Remote Access Hardware Component for Secure LAN Tunneling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for remote access to local area networks require dedicated software installation on terminals, consuming resources and relying on additional servers, which can lead to performance degradation, increased costs, and reduced security and reliability.

Innovation Solution

A hardware component with non-volatile storage for access identifiers and direct connection means, capable of establishing a secure communication tunnel with the original gateway without intermediate equipment, eliminating the need for software installation and reducing reliance on external servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If dedicated software is installed on the terminal for remote access, then remote access capability is achieved, but terminal performance decreases due to resource consumption

Engineering Contradiction:
Improveremote access capabilityVSAvoidterminal performance
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The invention extracts the remote access functionality from the terminal device and relocates it to a dedicated hardware component (remote access device). This extraction eliminates the need for software installation on the terminal, thereby preserving terminal performance while maintaining remote access capability. The hardware component contains all necessary processing power, memory, and communication interfaces to handle remote access independently.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system is segmented into distinct functional components: the terminal device, the hardware component (remote access device), and the local network infrastructure. This segmentation allows each component to perform its specific function optimally without burdening other components. The hardware component acts as an intermediary that handles all remote access operations, separating this function from the terminal's core operations.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If an additional server is used to establish connection between terminal and LAN, then connection capability is improved, but security and reliability are reduced

Engineering Contradiction:
Improveconnection capabilityVSAvoidsecurity and reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The hardware component serves as a trusted intermediary device that is physically part of the local network infrastructure. Unlike an external third-party server, this intermediary is embedded within the network boundary, providing secure access control. It establishes direct connections between the terminal and local network resources without requiring external server mediation, thereby maintaining security while enabling connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The hardware component provides self-service functionality by autonomously managing connection establishment, authentication, and data routing between the terminal and local network. It contains embedded credentials and authentication mechanisms that allow it to independently verify and authorize access without requiring external server intervention, thus improving reliability and security.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If third-party server is used for linking terminal to LAN, then remote access is enabled, but costs increase

Engineering Contradiction:
Improveremote access functionalityVSAvoidcost
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The invention merges the remote access functionality with existing network infrastructure components (such as gateways, routers, or set-top boxes). By combining these functions into a single integrated hardware component that is already present in the network, the solution eliminates the need for separate third-party server infrastructure, thereby reducing deployment and operational costs while maintaining remote access capability.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3311531B1Hardware component and method for a remote terminal to access a local network, corresponding service gateway, access authorisation method and computer program
Publication Date: 2020.08.19 ORANGE SA
  • EP3311531B1 patent drawingFigure 1~2
  • EP3311531B1 patent drawingFigure 3A~5

AI summary

The invention relates to a hardware component, to a method for a remote terminal to access a local network, and to a corresponding service gateway, access authorisation method and computer program. The invention relates to a hardware component which is configured to allow a remote terminal (14) to access a local area communication network (11), said local area communication network being connected to a wide area communication network (13) via a service gateway, referred to as source gateway (12). According to the invention, the hardware component (15) includes: at least one memory unit including an area for non-volatile storage of at least one identifier for accessing said source gateway; means for connecting to said wide area communication network; means for connecting to said terminal; and means for requesting the opening of a secure communication tunnel with said source gateway, from said at least one identifier for accessing said source gateway.