Outbound IT Product Connection for Secure Remote Support

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote IT support methods often face security constraints that prevent IT support providers from initiating inbound connections, limiting their ability to assist users within private networks, even though inbound connections are blocked by customer security measures.

Innovation Solution

Implementing a method that uses outbound connections, such as 'call home' functionality, where IT products in a private cloud connect to a database within the vendor's network to execute commands and send results without requiring inbound access, ensuring secure remote support without violating customer security rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If inbound connections are blocked by customer security measures, then network security is improved, but remote support capability deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidremote support capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Instead of the support provider initiating an inbound connection to the customer's private network (conventional approach), the invention inverts the connection direction by having the customer's IT product initiate an outbound connection to the support provider's database. This reversal allows remote support functionality to work around the firewall security constraint, enabling command execution and data retrieval without requiring inbound access to the private network.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The invention introduces a database as an intermediary component that facilitates secure communication between the private network and the support provider. The database receives outbound connections from IT products, stores commands and results, and communicates with support providers without requiring direct inbound access to the private network. This intermediary architecture enables remote support while maintaining network security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If outbound connections are used instead of inbound connections, then remote support capability is improved, but connection security control deteriorates

Engineering Contradiction:
Improveremote support capabilityVSAvoidconnection security control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The invention implements a feedback mechanism where the database stores command results and sends them back to the support provider through the outbound connection. The IT product executes commands, captures results, and returns them to the database, which then communicates with the support provider. This feedback loop ensures that security-critical operations are monitored and controlled while enabling remote support functionality.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11909720B2Secure remote support of systems deployed in a private network
Publication Date: 2024.02.20 KYNDRYL INC
  • US11909720B2 patent drawing
  • US11909720B2 patent drawing
  • US11909720B2 patent drawing

AI summary

A computer-implemented method includes: connecting, by a computing device, to a database using an outbound connection, wherein the computing device is an information technology (IT) product in a private network and the database is outside the private network; receiving, by the computing device, a response from the database, the response including a command; executing, by the computing device, the command; and sending, by the computing device, result data to the database, wherein the result data is data that results from executing the command on the computing device.