Remote Access Control Mediation with Authentication and Port Forwarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number of remote devices with shared access information in a VPN network leads to increased management costs and compromised security due to unauthorized access risks.

Innovation Solution

A management device with authentication, authorization, and communication modules to verify the administrator device's correctness and access qualifications before establishing a connection and configuring port forwarding to a network device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If multiple remote devices are configured with the same or related access information to save management cost, then the management cost decreases, but the network security deteriorates because access information is easily obtained when VPN access information is stolen

Engineering Contradiction:
Improvemanagement costVSAvoidnetwork security
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent segments the access control system into multiple independent components: authentication module (verifies administrator identity), authorization module (checks access qualifications), and port forwarding module (establishes connections). This segmentation allows each module to perform its specific function independently, enabling secure access control without requiring shared access information across multiple devices, thus resolving the contradiction between management cost and network security.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If traditional VPN access control is used where administrator device accesses remote device directly using access information, then the access process is simple, but the network security deteriorates due to unauthorized access risks when access information is stolen

Engineering Contradiction:
Improveaccess process simplicityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a management device as an intermediary between the administrator device and remote devices. The management device includes authentication module, authorization module, and port forwarding module that work together to mediate access requests. This intermediary approach maintains operational simplicity for users while implementing robust security checks, resolving the contradiction between access process simplicity and network security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of time

If access information is shared among multiple remote devices to reduce management overhead, then the management overhead decreases, but the risk of unauthorized access increases significantly

Engineering Contradiction:
Improvemanagement overheadVSAvoidunauthorized access risk
Core Design Contradiction:
Loss of timeVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication and authorization actions before establishing any access connections. The authentication module verifies administrator identity in advance, and the authorization module checks access qualifications before allowing connections. This preliminary action approach eliminates the need for shared access information while maintaining low management overhead, resolving the contradiction between management overhead and unauthorized access risk.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12375487B2Device, method and system of handling access control
Publication Date: 2025.07.29 MOXA INC
  • US12375487B2 patent drawing
  • US12375487B2 patent drawing
  • US12375487B2 patent drawing

AI summary

A management device comprises a first authentication module, for receiving a first information and performing a first determination on whether an administrator device is correct according to the first information; an authorization module, coupled to the first authentication module, for performing a second determination on whether the administrator device comprises an access qualification for a remote device, when the first determination is positive and when receiving a first request message for accessing the remote device; a communication module, coupled to the authorization module, for transmitting a second request message for establishing a connection with a network device to the remote device, when the second determination is positive and when determining to establish the connection with the network device; an integration module, coupled to the authorization module, for transmitting a third request message for configuring a port forwarding to the network device, when the second determination is positive.