Mobile secure network systems and devices

The mobile security system addresses the vulnerability of portable server racks by implementing a secure mobile device with a housing, access control, and fail-secure mechanisms, enabling secure network extension and operation in remote locations.

JP7768892B2Active Publication Date: 2025-11-12SECUCART LLC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2022558502
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-03-27
Filing Date
2021-03-24
Publication Date
2025-11-12
Estimated Expiration
2041-03-24

AI Technical Summary

Technical Problem

Mobile or portable server racks lack sufficient security due to their mobile nature, making them vulnerable to intrusion, while traditional data center security measures are ineffective in these contexts.

Method used

A physically and electronically secured mobile security system and device that includes a housing with a door, access control mechanism, security module, and wireless router, featuring a local user cache, kill switch, and fail-secure mechanism to ensure secure extension of a remote home network, even in areas without internet connectivity.

Benefits of technology

Provides secure, portable network extension with integrated logical and physical security, allowing operation as a fully local data center environment, even with slow internet speeds, and ensuring secure access and remote tracking.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007768892000001
    Figure 0007768892000001
  • Figure 0007768892000002
    Figure 0007768892000002
  • Figure 0007768892000003
    Figure 0007768892000003
Patent Text Reader

Abstract

Disclosed are mobile security systems and devices that provide physically secured network devices for extending a home network anywhere in the world with access to a power source. The mobile security systems and devices have integrated logical and physical security and can be transported, self-sufficient, and secured to areas without Internet connectivity. The mobile security systems and devices include a housing that encloses a computer device, an access control mechanism that secures the housing door in a closed position, and a security control module that protects data stored on the computer device and provides authentication for accessing the enclosure. A backup power source supported by the housing and wireless router can also be provided to provide wireless network access to a remote home network.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to mobile secure network systems and devices, and more particularly to physically and electronically protected mobile systems for housing computer networks that provide secure extension of computer networks from remote home networks.

[0002] (CROSS-REFERENCE TO RELATED APPLICATIONS) This application claims priority to U.S. Non-provisional Application No. 16 / 833,396, filed March 27, 2020, the entire disclosure of which is incorporated herein by reference. [Background technology]

[0003] Data centers, which house computer networks for the remote storage, processing, and / or distribution of large volumes of data, are well known in the art. Such data centers are configured according to user demand or for specific purposes, such as financial transaction processing, corporate data storage, or global communications, to name just a few. The computer networks housed in the data centers store and transmit information critical to user operations. Data center security is a known issue to those skilled in the art and is achieved by restricting and tracking physical access to the data center. Because data centers house valuable information on computer networks, most data centers include lockable doors, cabinets, and / or racks to restrict access to network components and the power sources supported thereon.

[0004] Security and monitoring of cabinets and / or racks in data centers has not changed much over the years. Traditionally, racks and / or cabinets have manual keys to lock them. They may also have key-code access in addition to or instead of traditional keys, or may provide electronic access via smart locks that utilize card reader technology to authenticate user credentials with a central server and respond with a signal to unlock the cabinet, or that unlock remotely when instructed by an authorized user. Audit logs of users who have accessed the data center may also be kept for tracking purposes. Summary of the Invention

[0005] While data center security measures are generally effective because they are locked, difficult to move, and housed in large, secure rooms, mobile or portable server racks are not as secure because their mobile nature makes them vulnerable to intrusion. Mobile computing devices that can be used in remote locations are desirable in a variety of industries for a variety of reasons. Many industries deploy workers to remote locations that do not have an Internet connection, or to client locations where client Internet access is undesirable for security or other reasons. Therefore, mobile secure systems and devices that provide location-free security and accountability for the use of computer networks and devices contained within the mobile security system are desirable.

[0006] Disclosed herein is a physically and electronically secured mobile security system and device for housing a computing device that can securely extend a remote home network to the computing device's current location. The mobile security system uses the same logistical and physical access control system as the parent facility. The mobile system includes a housing supporting the computing device having a door for accessing the computing device, and may include a backup power source supported thereon, a wireless router supported on the housing for providing wireless network access to the remote home network, an access control mechanism for securing the door in a closed position relative to the housing, and a security module for protecting data stored on the computing device and for providing authentication for accessing the housing.

