Remote Work Network Security via Segmented Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current remote work environments are vulnerable to security threats due to multi-homing, where terminals can access both the Internet and work networks, potentially spreading malicious code, and there is a risk of data leakage from lost or stolen devices, necessitating enhanced security measures for user authentication and data protection.
Innovation Solution
An apparatus and method that perform VPN authentication, user authentication, and apply network management policies to restrict terminal functions, ensuring secure connections to the work network while preventing external Internet access and encrypting user data, thereby maintaining a secure remote work environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a terminal is allowed to access both the Internet and work network simultaneously, then remote work flexibility is improved, but security vulnerability increases due to multi-homing threats
Solution Approach 1:
The patent divides the network connection into two distinct phases: pre-connection phase where only Internet access is permitted, and post-connection phase where work network access is granted after security verification. This segmentation prevents simultaneous multi-homing access while maintaining remote work flexibility through controlled transition between phases.
Solution Approach 2:
The system performs preliminary security actions before granting work network access. Specifically, it verifies the terminal's security status, checks for malicious code, and validates user credentials before allowing connection to the work network, thereby preventing security vulnerabilities from propagating.
2Adaptability or versatility
If a terminal is used for remote work in arbitrary locations, then work mobility is improved, but risk of data leakage from lost or stolen devices increases
Solution Approach 1:
The patent applies preliminary anti-action by encrypting user data stored on the terminal before the terminal can be lost or stolen. The encryption keys are managed securely and can be revoked remotely, preventing data leakage even if the physical device is compromised during mobile remote work.
Solution Approach 2:
The system introduces an intermediary security management server that acts as a mediator between the mobile terminal and the work network. This intermediary verifies terminal security status, manages encryption keys, and controls access permissions, thereby protecting against data leakage while enabling work mobility.
3Reliability
If VPN authentication is performed before OS login, then network security is improved, but user authentication complexity increases
Solution Approach 1:
The patent merges VPN authentication and user authentication into a unified multi-factor authentication process. The terminal's security credentials and user credentials are verified together in sequence, creating a single integrated authentication flow that maintains high security while presenting a unified interface to users.
Data Source
AI summary
Disclosed herein are an apparatus and method for providing a remote work environment. The apparatus includes one or more processors and executable memory for storing at least one program executed by the one or more processors. The at least one program performs Virtual Private Network (VPN) authentication in response to a request for remote access to a work network from a user terminal, performs user authentication in order to connect the user terminal that succeeds in VPN authentication to the work network, decrypts the encrypted user data area of the user terminal that is connected to the work network, and provides the remote work environment to the user terminal based on the user data area through the work network.


