Proxy Gateway Session Monitoring with Disposable Agent

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for monitoring sessions on target systems require additional network connections, specific privileges, and an uninstallation step that consumes server resources and poses security risks.

Innovation Solution

A method involving a proxy gateway that establishes a secondary session for agent installation, using a disk redirection and time-delay script to copy the agent to a temporary directory, eliminating the need for explicit uninstallation and enhancing security by automatically destroying the directory at session end.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a temporary agent is installed on the target system to monitor sessions, then session monitoring capability is improved, but device complexity and security risks increase due to installation and uninstallation steps

Engineering Contradiction:
Improvesession monitoring capabilityVSAvoidinstallation and uninstallation steps
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses a temporary agent that is automatically created during session establishment and automatically removed when the session ends. The agent exists only for the duration of the session, eliminating the need for manual installation and uninstallation steps. This disposable approach reduces complexity and security risks while maintaining monitoring capability.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The session monitoring mechanism is self-managing through automatic agent deployment and removal. The system automatically creates the temporary agent when a session is established and automatically removes it when the session terminates, without requiring user intervention or separate uninstallation steps.

Inventive Principle:
Principle #25Self-service

2Reliability

If a temporary agent is installed for session monitoring, then monitoring function is improved, but loss of time occurs due to explicit uninstallation step

Engineering Contradiction:
Improvesession monitoring functionVSAvoiduninstallation step
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The temporary agent is designed to self-terminate automatically when the session ends. The agent monitors its own lifecycle and removes itself without requiring external uninstallation commands, thereby eliminating time loss associated with manual removal steps.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The monitoring function continues seamlessly from session start to session end without interruption. The agent remains active throughout the entire session duration and automatically cleans up upon session termination, ensuring continuous monitoring without gaps or additional time-consuming steps.

Inventive Principle:
Principle #20Continuity of useful action

3Ease of manufacture

If additional network connections and privileges are used for agent installation, then agent deployment is achieved, but use of energy and security risks increase

Engineering Contradiction:
Improveagent deploymentVSAvoidnetwork connections and privileges
Core Design Contradiction:
Ease of manufactureVSUse of energy by moving object

Solution Approach 1:

The patent employs a lightweight temporary agent that is quickly deployed and removed. This disposable approach minimizes the duration and intensity of network connections required, reducing energy consumption compared to permanent agents that require sustained privileged access.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The system changes the temporal parameter of agent presence from permanent to temporary. By limiting the agent's lifetime to the session duration only, the cumulative energy consumption and security exposure are significantly reduced while maintaining deployment capability.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10594662B2Method for secure connection from a client computer device to a computer resource
Publication Date: 2020.03.17 WALLIX
  • US10594662B2 patent drawing
  • US10594662B2 patent drawing

AI summary

The application relates to a method for secure connection from a client computer device to a target computer resource comprising a server, comprising the following steps: the emission of a session-opening request by an application installed on the client station, leading to the creation of a primary session between the client station and the proxy gateway, the request containing either the identifier of the target server or the identifier of the target application; and the opening of a session between the proxy gateway and the server. The request-emission step is implemented by the prior opening of a primary session [RDP] between the client station and the proxy gateway by the transmission of a message containing the identifier of the target server or the identifier of the target application.