[0007] In one embodiment, the security module includes a local cache of users authorized to unlock the enclosure. The local cache may also be configured to track users who have accessed the credential reader. The security module may be configured to synchronize the local cache with a cache in the remote home network. The local cache may also be used to cache data determined by the data center not to need to be synchronized with the remote home network.

[0008] In another embodiment, the access control mechanism is configured to deny access to the enclosure if the security module fails to synchronize the local cache with the cache on the remote home network. The mobile secure network device may include a kill switch that physically disables access to the enclosure by deactivating the credential reader after a set number of attempts by an unauthorized user who does not match a user in the local cache of authorized users. In another embodiment, activation of the kill switch also clears the local cache and disables access to the remote home network. Activation of the kill switch by an unauthorized user attempt or by forcible physical breach causes the fail-secure device to send a signal to clear the local cache and disable remote access to the home network. The computing device may also include a global positioning system supported by the housing so that the location of the secure network device can be remotely tracked as needed in the event of a breach.

[0009] Mobile secure network systems and devices are physically secured network devices that allow anyone to extend their network anywhere in the world with access to power. Caching and bandwidth optimization within the router allow the system to operate as a fully local data center environment in remote locations, even with very slow internet speeds. This is because bandwidth optimization allows the local cache to be synchronized when usage permits, while authorization requests are sent directly to the home data center as higher priority traffic. Mobile security systems can be deployed in areas without internet connectivity, making them self-sufficient and secure. Mobile secure network systems and devices have integrated logical and physical security and are fully portable.

[0010] Various aspects of at least one embodiment are described below with reference to a number of accompanying drawings, which are not necessarily drawn to scale, with emphasis instead being placed on illustrating the principles disclosed herein. These drawings are included to provide an explanation and further understanding of the various aspects and embodiments, and are incorporated into and constitute a part of this specification, but are not intended as a definition of the limits of particular embodiments. These drawings, together with the remainder of the specification, merely serve to explain the principles and operation of the described and claimed aspects and embodiments, and should not be construed as limiting the embodiments. In the drawings, like numerals represent identical or nearly identical components shown in the various drawings. For clarity, not every component is labeled in every drawing. [Brief explanation of the drawings]

[0011] [Figure 1] 1 is a perspective view of a mobile secure network device according to a first embodiment; [Figure 2] FIG. 2 is a schematic diagram of the mobile secure network system and devices of FIG. 1. [Figure 3] 1 is a flow chart illustrating an embodiment of a security module and locking mechanism for securing a mobile secure network device according to embodiments disclosed herein. [Figure 4] 10 is a flow chart illustrating an embodiment of a security module for synchronizing a local cache with a remote network according to embodiments disclosed herein. [Figure 5] FIG. 2 is a schematic diagram of a mobile secure network device according to FIG. 1; DETAILED DESCRIPTION OF THE INVENTION

[0012] The examples of systems and devices described herein are not limited in their application to the details of component configuration and arrangement set forth in the following description or illustrated in the accompanying drawings. Those skilled in the art will recognize that the systems and devices can be implemented in other embodiments and practiced or carried out in various ways. Specific example embodiments are provided herein for purposes of illustration only and are not intended to be limiting. Additionally, the phraseology and terminology used herein are for purposes of description and should not be considered limiting. References to examples, embodiments, components, elements, or operations of systems and devices referred to herein in the singular may encompass embodiments that include the plural, and references to any embodiment, component, element, or operation herein in the plural may encompass embodiments that include only the singular (or single structure). References to the singular or plural are not intended to limit the systems and devices of the present disclosure, their components, operations, or elements. As used herein, the singular forms "a," "an," and "the" are intended to include the plural unless the context clearly dictates otherwise. The use of "including," "comprising," "having," "including," "relat- ing to," and variations thereof in the specification is meant to include the items listed thereafter and equivalents thereof, but does not preclude the presence or addition of one or more other features or items. References to "or" may be construed as inclusive, such that terms listed using "or" may refer to either the singular, the plural, or all of the listed terms.

