Secure Relay Hardware for Stable TLS on Resource-Limited IoT

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VPN technologies require significant CPU capacity and power consumption, making them unstable in devices with limited resources, and impose restrictions on network address settings, limiting their application in embedded devices like IoT devices.

Innovation Solution

A secure relay device configured with hardware circuitry that establishes TLS tunnels and determines destination tunnels based on IP or MAC addresses, enabling flexible network address settings and stable VPN connections regardless of CPU capacity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VPN is implemented in software manner in personal computer, then data communication can be secured, but CPU capacity consumption increases and connection stability decreases

Engineering Contradiction:
ImproveVPN connection stabilityVSAvoidCPU capacity consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent introduces a relay device as an intermediary between terminal devices to handle VPN functions. The relay device includes a VPN function execution unit that performs encryption/decryption and tunnel management, freeing terminal devices from heavy CPU processing. This mediator approach resolves the contradiction by transferring the computational burden from resource-constrained terminal devices to a dedicated relay device with sufficient processing power.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces software-based VPN implementation with hardware-based implementation in the relay device. The VPN function execution unit is implemented as hardware circuitry rather than software, providing more efficient and stable processing. This substitution resolves the contradiction by moving from resource-intensive software processing to optimized hardware processing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If VPN is implemented in software manner, then data communication can be secured, but electric power consumption increases

Engineering Contradiction:
ImproveVPN connection stabilityVSAvoidelectric power consumption
Core Design Contradiction:
ReliabilityVSUse of energy by stationary object

Solution Approach 1:

The relay device acts as an intermediary that centralizes VPN processing, allowing terminal devices (especially battery-powered IoT devices) to minimize their power consumption. The relay device's VPN function execution unit handles all encryption/decryption operations, enabling terminal devices to use low-power modes while maintaining secure communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces power-intensive software-based VPN processing with hardware-based processing in the relay device. This hardware implementation is more energy-efficient and provides stable operation without the high power consumption associated with software-based VPN on resource-constrained devices.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If L2 switch or L3 switch is used to connect networks, then network connection can be established, but network configuration flexibility is restricted

Engineering Contradiction:
Improvenetwork address setting flexibilityVSAvoidswitch selection and configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The relay device is designed with multi-functionality, incorporating both L2 switching capabilities (via the L2 switch unit) and L3 routing capabilities (via the L3 switch unit and IP address management). This universal design allows the system to handle both MAC address-based and IP address-based communications, providing configuration flexibility without requiring separate specialized devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The relay device acts as an intermediary that translates between different network layers and address types. The address translation unit converts between MAC addresses and IP addresses, allowing terminal devices to use flexible IP addressing while the relay device manages the mapping to physical network connections. This mediation resolves the contradiction by providing L3 flexibility without sacrificing L2 connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4503525B1Secure relay device and data transmission/reception system
Publication Date: 2025.09.17 DENSO CORP
  • EP4503525B1 patent drawingFigure 1
  • EP4503525B1 patent drawingFigure 2
  • EP4503525B1 patent drawingFigure 3

AI summary

A secure relay device (18) determines whether a destination IP address of reception data, which is received from a LAN, is same as an IP address of the LAN for determining a destination TLS tunnel to which the reception data is to be transmitted. When the reception data is destined to a different network address from the IP address of the LAN, the secure relay device (18) executes a first process of selecting the destination TLS tunnel established between a termination point corresponding to the different network addresses and a transmission source of the reception data. When the reception data is destined to a same network address as the IP address of the LAN, the secure relay device (18) executes a second process of selecting the destination TLS tunnel established between a termination point corresponding to a destination MAC addresses of the reception data and the transmission source of the reception data.