Virtual Device Interface Management Behind Network Firewalls

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for remotely managing devices behind firewalls result in poor display performance and increased security risks due to direct network access through firewalls, compromising the security of internal networks.

Innovation Solution

A system comprising a server device, processing device, and terminal device, where an agent on the processing device acquires device information from internal network devices and transmits it to the server, which generates a virtual user interface displayed on the terminal device, bypassing direct network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If direct network access through firewalls is used to display device interfaces, then display performance is improved, but security risks increase

Engineering Contradiction:
Improvedisplay performanceVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a server device as an intermediary between the terminal device and the internal network device. The server device receives display requests from the terminal, acquires device information through the agent, generates virtual user interfaces, and transmits them to the terminal. This intermediary approach allows the terminal to access device information without direct network connection to the internal network, thereby maintaining display performance while eliminating security risks associated with direct firewall access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If direct firewall access is used to manage internal devices, then management efficiency is improved, but security protection deteriorates

Engineering Contradiction:
Improvemanagement efficiencyVSAvoidsecurity protection
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The server device serves as a secure intermediary that manages device information acquisition and interface generation. The agent installed on the internal network device communicates with the server device through controlled channels, allowing the server to acquire device information and generate virtual interfaces without requiring direct access from external terminals through the firewall. This maintains management efficiency while strengthening security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The server device creates a virtual copy of the internal network device's user interface by acquiring device information through the agent and generating a virtual user interface. This virtual interface is then transmitted to the terminal device for display and interaction. The copying approach allows remote management without direct network access to the internal device, thereby maintaining management efficiency while improving security protection.

Inventive Principle:
Principle #26Copying

3Object-affected harmful factors

If agent-based information acquisition is used, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The server device performs multiple functions within a unified architecture: it receives display requests from terminals, acquires device information through the agent, generates virtual user interfaces, and transmits them to terminals. The agent installed on the internal network device also serves multiple purposes by communicating device information to the server and receiving control commands. This multi-functionality approach improves security through centralized management while minimizing the increase in system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12489733B2Management system, management method, and server device
Publication Date: 2025.12.02 SHARP KK
  • US12489733B2 patent drawing
  • US12489733B2 patent drawing
  • US12489733B2 patent drawing

AI summary

A management system including a server device connected to a first network, a plurality of devices connected to a second network, and a terminal device connected to the first network or the second network, in which an agent is executed in a first device, which is any one of the plurality of devices, the agent acquires device information related to a second device connected to the second network and transmits the device information to the server device, the server device generates display information on the basis of the received device information and transmits the display information to the terminal device, and the terminal device displays a user interface related to the second device on the basis of the received display information.