Gateway Service for Secure On-Premises Remote Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing hybrid cloud environments face challenges in providing resilient and interactive command access to on-premises devices, especially over unreliable networks, due to network, access, and security issues.
Innovation Solution
A gateway service is implemented to manage connections between remote support service agents and on-premises devices, involving consent from authorized users, creation of limited-session connections, provisioning of device-specific hybrid connection endpoints, and forming secure sessions to ensure data and command transport within defined consent scopes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If direct inbound connections are allowed from remote support agents to on-premises devices, then remote access capability is improved, but security risk increases
Solution Approach 1:
A gateway service is introduced as an intermediary component between remote support agents and on-premises devices. The gateway receives connection requests from remote agents, obtains consent from authorized users, and establishes sessions that bridge the two parties without allowing direct peer-to-peer connections. This mediator architecture enables remote access while maintaining security boundaries.
Solution Approach 2:
The system requires preliminary consent from an authorized user associated with the on-premises device before any remote connection is established. The gateway service obtains this consent in advance, defines the scope of permitted operations, and enforces these constraints throughout the session. This preliminary authorization prevents unauthorized access while enabling legitimate remote support.
2Reliability
If session scope is limited to individual sessions, then security control is improved, but session management complexity increases
Solution Approach 1:
The gateway service dynamically creates and manages sessions with defined scopes that are specific to each individual session. Each session has its own consent scope that determines what operations are permitted. The system adapts the session configuration based on the specific support scenario, allowing flexible security control without requiring a rigid complex structure.
Solution Approach 2:
Access control is segmented into individual session-level permissions rather than broad continuous access. Each session is independently created with its own scope definition, allowing the system to provide fine-grained security control. The gateway manages multiple segmented sessions rather than a single monolithic connection, improving security while keeping each session's management straightforward.
Data Source
AI summary
Systems and methods for remote command access in a hybrid cloud to on-premises devices are described. An example method includes receiving, by a gateway service, a request for a connection between a remote support service agent and an on-premises device. The method further includes receiving, by the gateway service, consent from an authorized user associated with the on-premises device. The method further includes creating, by the gateway service, a first session with the on-premises device, where a scope of the consent is limited to the first session. The method further includes provisioning, by the gateway service, a device-specific hybrid connection endpoint for the first session. The method further includes forming, by the gateway service a secure session by binding the device-specific hybrid connection endpoint with a second session, the secure session allowing for transport of data and a set of commands based on a scope of the consent.