[0013] As will be appreciated by those skilled in the art, aspects of the systems and devices disclosed herein may be embodied as a system, method, or apparatus. Accordingly, aspects of the present disclosure may take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, microcode, etc.), or an embodiment combining software and hardware aspects, generally referred to herein as a "circuit," "module," or "system." Furthermore, aspects of the present disclosure may take the form of a computer program product embodied in one or more computer-readable medium(s) having computer-readable program code embodied therein. Any combination of one or more computer-readable medium(s) may be utilized. The computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. The program code embodied in the computer-readable medium may be transmitted using any suitable medium, including, but not limited to, wireless, wired, fiber optic cable, RF, etc., or any suitable combination thereof.

[0014] Aspects of the present disclosure are described below with reference to flowchart diagrams and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present disclosure. It will be understood that each block of the flowchart diagrams and / or block diagrams, and combinations of blocks in the flowchart diagrams and / or block diagrams, can be implemented by computer program instructions. When referring to flowchart diagrams and / or block diagrams, the functions described in the blocks may differ from the order described in the figures. For example, two blocks shown in succession may actually be executed substantially simultaneously, or the blocks may be executed in the reverse order, depending on the functionality involved. Each block of the block diagrams and / or flowchart diagrams, and combinations of blocks in the block diagrams and / or flowchart diagrams, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or a combination of dedicated hardware and computer instructions.

[0015] 1 and 2 , the present disclosure relates to a physically and electronically secured mobile security system and device 10 for housing a computing device 12, which provides a secure extension of a remote home network 14 to the computing device's current location. As used herein, the term “computing device” refers to electronic devices housed within the mobile security device for use in the home network, including, but not limited to, servers, patch panels, routers, switches, etc. The mobile security system 10 includes an enclosure, i.e., a housing 16, surrounding the computing device 12, having a door 18 for accessing the computing device 12, an access control mechanism 24 for securing the door 18 in a closed position relative to the housing 16, and a security control module 25 for protecting data stored on the computing device 12 and providing authentication for accessing the enclosure 16. The housing 16 may also include support members, such as a rack 11 that secures the computing device within the housing 16 and includes slidable rails, a backup power supply 20 supported by the housing 16, and a wireless router 22 that provides wireless network access to the remote home network 14.

[0016] In this embodiment, access control mechanism 24 communicates with remote home network 14 to authenticate requests to unlock door 18. Access control mechanism 24 may include a credential reader 26 and a locking device 28. Credential reader 26 may be communicatively coupled to door 18, and locking device 28 may be any of a variety of locking devices, including a conventional lock 30. Security control module 25 communicates with credential reader 26 and access control mechanism 24 and grants access to computing device 12 by unlocking lock 30 in response to verification of the credential by home network 14.

[0017] In one embodiment, as shown in FIG. 3 , security control module 25 includes a locally cached database 32 of users authorized to unlock housing 16. To gain access to housing 16, credentials read by credential reader 26 may be checked against the locally cached database of authorized users. If the user's identification matches that in locally cached database 32, the card is authenticated and door 18 is unlocked. If the user's identification does not match that in locally cached database 32, the card is invalid and an alert is stored in the local cache and may also be communicated to and stored on remote home network 14. In this manner, fraudulent attempts to gain access to mobile security system and device 10 may be stored in an audit log. Local cache 32 may also be configured to track users who access credential reader 26 and similarly store users who access mobile security system and device 10 in an audit log, either locally or remotely.

[0018] 4, security control module 25 may be configured to synchronize local cache 32 with cache 34 in remote home network 14. Local cache 32 may also be used to cache data that is determined not to need to be synchronized with remote home network 14. Access control mechanism 24 may be configured to deny access to housing 16 if security module 26 fails to synchronize local cache 32 with cache 34 in remote home network 14.

[0019] A shutdown protocol may be initiated when a predefined event occurs and access is denied by the security control module 25, for example, due to lack of authorization or failure to synchronize with the local cache 32. The mobile secure system 10 may include a kill switch 36 that physically disables access to the housing 16 by deactivating the credential reader 26 (e.g., after a set number of attempts by a user that does not match the user in the user's local cache 32 or upon failed synchronization). In one embodiment, activation of the kill switch 36 also clears (i.e., wipes, deletes, or discards) data stored in the local cache 32, disabling access to the remote home network 14. A fail-secure device 38 may be provided to signal a forced compromise of the mobile secure network device 10 and activate the kill switch. The fail-secure device 38 may be any known device that activates a signal in response to a physical compromise, including, for example, a glass-break sensor, a lock sensor, and / or a power sensor.

