Reverse Proxy for Enterprise Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for troubleshooting enterprise networks are impractical and pose security concerns, as they require physical presence or VPN access, and involve cumbersome credential management and screen sharing limitations.

Innovation Solution

A proxy infrastructure that authenticates client devices to navigate to enterprise network devices using a reverse proxy service, hiding device credentials from clients and user credentials from target devices, and enabling secure, end-to-end encrypted connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical presence or VPN access is used to access enterprise network devices, then users can authenticate and access devices, but security risks increase and access becomes impractical

Engineering Contradiction:
Improveaccess reliabilityVSAvoidsecurity risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a reverse proxy server as an intermediary between users and enterprise network devices. The proxy server handles authentication and credential management, allowing users to access devices without directly sharing credentials or requiring physical presence. The proxy acts as a secure mediator that verifies user identity and manages device access tokens, thereby maintaining security while enabling remote access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If screen sharing is used for remote access, then users can access devices remotely, but responsiveness decreases and file transfer capabilities are limited

Engineering Contradiction:
Improveremote access capabilityVSAvoidresponsiveness and file transfer efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The reverse proxy server serves as an intermediary that enables direct device access while managing security credentials. Instead of screen sharing that creates a bottleneck, the proxy allows users to directly interact with device interfaces through a web browser, maintaining full responsiveness and native file transfer capabilities while the proxy handles authentication in the background.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If credentials are shared for every device-user combination, then users can access multiple devices, but credential management becomes cumbersome and security is compromised

Engineering Contradiction:
Improvedevice access flexibilityVSAvoidcredential management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The reverse proxy server provides universal authentication that works across multiple devices and users. Instead of creating unique credentials for each device-user combination, the proxy implements a single sign-on mechanism where users authenticate once and gain access to multiple devices. The proxy manages device-specific credentials centrally, allowing flexible device access without requiring separate credential sets for each combination.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The proxy server mediates between users and multiple devices, handling credential translation and management. Users present a single set of credentials to the proxy, which then manages the appropriate device credentials behind the scenes. This intermediary approach eliminates the need for users to manage multiple credential sets while maintaining secure access to diverse devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If enterprises share credentials for troubleshooting, then users can access devices for maintenance, but security concerns increase and enterprises become reluctant to share credentials

Engineering Contradiction:
Improvetroubleshooting accessVSAvoidsecurity concerns
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The reverse proxy server acts as a secure intermediary that eliminates the need for enterprises to share credentials. Users authenticate through the proxy, which then manages device access on behalf of the enterprise. The proxy verifies user identity and credentials, and handles device authentication transparently, allowing troubleshooting access without enterprises needing to expose their credential sets to external users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250119410A1Transitively authenticated reverse proxy
Publication Date: 2025.04.10 CISCO TECHNOLOGY INC
  • US20250119410A1 patent drawing
  • US20250119410A1 patent drawing
  • US20250119410A1 patent drawing

AI summary

Methods are provided for a proxy infrastructure that serves as a bridge between an enterprise network and a computing machine of a user ensuring a chain of trust. The methods involve obtaining, from a client device, a request to navigate to one or more target devices of a remote enterprise network and locally authenticating the client device based on at least one of an identity of the client device and user credentials. The methods further involve generating a connection request for the client device to navigate to the one or more target devices based on the client device being locally authenticated and providing the connection request to a proxy service executing in the remote enterprise network. The proxy service authenticates an access to the one or more target devices based on device credentials while hiding the device credentials from the client device.