Remote Work Network Security via Segmented Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current remote work environments are vulnerable to security threats due to multi-homing, where terminals can access both the Internet and work networks, potentially spreading malicious code, and there is a risk of data leakage from lost or stolen devices, necessitating enhanced security measures for user authentication and data protection.

Innovation Solution

An apparatus and method that perform VPN authentication, user authentication, and apply network management policies to restrict terminal functions, ensuring secure connections to the work network while preventing external Internet access and encrypting user data, thereby maintaining a secure remote work environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a terminal is allowed to access both the Internet and work network simultaneously, then remote work flexibility is improved, but security vulnerability increases due to multi-homing threats

Engineering Contradiction:
Improveremote work flexibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the network connection into two distinct phases: pre-connection phase where only Internet access is permitted, and post-connection phase where work network access is granted after security verification. This segmentation prevents simultaneous multi-homing access while maintaining remote work flexibility through controlled transition between phases.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary security actions before granting work network access. Specifically, it verifies the terminal's security status, checks for malicious code, and validates user credentials before allowing connection to the work network, thereby preventing security vulnerabilities from propagating.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If a terminal is used for remote work in arbitrary locations, then work mobility is improved, but risk of data leakage from lost or stolen devices increases

Engineering Contradiction:
Improvework mobilityVSAvoiddata leakage risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by encrypting user data stored on the terminal before the terminal can be lost or stolen. The encryption keys are managed securely and can be revoked remotely, preventing data leakage even if the physical device is compromised during mobile remote work.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system introduces an intermediary security management server that acts as a mediator between the mobile terminal and the work network. This intermediary verifies terminal security status, manages encryption keys, and controls access permissions, thereby protecting against data leakage while enabling work mobility.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If VPN authentication is performed before OS login, then network security is improved, but user authentication complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges VPN authentication and user authentication into a unified multi-factor authentication process. The terminal's security credentials and user credentials are verified together in sequence, creating a single integrated authentication flow that maintains high security while presenting a unified interface to users.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11991150B2Apparatus and method for providing remote work environment
Publication Date: 2024.05.21 ELECTRONICS & TELECOMM RES INST
  • US11991150B2 patent drawing
  • US11991150B2 patent drawing
  • US11991150B2 patent drawing

AI summary

Disclosed herein are an apparatus and method for providing a remote work environment. The apparatus includes one or more processors and executable memory for storing at least one program executed by the one or more processors. The at least one program performs Virtual Private Network (VPN) authentication in response to a request for remote access to a work network from a user terminal, performs user authentication in order to connect the user terminal that succeeds in VPN authentication to the work network, decrypts the encrypted user data area of the user terminal that is connected to the work network, and provides the remote work environment to the user terminal based on the user data area through the work network.