Private Matter Gateway P2P Cloud Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for accessing a Private Cloud Storage Server (PCSS) from Smart Device Clients are cumbersome and require technical expertise, especially in home or office environments, due to the need for complex router setups and reliance on public cloud-based routing servers, which compromise privacy and security.
Innovation Solution
A decentralized peer-to-peer (P2P) communication architecture is established using a Private Cloud VPN Server (PCVS) and a Private Metaverse (PM) with a Private Matter Gateway (PMG), allowing Smart Device Clients to access private cloud services securely and privately without relying on public cloud-based routing servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a fixed IP address and port opening are configured on the router to access PCSS from outside LAN, then the Smart Device Client can locate and authenticate with the PCSS, but the setup becomes complex and requires technical expertise
Solution Approach 1:
The patent introduces a relay server as an intermediary component that mediates between the Smart Device Client and the PCSS. The relay server receives connection requests from clients, establishes secure tunnels to the PCSS, and forwards data traffic, thereby eliminating the need for complex router configurations and port forwarding while maintaining secure access
2Ease of operation
If port forwarding is configured on the router to map dynamic IP addresses, then the PCSS becomes accessible via DDNS, but the configuration becomes more complex and requires additional services
Solution Approach 1:
The relay server acts as a mediator that handles dynamic IP address mapping and connection management centrally. Instead of configuring DDNS and port forwarding on the router, the relay server maintains a registry of PCSS locations and automatically routes client connections, simplifying the client-side configuration while maintaining accessibility
Solution Approach 2:
The relay server provides multiple functions including connection brokering, authentication, encryption key exchange, and traffic relaying in a single unified service. This multi-functional approach replaces the need for separate DDNS, port forwarding, and VPN configuration, reducing overall system complexity
3Reliability
If a public cloud-based routing server is used for VPN communication, then the Smart Device Client can penetrate the firewall and establish secure channels, but privacy and security are compromised
Solution Approach 1:
The system enables direct peer-to-peer communication between the Smart Device Client and the PCSS through mutual authentication and end-to-end encryption. Each party generates and manages its own cryptographic keys, and the relay server only facilitates initial connection setup without accessing or decrypting the actual communication content, thereby maintaining both reliability and privacy
Solution Approach 2:
The relay server serves as a trusted intermediary that enables secure connections without compromising privacy. It facilitates key exchange and establishes encrypted tunnels, but the actual data communication occurs directly between the client and PCSS through these encrypted channels, preventing the intermediary from accessing sensitive information
4Ease of operation
If remote desktop protocol or VNC communication is used through a routing server, then the Smart Device Client can access the PCSS, but it requires additional routing server infrastructure in the WAN
Solution Approach 1:
The system implements built-in remote access functionality directly within the PCSS and Smart Device Client through the decentralized P2P architecture. The clients autonomously establish encrypted communication channels and exchange necessary data without requiring external routing servers, eliminating the need for additional WAN infrastructure while maintaining full remote access capability
Data Source
AI summary
A method for a connection mechanism in a public cloud network is disclosed. The method includes acquiring a plurality of connection credentials from a public cloud portal (PCP) Admin Device; pairing and registration with a private cloud virtual private network (VPN) server (PCVS) from a private matter gateway (PMG); establishing a plurality of initial VPN tunnels between the PCVS and the PMG; connecting to the PMG on demand between a PCVS smart device client and the PMG through the PCVS; and running a plurality of vertical peer-to-peer (P2P) private and secure PCVS smart device client applications between at least one PCVS smart device client and one of at least one PMG smart device client, at least one PMG network service and another PCVS smart device client.


