Remote Access Hardware Component for Secure LAN Tunneling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for remote access to local area networks require dedicated software installation on terminals, consuming resources and relying on additional servers, which can lead to performance degradation, increased costs, and reduced security and reliability.
Innovation Solution
A hardware component with non-volatile storage for access identifiers and direct connection means, capable of establishing a secure communication tunnel with the original gateway without intermediate equipment, eliminating the need for software installation and reducing reliance on external servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If dedicated software is installed on the terminal for remote access, then remote access capability is achieved, but terminal performance decreases due to resource consumption
Solution Approach 1:
The invention extracts the remote access functionality from the terminal device and relocates it to a dedicated hardware component (remote access device). This extraction eliminates the need for software installation on the terminal, thereby preserving terminal performance while maintaining remote access capability. The hardware component contains all necessary processing power, memory, and communication interfaces to handle remote access independently.
Solution Approach 2:
The system is segmented into distinct functional components: the terminal device, the hardware component (remote access device), and the local network infrastructure. This segmentation allows each component to perform its specific function optimally without burdening other components. The hardware component acts as an intermediary that handles all remote access operations, separating this function from the terminal's core operations.
2Adaptability or versatility
If an additional server is used to establish connection between terminal and LAN, then connection capability is improved, but security and reliability are reduced
Solution Approach 1:
The hardware component serves as a trusted intermediary device that is physically part of the local network infrastructure. Unlike an external third-party server, this intermediary is embedded within the network boundary, providing secure access control. It establishes direct connections between the terminal and local network resources without requiring external server mediation, thereby maintaining security while enabling connectivity.
Solution Approach 2:
The hardware component provides self-service functionality by autonomously managing connection establishment, authentication, and data routing between the terminal and local network. It contains embedded credentials and authentication mechanisms that allow it to independently verify and authorize access without requiring external server intervention, thus improving reliability and security.
3Adaptability or versatility
If third-party server is used for linking terminal to LAN, then remote access is enabled, but costs increase
Solution Approach 1:
The invention merges the remote access functionality with existing network infrastructure components (such as gateways, routers, or set-top boxes). By combining these functions into a single integrated hardware component that is already present in the network, the solution eliminates the need for separate third-party server infrastructure, thereby reducing deployment and operational costs while maintaining remote access capability.
Data Source
Figure 1~2
Figure 3A~5
AI summary
The invention relates to a hardware component, to a method for a remote terminal to access a local network, and to a corresponding service gateway, access authorisation method and computer program. The invention relates to a hardware component which is configured to allow a remote terminal (14) to access a local area communication network (11), said local area communication network being connected to a wide area communication network (13) via a service gateway, referred to as source gateway (12). According to the invention, the hardware component (15) includes: at least one memory unit including an area for non-volatile storage of at least one identifier for accessing said source gateway; means for connecting to said wide area communication network; means for connecting to said terminal; and means for requesting the opening of a secure communication tunnel with said source gateway, from said at least one identifier for accessing said source gateway.