish secure channels, but privacy and security are compromised

Engineering Contradiction:
Improvesecure communication channelVSAvoidprivacy and security compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system enables direct peer-to-peer communication between the Smart Device Client and the PCSS through mutual authentication and end-to-end encryption. Each party generates and manages its own cryptographic keys, and the relay server only facilitates initial connection setup without accessing or decrypting the actual communication content, thereby maintaining both reliability and privacy

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The relay server serves as a trusted intermediary that enables secure connections without compromising privacy. It facilitates key exchange and establishes encrypted tunnels, but the actual data communication occurs directly between the client and PCSS through these encrypted channels, preventing the intermediary from accessing sensitive information

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If remote desktop protocol or VNC communication is used through a routing server, then the Smart Device Client can access the PCSS, but it requires additional routing server infrastructure in the WAN

Engineering Contradiction:
Improveremote access capabilityVSAvoidWAN routing server infrastructure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system implements built-in remote access functionality directly within the PCSS and Smart Device Client through the decentralized P2P architecture. The clients autonomously establish encrypted communication channels and exchange necessary data without requiring external routing servers, eliminating the need for additional WAN infrastructure while maintaining full remote access capability

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12323272B2Private matter gateway connection mechanism for use in a private communication architecture
Publication Date: 2025.06.03 PRIMES LAB INC
  • US12323272B2 patent drawing
  • US12323272B2 patent drawing
  • US12323272B2 patent drawing

AI summary

A method for a connection mechanism in a public cloud network is disclosed. The method includes acquiring a plurality of connection credentials from a public cloud portal (PCP) Admin Device; pairing and registration with a private cloud virtual private network (VPN) server (PCVS) from a private matter gateway (PMG); establishing a plurality of initial VPN tunnels between the PCVS and the PMG; connecting to the PMG on demand between a PCVS smart device client and the PMG through the PCVS; and running a plurality of vertical peer-to-peer (P2P) private and secure PCVS smart device client applications between at least one PCVS smart device client and one of at least one PMG smart device client, at least one PMG network service and another PCVS smart device client.