Proxy Device Credential Provisioning for Secure Remote Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Connected household and industrial devices often lack unique IP addresses and are restricted by firewalls, making remote access and management difficult, while allowing unrestricted connections poses security vulnerabilities.

Innovation Solution

A centralized credential provisioning system instantiates a proxy device to facilitate secure remote connections between client devices and computing devices, using a device management service to manage proxy instances and exchange credentials, enabling communication through a lightweight protocol like MQTT.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If devices are deployed in locations without unique IP addresses or with firewall restrictions, then device deployment flexibility is improved, but remote accessibility deteriorates

Engineering Contradiction:
Improvedevice deployment flexibilityVSAvoidremote accessibility
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent introduces a gateway device as an intermediary between the restricted device and the external network. The gateway maintains a persistent connection to the device behind the firewall and forwards messages bidirectionally, enabling remote access without requiring the device to have direct network accessibility or unique IP address

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If devices accept connections from any device that can find them, then ease of connection is improved, but security vulnerability increases

Engineering Contradiction:
Improveconnection easeVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The gateway acts as a trusted intermediary that controls and filters all connections to the device. Instead of allowing direct connections from any external device, all communication must route through the gateway which validates and manages connections, maintaining security while enabling accessibility

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The device automatically establishes and maintains a persistent connection to the gateway, and the gateway automatically manages the forwarding of messages. This self-service mechanism eliminates the need for manual connection management while maintaining secure access control

Inventive Principle:
Principle #25Self-service

3Reliability

If physical connection or local network login is required for device reconfiguration, then security is improved, but operational convenience deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidoperational convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The gateway serves as a secure intermediary that the device can trust. Since the device already has an established secure connection with the gateway (which it initiated), the gateway can safely forward reconfiguration commands and credentials to the device without requiring physical presence or local network access

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3391616B1Device management with tunneling
Publication Date: 2020.04.22 AMAZON TECH INC
  • EP3391616B1 patent drawingFigure 1
  • EP3391616B1 patent drawingFigure 2
  • EP3391616B1 patent drawingFigure 3

AI summary

A device management service provide a centralized credential provisioning system which can instantiate a proxy device that facilitates remote connections between various computing devices and various client devices. The device management service can manage instances of proxy devices in a resource provider environment that are associated with various computing devices. When a client device requests to access a computing device, the device management service can identify an instance of a proxy device associated with the computing device. The instance of the proxy device and the computing device can be configured to securely connect using credentials exchanged through, and managed by, the device management service. The computing device can be instructed to connect to the instance of the proxy device, and the client device can be provided with access information for the instance of the proxy device.