Secure Relay TLS Tunnel Selection for Mixed LAN and VPN Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional VPN technologies, such as those using Transport Layer Security (TLS), are CPU-intensive and power-consuming, making them unstable in devices with limited capacity, and they impose restrictions on network configurations, limiting their applicability to embedded devices like IoT devices.
Innovation Solution
A secure relay device configured by hardware circuit that determines the destination TLS tunnel based on IP and MAC addresses, enabling flexible network settings and stable VPN connections, even in devices with limited CPU capacity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software-based VPN using TLS is used, then security is improved, but CPU consumption and power consumption increase
Solution Approach 1:
The patent replaces software-based TLS processing with hardware circuit implementation. The secure relay device uses dedicated hardware circuits to perform TLS tunnel establishment, data encryption/decryption, and tunnel selection, eliminating the need for CPU-intensive software processing while maintaining security functionality.
Solution Approach 2:
The patent introduces a secure relay device as an intermediary component between terminal devices and the network. This relay device handles all TLS processing operations, allowing terminal devices with limited CPU capacity to benefit from secure communication without bearing the computational burden.
2Reliability
If software-based VPN is used, then security is improved, but device complexity and configuration restrictions increase
Solution Approach 1:
The patent replaces software-based VPN protocols with hardware-implemented secure relay functionality. The hardware circuit directly handles TLS tunnel management and routing decisions based on IP and MAC addresses, eliminating complex software configuration requirements and making the system adaptable to various network topologies including L2 and L3 configurations.
Data Source
AI summary
A secure relay device is connected to a terminal device and configures a termination point of a TLS tunnel in a VPN network. The secure relay device determines whether a destination IP address of reception data, which is received from a LAN, is same as an IP address of the LAN. When the reception data is destined to a different network address from the IP address of the LAN, the secure relay device selects the TLS tunnel established between a termination point corresponding to the different network address and a transmission source of the reception data. When the reception data is destined to a same network address as the IP address of the LAN, the secure relay device selects the TLS tunnel established between a termination point corresponding to a destination MAC addresses of the reception data and the transmission source of the reception data.


