Central Console Remote Device Configuration via Signed Messaging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic messaging systems face challenges in remotely configuring devices within networks with multiple security-trust boundaries, as traditional methods require direct connectivity or physical presence and often involve opening multiple ports, making them vulnerable to attacks.

Innovation Solution

The solution employs a standard messaging transport protocol using an existing open port to remotely configure devices, with command/control information encoded in hidden fields of messages that are digitally signed for authentication, allowing secure and centralized monitoring and reporting of configuration status changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If direct connectivity or physical presence is required to configure devices, then configuration control is secure, but remote accessibility and operational convenience deteriorate

Engineering Contradiction:
Improveremote configuration accessibilityVSAvoidsecurity-trust boundary protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary mechanism (messaging system with digital signatures and hidden fields) that enables remote configuration without requiring direct connectivity or physical presence. The intermediary validates commands through digital signatures while keeping configuration channels separate from data channels, thus maintaining security-trust boundaries while improving remote accessibility

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The configuration system is segmented into separate command/control channels and data channels. Command/control information is embedded in hidden fields of messaging protocol data units, allowing configuration commands to be transmitted through existing open ports without opening additional ports, thus maintaining security while enabling remote access

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple ports are opened for remote configuration, then configuration capability is enhanced, but vulnerability to attacks increases

Engineering Contradiction:
Improveremote configuration capabilityVSAvoidvulnerability to attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent makes the existing messaging protocol port multi-functional by embedding command/control information in hidden fields of regular messaging data units. This allows the same open port to handle both data communication and device configuration, eliminating the need to open additional ports for configuration purposes, thus maintaining configuration capability while reducing vulnerability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The messaging system acts as an intermediary that securely transmits configuration commands through existing open ports. Digital signatures and validation mechanisms within the messaging protocol provide security verification without requiring additional open ports, reducing the attack surface while maintaining remote configuration capability

Inventive Principle:
Principle #24Intermediary (Mediator)

3Extent of automation

If configuration status monitoring is implemented across multiple devices, then centralized control is improved, but system complexity increases

Engineering Contradiction:
Improvecentralized monitoring capabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where configuration status information is automatically reported back to the messaging system. The system tracks configuration requests and status changes through the messaging protocol, enabling centralized monitoring of multiple devices without requiring complex dedicated monitoring infrastructure, thus improving automated control while managing system complexity

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7509678B2Central console for monitoring configuration status for remote devices
Publication Date: 2009.03.24 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7509678B2 patent drawing
  • US7509678B2 patent drawing
  • US7509678B2 patent drawing

AI summary

The present invention allows for remotely and securely configuring settings for targeted devices within a network with multiple security-trust boundaries. Configuration information is encoded in messages that are digitally signed to ensure the integrity of the configuration information and sent in accordance with a standard messaging transport protocol. By utilizing an already existing port of the standard messaging transport protocol, e.g., SMTP, the number of open ports for configuration purposes is minimized. Further, example embodiments take advantage of hidden fields, i.e., machine readable fields that contain metadata that by default are not presented at a client user interface, for encoding the configuration or command/control information within the messages. The present invention further provides for a central console module that can manage and report on the status of the configuration settings for a plurality of targeted devices that an authorized user or system administrator has attempted to remotely configure.