Gateway Device Secure Ephemeral Access to Premise Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for remote access to network devices, particularly those with insecure configurations, face challenges in providing secure and dynamic access while preventing unauthorized access, leading to potential security breaches and losses.

Innovation Solution

A system utilizing a gateway device that manages network connections and employs strong authentication methods, coupled with ephemeral secure connections and address translation, to enable secure remote access to premise devices while isolating them from unauthorized remote addresses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If remote access to premise devices is enabled through conventional firewalls allowing connections from any address, then accessibility and ease of operation are improved, but security and reliability deteriorate due to unauthorized access risks

Engineering Contradiction:
Improveremote accessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a gateway device as an intermediary between remote users and premise devices. The gateway establishes secure tunnel connections that mediate all communication, preventing direct unauthorized access to premise devices while enabling controlled remote access. The gateway acts as a security boundary that filters and manages all connection attempts.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments network connections into distinct secure tunnels for each authorized user. Each tunnel is isolated and dedicated to a specific authenticated user, preventing cross-user access and limiting the attack surface. This segmentation allows multiple users to access the network simultaneously with individual security contexts.

Inventive Principle:
Principle #1Segmentation

2Reliability

If fixed location and address access is configured in conventional firewalls, then security is improved by limiting access sources, but adaptability deteriorates as dynamic access from different locations is prevented

Engineering Contradiction:
ImprovesecurityVSAvoiddynamic access capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The gateway device dynamically creates and manages secure tunnel connections based on authentication events. Rather than relying on static firewall rules, the system adapts to each authenticated user by creating personalized secure access paths. The gateway can accommodate users from any location as long as they are properly authenticated, providing dynamic adaptability while maintaining security.

Inventive Principle:
Principle #15Dynamics

3Reliability

If ephemeral secure connections are implemented through gateway devices, then security is improved by automatically terminating connections, but device complexity increases due to connection management overhead

Engineering Contradiction:
ImprovesecurityVSAvoidconnection management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway device implements automatic connection termination through ephemeral tunnel technology. Each secure tunnel is automatically created upon authentication and automatically terminated when the user session ends or the gateway detects inactivity. This self-managing behavior eliminates the need for manual connection cleanup and reduces security risks from abandoned connections without requiring complex manual management procedures.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11750585B2Secure ephemeral access to insecure devices
Publication Date: 2023.09.05 SCALE COMPUTING INC
  • US11750585B2 patent drawing
  • US11750585B2 patent drawing
  • US11750585B2 patent drawing

AI summary

Embodiments are described for establishing a connection between a premise device and a remote user. A security message may be received from an authentication server. The security message may include an origination address of a request from an authenticated remote user. Connections may be allowed from the origination address of the authenticated remote user with the premise device. A timer may be started which counts an amount of time that the connections are allowed. Forwarding may be enabled of connection data between the premise device and the remote user. An acknowledgement message may be sent to the authentication server indicating completion of preparation of the remote access.