Connectivity Platform Zero-Trust Gateway for OEM Remote Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional remote access technologies are vulnerable to security breaches due to weak user authentication policies, unsecured networks, lack of visibility into remote user activity, and inadequate physical security controls, posing risks for organizations that need secure remote connections, such as Original Equipment Manufacturers (OEMs) and fabrication plants (FABs).

Innovation Solution

The Connectivity platform provides a secure, scalable, and reliable connectivity solution that enables authorized access for OEM engineers to equipment located in FABs, employing a zero-trust policy, multi-tenancy, and advanced security features like Remote Take Over (RTO), Remote Command Execution (RCE), and secure file transfer, while ensuring data privacy and intellectual property protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional remote access technologies are used to enable remote connections between OEMs and FABs, then connectivity and collaboration are improved, but security vulnerabilities and risk of unauthorized access increase

Engineering Contradiction:
Improveremote connectivityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a gateway device as an intermediary between the remote user and the target device. This gateway establishes separate encrypted connections with both parties, mediating all communication through a secure intermediate point rather than allowing direct connection, thereby eliminating security vulnerabilities while maintaining connectivity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical security measures (physical security, direct network connections) with cryptographic mechanisms (encryption, authentication protocols). Security is achieved through mathematical algorithms rather than physical barriers, enabling secure remote access without direct network exposure

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If direct connection is established between OEM network and FAB network for remote access, then access simplicity is improved, but network security and data protection deteriorate

Engineering Contradiction:
Improveconnection simplicityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The gateway device serves as a mediator that simplifies the connection process for users while simultaneously protecting network security. Users interact with the gateway through a simple interface, but the gateway handles complex security protocols and encrypted tunnel establishment, achieving both simplicity and security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network connection into separate encrypted tunnels: one between the user and gateway, another between the gateway and target device. This segmentation isolates network segments, preventing direct exposure while maintaining connectivity through controlled encrypted channels

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If traditional authentication policies are implemented for remote access, then user convenience is improved, but authentication security and access control effectiveness worsen

Engineering Contradiction:
Improveuser convenienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transforms authentication from simple credential verification to a multi-parameter process involving device fingerprinting, cryptographic key exchange, session token generation, and continuous authentication. This changes the authentication parameters from basic username/password to complex cryptographic verification, significantly enhancing security while maintaining user convenience through automated processes

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If remote access is enabled without oversight mechanisms, then operational flexibility is improved, but visibility into user activity and security monitoring deteriorate

Engineering Contradiction:
Improveoperational flexibilityVSAvoiduser activity visibility
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The gateway device implements continuous feedback mechanisms by monitoring all communications passing through it. It logs authentication events, tracks user actions, detects anomalies in real-time, and provides visibility into remote activity. This feedback enables security monitoring and auditing while maintaining operational flexibility through automated response protocols

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250168166A1System and method for a connectivity platform and remote management
Publication Date: 2025.05.22 CAPGEMINI SEMICONNEXT PLATFORM BV
  • US20250168166A1 patent drawing
  • US20250168166A1 patent drawing
  • US20250168166A1 patent drawing

AI summary

A system and method providing a secure, scalable, reliable, and transparent connectivity platform between an Original Equipment Manufacturer (OEM) side and OEM customer production plants (FAB) side. The zero-trust architecture facilitates the transport of data to and from equipment located on the FAB side and provides access for service engineers, for example, to remotely operate the equipment. The connectivity platform includes a plurality of innovative networking applications to provide secure access to authorized users.