Proxy Device Credential Provisioning for Secure Remote Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Connected household and industrial devices often lack unique IP addresses and are restricted by firewalls, making remote access and management difficult, while allowing unrestricted connections poses security vulnerabilities.
Innovation Solution
A centralized credential provisioning system instantiates a proxy device to facilitate secure remote connections between client devices and computing devices, using a device management service to manage proxy instances and exchange credentials, enabling communication through a lightweight protocol like MQTT.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If devices are deployed in locations without unique IP addresses or with firewall restrictions, then device deployment flexibility is improved, but remote accessibility deteriorates
Solution Approach 1:
The patent introduces a gateway device as an intermediary between the restricted device and the external network. The gateway maintains a persistent connection to the device behind the firewall and forwards messages bidirectionally, enabling remote access without requiring the device to have direct network accessibility or unique IP address
2Ease of operation
If devices accept connections from any device that can find them, then ease of connection is improved, but security vulnerability increases
Solution Approach 1:
The gateway acts as a trusted intermediary that controls and filters all connections to the device. Instead of allowing direct connections from any external device, all communication must route through the gateway which validates and manages connections, maintaining security while enabling accessibility
Solution Approach 2:
The device automatically establishes and maintains a persistent connection to the gateway, and the gateway automatically manages the forwarding of messages. This self-service mechanism eliminates the need for manual connection management while maintaining secure access control
3Reliability
If physical connection or local network login is required for device reconfiguration, then security is improved, but operational convenience deteriorates
Solution Approach 1:
The gateway serves as a secure intermediary that the device can trust. Since the device already has an established secure connection with the gateway (which it initiated), the gateway can safely forward reconfiguration commands and credentials to the device without requiring physical presence or local network access
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A device management service provide a centralized credential provisioning system which can instantiate a proxy device that facilitates remote connections between various computing devices and various client devices. The device management service can manage instances of proxy devices in a resource provider environment that are associated with various computing devices. When a client device requests to access a computing device, the device management service can identify an instance of a proxy device associated with the computing device. The instance of the proxy device and the computing device can be configured to securely connect using credentials exchanged through, and managed by, the device management service. The computing device can be instructed to connect to the instance of the proxy device, and the client device can be provided with access information for the instance of the proxy device.