Virtual IP Tunneling for Remote Device Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Establishing remote access to network devices across firewalls is challenging due to stringent security policies that prevent changes in firewall configurations, making it difficult to allow remote monitoring and control while maintaining data security.

Innovation Solution

A method involving a Device Service Manager server that allocates and assigns Virtual IP addresses to network devices, creating a tunnel for secure communication through device service controllers, allowing secure access and management of equipment behind firewalls without compromising security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firewall configuration is made rigorous to defend information security, then data security is improved, but remote access capability deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidremote access capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a Device Service Manager (DSM) and Device Service Controller (DSC) as intermediary components that mediate between external networks and protected devices. The DSC acts as a local service provider that discovers devices on the LAN, manages their service information, and handles communication requests without requiring firewall configuration changes. This intermediary architecture enables remote access while maintaining firewall security policies intact.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the network access architecture into multiple components: external networks, firewall, Device Service Manager, Device Service Controller, and protected devices. This segmentation allows each component to have specific security responsibilities, with the DSC handling local device discovery and service management, thereby enabling remote access functionality without compromising the overall firewall security posture.

Inventive Principle:
Principle #1Segmentation

2Reliability

If firewall security policies are maintained without changes, then security integrity is improved, but ability to allow remote monitoring and control deteriorates

Engineering Contradiction:
Improvesecurity integrityVSAvoidremote monitoring capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The Device Service Controller serves as an intermediary that provides remote monitoring and control capabilities without requiring changes to firewall security policies. It discovers devices on the LAN, manages their service information, and handles communication requests through standardized protocols, thereby adding adaptability while preserving security integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The Device Service Controller is designed as a universal component that can manage multiple types of network devices (servers, PLCs, etc.) and provide various services (discovery, monitoring, control) through a standardized interface. This multi-functionality enables versatile remote access capabilities without requiring specific firewall configurations for each device or service type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If Virtual IP addresses are allocated to proxy communications, then remote access capability is improved, but system complexity increases

Engineering Contradiction:
Improveremote access capabilityVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The Device Service Manager and Controller act as intermediaries that automatically manage Virtual IP address allocation and routing. This automation reduces the complexity burden on users, as the system handles the complex tasks of VIP assignment, device discovery, and communication routing without requiring manual configuration or deep user understanding of the underlying mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8571038B2Method to tunnel UDP-based device discovery
Publication Date: 2013.10.29 LANTRONIX INC
  • US8571038B2 patent drawing
  • US8571038B2 patent drawing
  • US8571038B2 patent drawing

AI summary

A method, apparatus, and system are described for a central station to allocate virtual IP addresses. A device service manager server (DSM) has a network access module configured to cooperate with two or more device service controllers (DSCs). The DSM serves as a central management station for allocating and assigning Virtual IP addresses to network devices to proxy communications for networked devices on a local area network (LAN) where each DSC resides. The DSM is located exterior from the network devices on the LAN where communications associated with the assigned VIP addresses are being routed to. The DSM assigns a Virtual IP Addresses to each DSC and establishes a route from the assigned Virtual IP address to a destination network device on a LAN, based on corresponding DSC and network device information stored in a registry of the DSM.