[0020] In an emergency situation where it is desirable to remove the computing device 12 from the housing 16, an emergency key may be provided to allow removal of the computing device 12. The emergency key in this embodiment is a physical key that may be stored in a secure location remote from the housing and can be used to access a lock located on the rear of the housing in the event of a malfunction of the electronic lock. Accessing the housing 16 from the rear allows access to the interior of the housing to remove side panels and / or remove a rack-mounted computing device 12 from the inside. Entering the housing from the front, equipped with the credential reader 26 and locking device 28, provides access but does not easily allow removal of the computing device 12. Additionally, a tamper-evident indicator, such as tamper-evident tape or a pressure sensor, may be provided to indicate rear access to the housing, which can then be reset electronically and / or physically. For example, if a pressure sensor is used, it must first be placed back in place and then reset electronically. If tamper-evident tape is utilized, it must be physically replaced. Therefore, the use of the emergency key is obvious.

[0021] The computing device 12 may include a server 40 that communicates with the remote home network 14 over a secure network channel, such as a VPN channel or a local wireless network. The local wireless network may include a WiFi network, a cellular network, and / or a mesh network, or similar networks. The computing device may further include a global positioning system 42 supported by the housing 16 so that the location of the secure network device 10 can be remotely tracked as needed.

[0022] The mobile security system and device 10 provides a physically secured network device that allows anyone to extend their network anywhere in the world where they have access to power. Caching and bandwidth optimization within the router allows the system to operate as a fully local data center environment in remote locations, even with very slow internet speeds. This is because bandwidth optimization allows the local cache to be synchronized when usage permits, while authorization requests are sent directly to the home data center as higher priority traffic. The mobile security system can be deployed in areas without internet connectivity and be self-sufficient and secure. The mobile device has integrated logical and physical security and is fully portable.

[0023] Those skilled in the art will appreciate that the underlying concepts of the present disclosure may readily be utilized as a basis for designing other products without departing from the spirit and scope of the present invention as defined by the appended claims. Accordingly, the claims are not limited to the specific examples set forth herein. For example, features of one example disclosed above may be used with features of another example. Furthermore, various modifications and rearrangements of parts may be made without departing from the spirit and scope of the underlying inventive concept. Accordingly, details of these components shown in the above examples should not be construed as limiting the scope of the claims.

[0024] Additionally, the purpose of the Abstract is to enable the U.S. Patent and Trademark Office, the general public, and particularly scientists, engineers, and practitioners in the art who are not familiar with patent or legal terminology or language, to quickly assess the nature and substance of the technical disclosure of the application at a glance. The Abstract is not intended to define the claims of the application, nor is it intended to limit the claims in any manner.

Claims

1. a computing device (12) configured to extend a remote home network (14) to a current location of the network device (10) such that one or more endpoint devices at the current location of the network device (10) can join the remote home network (14); a local cache (32) of data stored by said computing device (12); a housing (16) for supporting said computer equipment (120) and including a door (18) for accessing said computer equipment (120), said housing being constructed and arranged to be mobile and transportable and including a backup power supply (20) supported thereon; an access control mechanism for securing the housing (16) including an authentication information reader communicatively connected to the door and a locking device for securing the door in a locked position, the locking device being movable between a locked position and an unlocked position to allow access to the computer device; and a security control module communicatively connected to the access control mechanism and constructed and arranged to deny access to the housing by communicating an alert to the access control mechanism to prevent access to the housing; Equipped with When access to the housing is denied by the security control module, a shutdown protocol is initiated to protect the local cache (32) of data of the computing device (12), the shutdown protocol including transferring data from the local cache (32) of data to the remote home network (14), deleting the data from the local cache (32), and disabling access to the remote home network (14).

2. The system described in claim 1, wherein the predefined events are selected from a group including an unidentified user attempting to gain access to the computing device via an access control module, a failure to synchronize a local cache with a remote cache in the remote home network, a physical breach of the housing, and a loss of power.

