Remote Access System with Unidirectional Data Streaming
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for secure communication in remote, contested, or unfriendly environments rely on pre-distribution of contact information and logging into enterprise services from potentially untrusted networks, risking data loss or compromise.
Innovation Solution
The solution enables secure remote access to a Target Device while preventing data flow from the Host Device to the Target Device, allowing ephemeral access and limiting data transfer to streaming audio and video, thereby maintaining data security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a burner phone is used to maintain communication continuity in remote environments, then communication availability is improved, but data security and information protection deteriorate due to potential data loss or compromise
Solution Approach 1:
The system segments the device into a Host Device (burner phone) and a Target Device (secure device), separating communication functions from data storage. The Host Device handles only communication tasks while the Target Device maintains secure data storage, allowing continuous communication without compromising data security.
Solution Approach 2:
The system introduces an intermediary architecture where the Host Device connects to the Target Device through controlled data flow channels. This intermediary structure allows communication continuity while preventing unauthorized data transfer to untrusted environments, resolving the contradiction between availability and security.
2Adaptability or versatility
If access to enterprise services is enabled from untrusted network environments, then communication flexibility is improved, but data loss or compromise risk increases
Solution Approach 1:
The system applies local quality by creating a secure enclave (Target Device) with different security characteristics from the Host Device. The Target Device maintains trusted data storage and processing capabilities, while the Host Device operates in untrusted environments, allowing flexibility without compromising data integrity.
Solution Approach 2:
The Host Device functions as a disposable burner phone that can be discarded or replaced without affecting data security. The critical data and security credentials remain on the Target Device, allowing the system to tolerate the loss or compromise of the Host Device while maintaining data security.
3Ease of operation
If critical applications and data are stored on the business or personal phone, then operational readiness is improved, but vulnerability to confiscation or data loss increases
Solution Approach 1:
The system extracts critical applications and data from the Host Device and relocates them to the Target Device. This extraction eliminates the vulnerability of having valuable data on a confiscable device, while the Host Device can still access these resources through the established connection for operational readiness.
Solution Approach 2:
The system moves data and applications from the physical dimension (stored on the Host Device) to the virtual dimension (accessed through remote connection to Target Device). This dimensional change allows operational readiness without physical possession of critical data, reducing confiscation vulnerability.
4Ease of operation
If data transfer is enabled from Host Device to Target Device, then data accessibility is improved, but security and information protection deteriorate
Solution Approach 1:
The system inverts the traditional data flow direction by allowing data to move from the Target Device to the Host Device for display and processing, while blocking the reverse flow from Host Device to Target Device. This inversion maintains data accessibility while preventing information leakage to untrusted environments.
Solution Approach 2:
The system extracts data access functionality from the Host Device and implements it through controlled channels from the Target Device. Data is extracted from the secure Target Device environment and made accessible to the Host Device through monitored pathways, maintaining both accessibility and protection.
Data Source
AI summary
A mobile communications system comprises a host device and a target device. A connection is established between the host device and the target device. Remote desktop protocol permits mirroring of audio and video originated from the target device on the host device, and prohibits data transmission of data from the target device to the host device.


