Edge Device Secure Remote Support for Unbooted Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Remote technical support systems face challenges in providing secure and efficient troubleshooting and device management, especially when the target device cannot boot up or has issues with network connectivity, as they rely on established Internet connections and secure VPN or NAC software execution, which may not function without proper boot-up or power.
Innovation Solution
A system utilizing an edge device that establishes a secure connection with a trusted server, allowing remote technicians to access and control target devices through a secure protocol, using cryptographic keys for message validation and efficient communication paths via USB microcontrollers, enabling data collection, control, and feedback even when the target device is not fully operational.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If remote support software is used to provide technical support, then support technicians can collect information and remotely control devices, but the system requires established Internet connection and VPN/NAC software execution which may not function when devices cannot boot up or have power issues
Solution Approach 1:
The patent introduces an intermediary device (such as a USB dongle or external controller) that mediates between the remote support technician and the target device. This intermediary contains the necessary software components (VPN client, NAC agent, remote support agent) that would normally need to run on the target device itself. By offloading these requirements to a separate intermediary device that connects to the target device via USB or similar interface, the system can provide remote support even when the target device's operating system is not running or network stack is unavailable.
2Reliability
If secure remote support relies on VPN software or NAC software, then security is maintained, but these software components will not execute if the computer cannot boot up or has software loading issues
Solution Approach 1:
The intermediary device hosts the VPN and NAC software components separately from the target device's operating system. This allows security protocols to be established and maintained through the intermediary device's own operating system, while still providing secure access to the target device through the intermediary's connection to the target device's hardware interfaces.
Solution Approach 2:
The intermediary device is pre-configured with security credentials, VPN certificates, and NAC policies before connecting to the target device. This preliminary setup ensures that security authentication can be performed immediately upon connection without requiring the target device's OS to be functional, allowing secure remote support sessions to be established even in boot-failure scenarios.
3Reliability
If the computer loads network interface drivers after boot-up, then network connectivity is established, but issues during boot-up sequence or power-related problems prevent this loading process
Solution Approach 1:
The intermediary device provides network connectivity and communication capabilities independently of the target device's boot sequence. By using the intermediary as a communication bridge (connecting via USB to the target device while having its own network stack), the system bypasses the need for network drivers to load on the target device during boot-up, eliminating the boot-up sequence dependency for remote support functionality.
Data Source
AI summary
A secure, remote support platform allows secure, remote device support with an edge device (101) and a trusted intermediary server resource (“trusted server”). The trusted server (113) is an endpoint for secure connections with a support application used by a remote technician and with the edge device. The secure connections carry messages with inputs, data requests, and feedback. Messages between the trusted server and support edge device are secured in a manner that allows each endpoint to validate the messages. The remote technician controls the edge device to assesses a target device connected to the edge device. The edge device presents emulated peripheral devices to the target device while capturing the target device desktop with a camera or presents remotely controlled peripherals and returns screen captures or updates of the desktop from the target device.


