Remote Port Access Server for Firewall-Bypassed Device Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network protocols face challenges in accessing remote devices behind firewalls due to the need for complex firewall modifications and the use of dynamic IP addresses, making it impractical to establish connections for data access and communication.

Innovation Solution

A remote port access (RPA) server system that allows remote devices to automatically detect network connectivity and initiate outgoing connections, enabling communication through firewalls without requiring modifications to the network or firewall configurations, using a 'plug-and-play' approach with dynamic IP addresses and secure communication protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If remote devices are installed behind a firewall with dynamic IP addresses, then ease of deployment is improved, but ability to establish incoming connections deteriorates

Engineering Contradiction:
Improveease of deploymentVSAvoidability to establish incoming connections
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

Instead of allowing incoming connections to remote devices through the firewall (which requires opening security holes), the system inverts the connection direction by having remote devices initiate outgoing connections to the RPA server. This reversal allows connections while maintaining firewall security, as outbound connections are typically permitted by default firewall configurations.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The RPA server acts as an intermediary between client devices and remote devices. Client devices connect to the RPA server, which then communicates with remote devices through their established outbound connections. This mediator enables indirect access without requiring direct incoming connections through the firewall.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If firewall modifications are made to allow incoming connections, then connectivity to remote devices is improved, but device complexity and technical knowledge requirements worsen

Engineering Contradiction:
Improveconnectivity to remote devicesVSAvoidfirewall configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system eliminates the need for firewall modifications by inverting the connection model. Instead of configuring firewalls to allow incoming connections, remote devices automatically establish outgoing connections to the RPA server, which are permitted by default firewall rules. This removes the complexity of firewall configuration entirely.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

Remote devices automatically detect network connectivity and self-configure outbound connections to the RPA server without requiring manual firewall configuration. The system performs its own setup, eliminating the need for users to have technical knowledge of firewall configurations.

Inventive Principle:
Principle #25Self-service

3Stability of the object's composition

If static IP addresses are assigned to remote devices, then connection stability is improved, but ease of deployment and adaptability worsen

Engineering Contradiction:
Improveconnection stabilityVSAvoidease of deployment
Core Design Contradiction:
Stability of the object's compositionVSEase of manufacture

Solution Approach 1:

The system inverts the traditional client-server connection model. Instead of clients connecting to remote devices with static IPs, remote devices connect to the RPA server with stable, predictable addresses. This allows the server to have a stable endpoint while clients and remote devices can use dynamic addresses.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system embraces dynamic IP addresses for remote devices and client devices while maintaining connection stability through the RPA server's persistent outbound connections. The dynamic nature of IP addresses is accommodated because the connection model is designed around devices initiating connections rather than receiving them.

Inventive Principle:
Principle #15Dynamics

4Object-affected harmful factors

If outgoing connections are blocked by firewall, then security is improved, but remote device communication capability deteriorates

Engineering Contradiction:
Improvefirewall securityVSAvoidremote device communication capability
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The system exploits the typical firewall behavior of allowing outbound connections while blocking inbound connections. By inverting the connection direction so that remote devices initiate outbound connections to the RPA server, the system maintains strong firewall security while enabling full communication capability.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system converts the restrictive nature of firewalls (which block incoming connections) into a benefit by designing a connection model where only outgoing connections are needed. The firewall's default blocking of incoming connections becomes an advantage, as the system never requires such connections.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS8812616B2Remote port access (RPA) server
Publication Date: 2014.08.19 SYSTECH CORP
  • US8812616B2 patent drawing
  • US8812616B2 patent drawing
  • US8812616B2 patent drawing

AI summary

Systems and methods for accessing data from one or more remote devices and providing data to remote devices installed behind one or more firewalls are provided. The remote devices are configured to automatically detect network connectivity and to open a network connection to a remote port access (RPA) server. The remote devices initiate the connection with the RPA server enabling the connection to be established through the firewall. A client device establishes a network connection to the RPA server in order to access data from or to provide data to one or more of the remote devices. The RPA server acts as an intermediary between the RPA server and the remote devices that receives data from the client device and sends the data to the remote device and receives data from the remote devices and sends the data to the client device.