Server-Mediated Virtual Connection for Chip Card Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for establishing direct connections between data processing systems are hindered by network configurations, such as firewalls, and are complex to manage, especially when accessing multiple chip cards, as each connection needs to be set up separately.

Innovation Solution

A method providing a virtual connection for transmitting application data units involves client authentication with a server, using a server to switch control and response application data units between clients, allowing for indirect communication through a network, even when direct connections are prevented by firewalls, and enabling efficient management of multiple chip card access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If direct connections are established between data processing systems, then communication between systems is achieved, but network firewalls prevent such connections and system complexity increases when accessing multiple chip cards

Engineering Contradiction:
Improveconnection establishmentVSAvoidconnection management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a server as an intermediary system that mediates communication between first clients and second clients. Instead of establishing direct connections between clients, all communication is routed through the server, which receives data units from first clients, stores them, and forwards them to the appropriate second clients. This intermediary approach bypasses firewall restrictions that block direct peer-to-peer connections while centralizing connection management to reduce overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If separate direct connections are set up for each chip card, then access to individual chip cards is enabled, but the complexity of managing multiple connections increases significantly

Engineering Contradiction:
Improvechip card accessVSAvoidconnection management
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges multiple individual connection management tasks into a single centralized connection managed by the server. Instead of requiring separate direct connections for each chip card access, the server consolidates all communication channels, storing and forwarding data units between clients and multiple chip cards through a unified architecture. This combining approach maintains ease of access to individual chip cards while dramatically reducing the complexity of managing multiple separate connections.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If firewall configurations are implemented for security, then system security is improved, but direct connections between data processing systems are blocked

Engineering Contradiction:
Improvesystem securityVSAvoiddirect connection capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The server acts as a secure intermediary that operates within the firewall-protected network architecture. By routing all communications through this centralized server, the system maintains firewall security configurations while enabling data exchange between clients. The server handles authentication, data storage, and forwarding operations, allowing secure communication without requiring clients to establish direct connections that would be blocked by firewall rules.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3130165B1Provisioning a virtual connexion for application data units transmission
Publication Date: 2018.11.07 CERTGATE
  • EP3130165B1 patent drawingFigure 1~2
  • EP3130165B1 patent drawingFigure 3
  • EP3130165B1 patent drawingFigure 4

AI summary

Method, comprising authentication of one or more first clients by a server, authentication of one or more second clients by the server and provision of at least one application data unit conveyance by the server such that, when a data packet having a control application data unit is received from one of the first clients on the server, the server sends a data packet having the control/application data unit that the received data packet contains to at least one of the second clients, and/or that, when a data packet having a response application data unit is received from one of the second clients on the server, the server sends a data packet having the response application data unit that the received data packet contains to at least one of the first clients.