Proxy-Chain Remote Access Across Layered IoT Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Configuring secure remote access to endpoint devices in multi-layered IoT and IIoT networks is challenging due to the need to span multiple network layers while avoiding security risks, as exposing devices to the Internet can allow malicious entities to take control.
Innovation Solution
A discovery mechanism is used to identify networking devices capable of forming a proxy chain across network layers, allowing external clients to access endpoints securely by determining the network hierarchy and configuring proxy agents to proxy traffic between layers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the target device is exposed to the Internet for remote access, then remote access capability is improved, but security risk increases allowing malicious entities to take control
Solution Approach 1:
The patent introduces a remote access gateway as an intermediary device that mediates all remote access requests to IoT devices. The gateway establishes secure connections and forwards authenticated traffic to target devices, preventing direct Internet exposure. This intermediary architecture enables remote access while maintaining security by controlling and filtering all traffic through a trusted gateway rather than exposing devices directly to the Internet.
2Reliability
If a remote access gateway is introduced to secure connections, then security is improved, but device complexity increases due to multi-layered network configuration
Solution Approach 1:
The patent implements automatic discovery mechanisms where the remote access gateway autonomously discovers IoT devices on the local network and dynamically generates appropriate routing rules. The system performs self-configuration by automatically establishing secure tunnels and mapping device addresses without requiring manual network administration. This self-service approach maintains high security through enforced gateway mediation while reducing configuration complexity through automation.
Solution Approach 2:
The system performs preliminary actions by pre-establishing secure communication channels and authentication mechanisms before actual remote access requests occur. The gateway pre-discovers devices, pre-configures security policies, and pre-establishes trusted connections, so that when remote access is needed, the configuration work is already complete and the process is simplified.
3Reliability
If direct Internet exposure is avoided for security, then security is improved, but remote access capability deteriorates
Solution Approach 1:
The patent transitions from direct one-to-one Internet connectivity to a multi-dimensional access architecture where the gateway operates as an intermediate layer. Remote access requests traverse multiple dimensions: from the Internet through the gateway's external interface, across secure internal channels, to the target device's local interface. This dimensional transformation maintains security by preventing direct exposure while preserving access capability through the added gateway dimension.
Data Source
AI summary
In one embodiment, a device receives discovery data generated by a plurality of networking devices in a network. The device determines, based on the discovery data, a hierarchy of layers of the network. The device receives a request by a client that is external to the network to access remotely a particular endpoint in the network. The device configures, and in response to the request, a proxy chain of remote access agents executed by a subset of networking devices from the plurality of networking devices to allow the client to access remotely the particular endpoint, each of those networking devices proxying traffic between different layers of the network.


