Remote Access Man-in-the-Middle Prevention via Signed Key Fingerprints
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Intermediate signaling services used for establishing peer-to-peer connections in remote network access are vulnerable to man-in-the-middle attacks, where malicious parties can tamper with connectivity information, compromising the security of data transmission between network devices.
Innovation Solution
A method that involves generating a data item including a public key or its fingerprint by the second network device, cryptographically signing it using a trusted network service, and verifying the signature and network address through an intermediate signaling service to ensure authenticity and prevent tampering, allowing secure remote network access only after validation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If an intermediate signaling service is used to establish peer-to-peer connections, then remote network access between devices on different networks is enabled, but the service becomes vulnerable to man-in-the-middle attacks where connectivity information can be tampered with
Solution Approach 1:
The patent applies preliminary action by having the second network device generate and send its public key to the first network device before the peer-to-peer connection is established. This advance provision of authentication information allows the first device to verify the identity of the second device before any data transmission occurs, preventing man-in-the-middle attacks where connectivity information might be tampered with during the connection setup process
Solution Approach 2:
The patent uses the public key as an intermediary authentication mechanism between the two network devices. Instead of directly trusting the signaling service, the devices use cryptographic keys as a mediator to verify each other's identities. The public key acts as a digital credential that proves ownership of the corresponding private key, enabling secure authentication without requiring direct trust in the signaling service
Data Source
AI summary
A method of enabling a remote access to a first network device from a second network device includes the second device generating a data item signed by a network service trusted by the first device, and including a fingerprint of a public key of the second device. The signed data item is sent to the first device via a signalling service, SIGS, as part of a negotiation of terms for a peer-to-peer connection. The first device uses the received signed data item to verify that the terms it receives from the SIGS has not been tampered with by the SIGS, in order to prevent the SIGS from performing a Man-In-The-Middle attack. Various network devices and a network system are also provided.


