Tunnel Server for Secure Firewall Data Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure communications systems, such as firewalls, prevent authorized remote access and control of protected devices while blocking unauthorized access, creating a need for secure and controlled data transmission methods.

Innovation Solution

A data and image transmission system that includes an interactive control server system and a remote image-data acquisition system behind a communications security firewall, utilizing a tunnel client and dynamic domain name server to establish a communications tunnel for secure data exchange, with prioritization rules and user databases to manage access and data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a communications security firewall is used to protect devices from unauthorized access, then security protection is improved, but authorized remote access and control capability deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidauthorized remote access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a tunnel server as an intermediary component that mediates between the firewall-protected image-data acquisition system and remote users. The tunnel server establishes encrypted communication tunnels through the firewall, allowing authorized access while maintaining firewall security rules. This intermediary enables authorized remote control without compromising the firewall's protective function.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments access control by creating individual communication tunnels for different authorized users rather than opening general access. Each tunnel is independently managed with specific authentication, allowing the firewall to maintain granular control over authorized connections while blocking unauthorized access attempts.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If remote access to protected devices is enabled, then ease of operation is improved, but security protection deteriorates

Engineering Contradiction:
Improveremote accessVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The tunnel server acts as a secure intermediary that all remote access must pass through. It implements authentication, encryption, and access control policies, enabling remote access functionality while maintaining security through centralized control and monitoring of all communication sessions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes security parameters dynamically by establishing encrypted communication channels with specific security configurations for each authorized connection. Encryption protocols, authentication credentials, and tunnel parameters are adjusted per user and session, maintaining high security while enabling diverse remote access requirements.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If a communications tunnel is established for secure data transmission, then security protection is improved, but device complexity increases

Engineering Contradiction:
Improvesecure data transmissionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The tunnel server consolidates tunnel establishment and management functionality in a centralized location rather than requiring complex tunneling capabilities in each image-data acquisition system. This intermediary handles the complexity of encrypted tunnel protocols, certificate management, and session control, simplifying the endpoint devices while maintaining secure transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8230472B2Camera image transmission
Publication Date: 2012.07.24 ADVANCED VIDEO COMM
  • US8230472B2 patent drawing
  • US8230472B2 patent drawing
  • US8230472B2 patent drawing

AI summary

A data and image transmission system includes at least one interactive control server system, coupled to a communications network, to which a user may connect for interactive communication to at least one remote image-data acquisition system located behind a communications security firewall. The image-data acquisition system includes a tunnel client, and the interactive control server system includes a active connection to enable the interactive control server system and the image-data acquisition system to transmit and receive communications through the firewall. A set of rules and the operational specifications of the image-data acquisition system, operable on the interactive control server system, determine how the data from the image-data acquisition system is provided to the interactive control server system. Conflicts between the data received from the image-data acquisition system and the data requested by the user are resolved by a set of prioritizing rules to determine the data transmitted to the user.