Hierarchical Proxy Chain for Secure Remote Endpoint Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in configuring secure remote access to endpoint devices in multi-layered networks, particularly in industrial IoT settings, where exposing devices to the Internet poses significant security risks.

Innovation Solution

A device determines the hierarchy of network layers and configures a proxy chain of remote access agents across multiple networking devices to enable secure remote access, while enforcing access policies based on the endpoint's location in the hierarchy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the target device is exposed to the Internet for remote access, then remote accessibility is improved, but network security deteriorates

Engineering Contradiction:
Improveremote accessibilityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a remote access server as an intermediary between external users and target devices. The server establishes indirect connections through multiple network layers, allowing remote access without direct Internet exposure of target devices. The server acts as a mediator that forwards commands and data through the hierarchical network structure while maintaining security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network is segmented into multiple hierarchical layers (enterprise zone, DMZ, industrial zone, etc.), with each layer having specific security policies. The remote access server operates at higher layers and proxies connections through intermediate layers to reach target devices, allowing segmentation of security concerns and controlled access at each boundary.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If a proxy chain is configured across multiple network layers, then network security is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The remote access server automatically discovers the hierarchical network structure and configures proxy chains without manual intervention. The system self-organizes the connection path through multiple layers by querying network devices and determining the hierarchy, reducing operational complexity despite the sophisticated security architecture.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary discovery of the network hierarchy and pre-configures access policies before actual remote access sessions. By establishing the hierarchical structure and security rules in advance, the system simplifies real-time connection establishment while maintaining comprehensive security controls.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If access policies are enforced based on endpoint location, then network security is improved, but operational flexibility decreases

Engineering Contradiction:
Improvenetwork securityVSAvoidoperational flexibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

Access policies are dynamically determined based on the real-time hierarchical location of the endpoint device and the identity of the requesting user. The remote access server queries the network hierarchy and applies appropriate security policies on-the-fly, allowing flexible adaptation to different access scenarios while maintaining security requirements for each network layer.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12328204B2Cloud-based security controls for multi-level hierarchal equipment access
Publication Date: 2025.06.10 CISCO TECHNOLOGY INC
  • US12328204B2 patent drawing
  • US12328204B2 patent drawing
  • US12328204B2 patent drawing

AI summary

In one embodiment, a device determines a hierarchy of layers of a network comprising a plurality of networking devices. The device configures, in response to a request by a client to access remotely a particular endpoint in the network, a proxy chain of remote access agents executed by a plurality of networking devices in the network to allow the client to access remotely the particular endpoint. Each of those networking devices proxies traffic between different layers of the hierarchy. The device determines an access policy for the particular endpoint indicative of which commands may be sent to the particular endpoint by the client, based in part on where the particular endpoint is in the hierarchy. The device controls, based on the access policy, whether a command sent by the client is transmitted via the proxy chain to the particular endpoint.