Remote Secured Terminal for Cross-Platform Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote secured terminals face challenges in maintaining transport and payload security due to vulnerabilities in client computers, particularly when using Intel Skylake platforms with SGX, which are limited to specific vendors and platforms, and other prior art solutions like secure device pairing and security provisioning manifests have limitations.

Innovation Solution

A system utilizing System On Chip (SOC) architecture with cryptographic modules and trusted platform modules (TPM) to establish secure peer-to-peer communication channels between peripheral components and remote servers, employing non-symmetric and symmetric keys for encryption and decryption, ensuring data integrity and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Intel Skylake SGX is used for securing remote terminals, then payload security and transport security are improved, but device compatibility is limited to specific vendors and platforms

Engineering Contradiction:
Improvepayload securityVSAvoidplatform compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a remote secured terminal (RST) as an intermediary device between the client computer and the remote server. This RST acts as a mediator that handles secure communication, allowing standard client computers without specialized hardware (like Intel Skylake SGX) to achieve secure remote access. The RST contains the cryptographic modules and trusted platform module, separating the security functions from the main client computer and enabling broader platform compatibility while maintaining high security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If Intel Skylake SGX is used for securing remote terminals, then transport security is improved, but implementation cost increases

Engineering Contradiction:
Improvetransport securityVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent segments the security functions into a separate remote secured terminal device with dedicated cryptographic modules and trusted platform module. This segmentation allows the main client computer to remain a standard, lower-cost device while the security-critical functions are isolated in the RST. The segmentation enables organizations to deploy security without requiring expensive specialized hardware in every client computer, reducing overall implementation costs while maintaining transport security.

Inventive Principle:
Principle #1Segmentation

3Reliability

If secure device pairing is used for remote access, then authentication security is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the remote secured terminal automatically performs cryptographic operations, key management, and security protocol execution. The trusted platform module within the RST handles authentication and encryption tasks autonomously without requiring complex configuration or management overhead. This self-service approach maintains strong authentication security while reducing the operational complexity for users and administrators.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3776324B1Remote secured terminal
Publication Date: 2025.06.25 KAZUAR ADVANCED TECH LTD
  • EP3776324B1 patent drawingFigure 1
  • EP3776324B1 patent drawingFigure 2
  • EP3776324B1 patent drawingFigure 3~4

AI summary

A computer implemented method for providing communication between a secured client computer and a remote computer. There is provided a client computer that includes peripheral components. Each peripheral component is configured, by a processor, to process a corresponding peripheral component data of a data type that is not compatible with peripheral component data types processed by a processor of other peripheral components. The processor of each peripheral component is further configured to code the corresponding data of the specified data type. Each peripheral component is configured, by the processor, to establish a secured peer-to-peer communication channel between the peripheral component and the remote computer that is authorized to communicate with the client computer, and is further configured to code data that is communicated between the authorized remote computer and the peripheral component through the secured communication channel. The coded data being indecryptable by the processors of other of the peripheral components.