Cloud Reflector for Secure Controller Remote Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for remote access to control systems, such as VPN connections and port forwarding, are insecure and require user configuration, posing risks and inconvenience.
Innovation Solution
A system utilizing a cloud server and security tokens, like JSON Web Tokens, to establish secure remote access by linking a client device directly to a controller via a reflector service, allowing secure communication and automation commands without needing separate links, thus bypassing security service traversal and reducing configuration needs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional remote access methods (VPN connections, port forwarding) are used, then remote access capability is achieved, but security risks increase and user configuration complexity increases
Solution Approach 1:
The patent introduces a cloud server as an intermediary between the controller and client device. The cloud server establishes a reflective link that enables remote access without requiring direct connections through firewalls or port forwarding. This mediator approach eliminates the need for users to configure complex network settings while maintaining security, as the cloud server handles the connection management and authentication processes.
2Reliability
If multiple separate communication links are established for remote access, then communication reliability is improved, but device complexity increases
Solution Approach 1:
The patent merges multiple communication functions into a single reflective link established through the cloud server. Instead of requiring separate links for different communication purposes, the reflective link consolidates these functions, allowing bidirectional communication between the controller and client device through one unified connection. This reduces the number of communication links from multiple to one, simplifying the system while maintaining communication reliability.
3Reliability
If security service traversal is required for remote access, then network security is maintained, but setup complexity and time increase
Solution Approach 1:
The cloud server performs preliminary actions by pre-establishing the reflective link and handling authentication before the user needs to access the controller. The security service traversal is completed in advance by the cloud server's automated processes, eliminating the need for users to manually configure security settings or wait for complex authentication sequences. This preliminary setup reduces both setup time and complexity while maintaining network security.
Data Source
AI summary
A method for providing secure remote access by a controller is described. The method includes establishing a link through a security service to a client device via a cloud server based on a security token from the client device. The method also includes receiving a command message from the client device for an application program interface (API) located within the controller. The command message is forwarded by the cloud server. The method further includes producing an automation command based on the command message. The API interprets the command message.


