External Network Content Access via Proxy Port Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for accessing content from a local network using UPnP protocols are cumbersome and complex, particularly when trying to connect devices outside the network, and often overload the access gateway's processor, while also posing security risks due to address conflicts and resource limitations in residential gateways.
Innovation Solution
A method utilizing a proxy module and an access management module to create temporary port mappings and address translations, offloading processing from the main processor to accelerators, and employing a single-use access code for enhanced security, without relying on HTTP reverse proxies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If an HTTP reverse proxy is embedded on the residential access gateway to receive incoming requests and relay them to recipient entities, then external equipment can access local network content, but the gateway processor becomes overloaded and cannot support multiple simultaneous access flows
Solution Approach 1:
The patent extracts the proxy functionality from the gateway processor and implements it in a separate network element (such as a router or dedicated proxy server). This separation removes the processing burden from the gateway, allowing it to handle multiple access flows without overload while external equipment can still access local network content through the externalized proxy service.
Solution Approach 2:
The patent introduces an intermediary network element that acts as a dedicated proxy server between external equipment and the local network. This intermediary handles all request relay operations, freeing the gateway processor from this task and enabling it to focus on core networking functions, thus supporting multiple simultaneous access flows without performance degradation.
2Adaptability or versatility
If VPN tunnel or IMS architecture is used to establish network connection for controlling network entities from external terminals, then access is enabled, but the solutions become cumbersome and complex to implement
Solution Approach 1:
The patent employs lightweight, temporary port mappings instead of establishing permanent or semi-permanent VPN tunnels or IMS connections. Each access request triggers a short-lived port mapping that is automatically created and discarded, eliminating the need for complex authentication and connection management protocols while enabling external access to local network content.
Solution Approach 2:
The patent dynamically changes network parameters (port mappings) on-demand to enable external access. Instead of maintaining fixed complex connection architectures, the system modifies gateway port forwarding rules temporarily for each access request, allowing flexible external connectivity through simple parameter adjustments rather than complex structural changes.
3Reliability
If port mapping is created for each access to content, then security is enhanced by limiting access, but the gateway processor workload increases
Solution Approach 1:
The patent extracts the port mapping management function from the gateway processor and implements it in a separate network element. This dedicated component handles the creation and management of temporary port mappings for each access request, freeing the gateway processor from this overhead while maintaining security through individualized port mappings for each external access.
Solution Approach 2:
The system implements automatic, on-demand port mapping creation and removal without requiring manual configuration or continuous processor intervention. The proxy service automatically manages the lifecycle of port mappings, creating them when access is needed and removing them when no longer required, providing security through automated resource management while minimizing processor workload.
Data Source
Figure 1
Figure 2
AI summary
The invention relates to a method for providing a device (T1) with access to content (C1) listed by a content server (DMS1) of a local area network (RS1), the method including a step of providing said device, via a server (DMSP) suitable for receiving from said device, requests intended for being sent to said content server, with a temporary address for said content, which points to an entity (AM) of the network, said entity being designed such as to control, upon receiving a request to access said content, the placement of a map by a gateway (GW1) for accessing said network, reserved for said access, between a first so-called external port of the access gateway and a second so-called internal port of the content server.