Virtual CPE Tunneling via Authentication Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing virtual CPE technology requires complex VPN settings for terminals to access services outside the home, which negatively impacts communication quality compared to access within the communication service provider network.

Innovation Solution

A communication system comprising a first virtual CPE, a second virtual CPE, and an authentication server, where the second virtual CPE confirms terminal registration and performs a tunnel connection to the first virtual CPE upon successful authentication, enabling network connections similar to those inside the home without complex VPN settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a terminal connects to a network line outside the home using existing virtual CPE technology, then the terminal can access services outside the home, but complex VPN settings are required which worsen communication quality

Engineering Contradiction:
Improveaccess capability outside homeVSAvoidVPN setting complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication server as an intermediary between the terminal and the network. The authentication server manages terminal registration and provides authentication information to virtual CPEs, eliminating the need for complex VPN settings at the terminal side. The virtual CPE uses the authentication information from the server to establish connections, simplifying the overall system while maintaining outside-home access capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If VPN is used for outside-home access, then terminal can connect to services, but communication quality deteriorates compared to access within the communication service provider network

Engineering Contradiction:
Improveoutside-home service accessVSAvoidcommunication quality
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The authentication server acts as a trusted intermediary that enables terminals to access services outside the home through a controlled authentication mechanism rather than requiring VPN tunneling. This approach maintains communication quality by using the communication service provider's own authentication infrastructure, ensuring reliable and high-quality connections while providing outside-home access.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If complex VPN settings are implemented for outside-home access, then terminal can connect to external services, but the connection process becomes more difficult to configure and maintain

Engineering Contradiction:
Improveexternal service connectivityVSAvoidconnection configuration ease
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system implements self-service functionality where the authentication server automatically manages terminal registration and generates authentication information. When a terminal connects to a virtual CPE, the server automatically provides the necessary authentication credentials, eliminating the need for manual VPN configuration. This automated approach significantly improves ease of operation while maintaining external service connectivity.

Inventive Principle:
Principle #25Self-service

4Ease of operation

If terminal information is registered in the authentication server, then the second virtual CPE can establish tunnel connection to the first virtual CPE, but the system requires additional authentication infrastructure

Engineering Contradiction:
Improveconnection establishment simplicityVSAvoidauthentication infrastructure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The authentication server performs multiple functions: it registers terminal information, generates authentication information, and enables tunnel connection establishment. By consolidating these functions into a single multi-functional component, the system achieves simple connection establishment without requiring separate complex authentication infrastructure, as the same server handles all authentication and registration tasks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11165603B2Communication system and communication method using virtual customer premise equipment
Publication Date: 2021.11.02 NIPPON TELEGRAPH & TELEPHONE CORP
  • US11165603B2 patent drawing
  • US11165603B2 patent drawing
  • US11165603B2 patent drawing

AI summary

In a communication system including a first virtual CPE to which a terminal belongs, a second virtual CPE, and an authentication server, when the terminal connects to the second virtual CPE, the second virtual CPE confirms whether terminal information of the terminal is registered in the authentication server, and when the terminal information is registered in the authentication server, the authentication server notifies the second virtual CPE of an address of the first virtual CPE, and the second virtual CPE performs a tunnel connection to the first virtual CPE.