Gateway Service for Secure On-Premises Remote Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing hybrid cloud environments face challenges in providing resilient and interactive command access to on-premises devices, especially over unreliable networks, due to network, access, and security issues.

Innovation Solution

A gateway service is implemented to manage connections between remote support service agents and on-premises devices, involving consent from authorized users, creation of limited-session connections, provisioning of device-specific hybrid connection endpoints, and forming secure sessions to ensure data and command transport within defined consent scopes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If direct inbound connections are allowed from remote support agents to on-premises devices, then remote access capability is improved, but security risk increases

Engineering Contradiction:
Improveremote access capabilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

A gateway service is introduced as an intermediary component between remote support agents and on-premises devices. The gateway receives connection requests from remote agents, obtains consent from authorized users, and establishes sessions that bridge the two parties without allowing direct peer-to-peer connections. This mediator architecture enables remote access while maintaining security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system requires preliminary consent from an authorized user associated with the on-premises device before any remote connection is established. The gateway service obtains this consent in advance, defines the scope of permitted operations, and enforces these constraints throughout the session. This preliminary authorization prevents unauthorized access while enabling legitimate remote support.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If session scope is limited to individual sessions, then security control is improved, but session management complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoidsession management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway service dynamically creates and manages sessions with defined scopes that are specific to each individual session. Each session has its own consent scope that determines what operations are permitted. The system adapts the session configuration based on the specific support scenario, allowing flexible security control without requiring a rigid complex structure.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Access control is segmented into individual session-level permissions rather than broad continuous access. Each session is independently created with its own scope definition, allowing the system to provide fine-grained security control. The gateway manages multiple segmented sessions rather than a single monolithic connection, improving security while keeping each session's management straightforward.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12316603B2Remote command access in a hybrid cloud to on-premises devices
Publication Date: 2025.05.27 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12316603B2 patent drawing
  • US12316603B2 patent drawing
  • US12316603B2 patent drawing

AI summary

Systems and methods for remote command access in a hybrid cloud to on-premises devices are described. An example method includes receiving, by a gateway service, a request for a connection between a remote support service agent and an on-premises device. The method further includes receiving, by the gateway service, consent from an authorized user associated with the on-premises device. The method further includes creating, by the gateway service, a first session with the on-premises device, where a scope of the consent is limited to the first session. The method further includes provisioning, by the gateway service, a device-specific hybrid connection endpoint for the first session. The method further includes forming, by the gateway service a secure session by binding the device-specific hybrid connection endpoint with a second session, the secure session allowing for transport of data and a set of commands based on a scope of the consent.