Reverse Access Architecture for Secure DMZ-LAN Connections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems with DMZs face challenges such as high costs and vulnerabilities due to data duplication, management complexity, and susceptibility to hacking, which compromise the security of internal networks and data integrity in the LAN.

Innovation Solution

A system that secures data on the LAN by establishing a connection binder between the DMZ and LAN servers, allowing seamless communication without requiring administrative management on the LAN server, using a LAN controller to manage client requests and a DMZ stack pool service to route requests securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is duplicated on both DMZ and LAN computers, then service availability is improved, but cost and management complexity increase

Engineering Contradiction:
Improveservice availabilityVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the data storage function into a single location (LAN computer) while maintaining service availability through virtualization. The virtual machine on the LAN computer provides services to both DMZ and LAN, eliminating the need for physical data duplication across multiple computers.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a virtual copy of the data access interface through virtualization. Instead of copying physical data to multiple locations, a virtual machine interface is created that allows multiple access points to the single data source, reducing management complexity while maintaining availability.

Inventive Principle:
Principle #26Copying

2Reliability

If data is duplicated on both DMZ and LAN computers, then service availability is improved, but licensing costs increase

Engineering Contradiction:
Improveservice availabilityVSAvoidlicensing costs
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent consolidates data storage to a single LAN computer, which eliminates the need for multiple software licenses that would be required if data were duplicated across multiple DMZ and LAN computers. This merging approach reduces the quantity of licensed software instances while maintaining service availability.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If DMZ interfaces with external systems, then communication capability is improved, but vulnerability to hacking increases

Engineering Contradiction:
Improvecommunication capabilityVSAvoidvulnerability to hacking
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a virtual machine as an intermediary between the external DMZ interface and the internal LAN data. This virtual layer acts as a mediator that allows communication capability to external systems while isolating the actual data from direct exposure to hacking risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the system into distinct virtual and physical layers. The DMZ interface operates in a virtualized environment that is logically separated from the physical data storage on the LAN computer, creating security zones that reduce vulnerability while maintaining communication capability.

Inventive Principle:
Principle #1Segmentation

4Reliability

If administrative management is required on LAN server, then security control is improved, but operational complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service security control through the virtual machine architecture. The virtual machine on the LAN computer automatically manages security protocols and access control, reducing the need for manual administrative intervention while maintaining strong security control.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUSRE50745E1Reverse access method for securing front-end applications and others
Publication Date: 2026.01.06 NETNUT LTD
  • USRE50745E1 patent drawing

AI summary

A System that provides a secured connection between servers on the LAN and clients on the WAN comprises the LAN (which includes LAN Server and LAN Controller) and the DMZ (which includes DMZ Server and DMZ Stack Pool Service). Wherein the Client Request reaches the DMZ Server it stores it in the DMZ Stack Pool Service and the LAN Controller establishes outbound TCP based connection to the DMZ Stack Pool Service that passes the Client Connection Information to the LAN Server via the LAN Controller. Then the LAN Server then generates a connection between the Service and DMZ Server.