Remote Access Service Inspector Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional corporate firewall technologies are inadequate in protecting networks from remote attacks and virus infections, especially when devices connected through VPNs, as they do not provide protection against intrusions from remote devices and can spread viruses to other machines on the network.

Innovation Solution

The RAS Inspector system performs a series of inspections on remote access clients, including digital hash comparisons, live updates of virus definitions, validation of anti-virus software, and checks for operating system patches, before allowing access to a VPN, ensuring that only compliant devices connect to the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewall products are used to regulate traffic between physical networks, then access control based on rules is improved, but protection against remote device intrusions and virus spread is insufficient

Engineering Contradiction:
Improvenetwork securityVSAvoidprotection coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the network access control into multiple layers: traditional firewall rules for basic traffic control, and a new inspection mechanism that segments devices into quarantined and non-quarantined states based on security compliance. This allows the system to maintain basic firewall functionality while adding specialized protection for remote devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary inspection mechanism between the traditional firewall and network access. This intermediary layer performs security checks, virus scanning, and compliance verification on remote devices before allowing full network access, thereby extending protection coverage without replacing existing firewall functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If remote devices are allowed to connect to the corporate network through VPN, then remote access capability is improved, but the risk of virus infection and unauthorized access increases

Engineering Contradiction:
Improveremote access capabilityVSAvoidvirus infection risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security actions before granting full network access. Remote devices must undergo inspection, virus scanning, and compliance verification while in a quarantined state. Only after passing these preliminary security checks are devices allowed to access the full corporate network, thereby enabling remote access while mitigating virus risks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies preliminary anti-action by implementing a quarantine mechanism that prevents potentially harmful remote devices from accessing the network until they prove secure. The system proactively blocks access for uninspected devices and only removes restrictions after verifying security compliance, countering potential threats before they can affect the network.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If anti-virus applications are installed on all machines, then protection against virus infiltration is improved, but the complexity of ensuring current virus definitions across all devices increases

Engineering Contradiction:
Improvevirus protectionVSAvoidvirus definition management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where the inspection system continuously monitors remote devices for security compliance, including virus definition currency. The system provides feedback to devices about their compliance status and can enforce remediation actions. This centralized feedback approach simplifies the management complexity by providing automated monitoring and reporting rather than requiring manual tracking of each device.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent enables self-service by requiring remote devices to automatically perform security self-assessments, virus scans, and compliance verifications as part of the quarantine inspection process. Devices must demonstrate their own security posture without requiring manual intervention from administrators, thereby reducing management complexity while maintaining high virus protection standards.

Inventive Principle:
Principle #25Self-service

4Reliability

If inspection mechanisms are implemented to ensure device security before network access, then network security is improved, but the time required for remote access establishment increases

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements periodic action by conducting security inspections in structured phases during the quarantine period. Rather than requiring a single lengthy inspection before access, the system performs security checks at periodic intervals throughout the quarantine state, allowing devices to progressively demonstrate compliance. This phased approach balances security verification with reasonable access establishment time.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11522839B1Remote access service inspector
Publication Date: 2022.12.06 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11522839B1 patent drawing
  • US11522839B1 patent drawing
  • US11522839B1 patent drawing

AI summary

A method, system, and computer program product for providing protected remote access from a remote access client to a remote access server over a computer network through a plurality of inspections. A remote access configuration file is created for the remote access client. A digital hash of the configuration file is then generated. The digital hash is compared with a configuration file stored at a predefined web location. If the comparison results in a match between the digital hash and the stored configuration file, a digital hash comparison is performed between an encrypted remote access configuration file and an encrypted configuration file stored at the predefined web location. If the plurality of inspections are passed, the remote access client is released from a quarantine state and a virtual private network (VPN) connection to the remote access server is established.