3. 10. The system of claim 1, further comprising a local cache supported by said housing, said local cache containing a list of users authorized to access said computing device.

4. The system of claim 3 , wherein the local cache further includes a log of users who have accessed the credential reader.

5. 4. The system of claim 3, wherein the user credential data representing the user is compared to the local cache of authorized users for verification, and if a match is found, the door is unlocked.

6. 6. The system of claim 5, wherein the shutdown protocol is initiated in response to a predetermined number of attempts by a user whose authentication information does not match an authorized user when compared to the local cache of authorized users.

7. 2. The system of claim 1, wherein the security control module further comprises a local cache configured to remotely cache data that has not yet been synchronized with the remote home network, and the security control module is configured to synchronize the data in the local cache with the remote home network.

8. The system of claim 7 , wherein the access control mechanism is configured to deny access to the housing if the security control module fails to synchronize the local cache with the remote home network.

9. The system of claim 1 , further comprising a kill switch that disables access to the housing by deactivating the credential reader in response to initiation of the shutdown protocol.

10. The system described in claim 1, further comprising a fail-secure device (38) that sends a signal to a kill switch in response to a physical breach of the network device, and in response to receiving the signal, the kill switch clears the local cache and disables access of the network device to data stored on the remote home network of the computer device.

11. 11. The system of claim 10, wherein the fail-secure device is selected from the group including a glass shatter sensor that transmits the signal to the kill switch in response to detecting a physical breach by shattered glass, a lock sensor that transmits the signal to the kill switch in response to detecting a physical breach of the locking device, and a power sensor that transmits the signal to the kill switch in response to detecting a physical breach by loss of power.

12. a global positioning system supported by the housing; The system of claim 1, wherein the location of the network device (10) is remotely trackable.

13. A computing device (12) configured to extend a remote home network (14) to the current location of a mobile secure network device (10) such that one or more endpoint devices at the current location of the mobile secure network device (10) can join the remote home network (14); a local cache of data stored by the computing device; a housing for supporting said computer device and including a door for accessing said computer device, said housing being constructed and arranged to be mobile and transportable and including a backup power supply supported thereon; an access control mechanism for securing the housing (16) including a locking device for securing the door in a locked position, the locking device being movable between a locked position and an unlocked position to allow access to the computer device; a security control module communicatively connected to the access control mechanism and constructed and arranged to deny access to the housing (16) in response to the occurrence of one or more predefined events; Equipped with When access to the housing (16) is denied by the security control module, a shutdown protocol is initiated to physically secure the housing and protect the data contained in the local cache (32) by deleting data from the local cache and denying the computing device access to the cache of data stored on the remote home network (14).

14. The device described in claim 13, wherein, in response to access to the housing being denied by the security control module, the data from the local cache is transferred to the remote home network before deleting the data from the local cache.

15. 14. The device of claim 13, wherein the predefined event is selected from the group including an unauthorized user attempting to gain access to the computing device via an access control module, a failure to synchronize the local cache with a remote cache in the remote home network, a physical breach of the housing, and a loss of power.

16. 16. The device of claim 15, wherein the shutdown protocol is initiated in response to a predetermined number of attempts by a user whose authentication information does not match an authorized user when compared to the local cache containing a list of authorized users.

17. 14. The device of claim 13, further comprising a kill switch that disables access to the housing by deactivating a credential reader communicatively connected to the locking device in response to initiation of the shutdown protocol.

18. The device described in claim 17, further comprising a fail-secure device that deletes the local cache in response to a physical breach of the mobile secure network device and sends a signal to the security control module to deny access to the cache of data on the remote home network.

19. 20. The device of claim 18, wherein the fail-secure device is selected from the group including a glass shatter sensor that sends the signal to the kill switch in response to detecting a physical breach by shattered glass, a lock sensor that sends the signal to the kill switch in response to detecting a physical breach of the locking device, and a power sensor that sends the signal to the kill switch in response to detecting a physical breach by loss of power.

Citation Information

Patent Citations

  • Self-provisioning access control

    JP2020013591A

  • Secure computing environment in a transportable container

    US20100306544A1

  • Smart lock structure and operating method thereof

    US20130342314A1