Virtual IP Tunneling for Remote Device Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing remote access to network devices across firewalls is challenging due to stringent security policies that prevent changes in firewall configurations, making it difficult to allow remote monitoring and control while maintaining data security.
Innovation Solution
A method involving a Device Service Manager server that allocates and assigns Virtual IP addresses to network devices, creating a tunnel for secure communication through device service controllers, allowing secure access and management of equipment behind firewalls without compromising security policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firewall configuration is made rigorous to defend information security, then data security is improved, but remote access capability deteriorates
Solution Approach 1:
The patent introduces a Device Service Manager (DSM) and Device Service Controller (DSC) as intermediary components that mediate between external networks and protected devices. The DSC acts as a local service provider that discovers devices on the LAN, manages their service information, and handles communication requests without requiring firewall configuration changes. This intermediary architecture enables remote access while maintaining firewall security policies intact.
Solution Approach 2:
The system segments the network access architecture into multiple components: external networks, firewall, Device Service Manager, Device Service Controller, and protected devices. This segmentation allows each component to have specific security responsibilities, with the DSC handling local device discovery and service management, thereby enabling remote access functionality without compromising the overall firewall security posture.
2Reliability
If firewall security policies are maintained without changes, then security integrity is improved, but ability to allow remote monitoring and control deteriorates
Solution Approach 1:
The Device Service Controller serves as an intermediary that provides remote monitoring and control capabilities without requiring changes to firewall security policies. It discovers devices on the LAN, manages their service information, and handles communication requests through standardized protocols, thereby adding adaptability while preserving security integrity.
Solution Approach 2:
The Device Service Controller is designed as a universal component that can manage multiple types of network devices (servers, PLCs, etc.) and provide various services (discovery, monitoring, control) through a standardized interface. This multi-functionality enables versatile remote access capabilities without requiring specific firewall configurations for each device or service type.
3Ease of operation
If Virtual IP addresses are allocated to proxy communications, then remote access capability is improved, but system complexity increases
Solution Approach 1:
The Device Service Manager and Controller act as intermediaries that automatically manage Virtual IP address allocation and routing. This automation reduces the complexity burden on users, as the system handles the complex tasks of VIP assignment, device discovery, and communication routing without requiring manual configuration or deep user understanding of the underlying mechanisms.
Data Source
AI summary
A method, apparatus, and system are described for a central station to allocate virtual IP addresses. A device service manager server (DSM) has a network access module configured to cooperate with two or more device service controllers (DSCs). The DSM serves as a central management station for allocating and assigning Virtual IP addresses to network devices to proxy communications for networked devices on a local area network (LAN) where each DSC resides. The DSM is located exterior from the network devices on the LAN where communications associated with the assigned VIP addresses are being routed to. The DSM assigns a Virtual IP Addresses to each DSC and establishes a route from the assigned Virtual IP address to a destination network device on a LAN, based on corresponding DSC and network device information stored in a registry of the DSM.


