Reverse Proxy for Enterprise Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for troubleshooting enterprise networks are impractical and pose security concerns, as they require physical presence or VPN access, and involve cumbersome credential management and screen sharing limitations.
Innovation Solution
A proxy infrastructure that authenticates client devices to navigate to enterprise network devices using a reverse proxy service, hiding device credentials from clients and user credentials from target devices, and enabling secure, end-to-end encrypted connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical presence or VPN access is used to access enterprise network devices, then users can authenticate and access devices, but security risks increase and access becomes impractical
Solution Approach 1:
The patent introduces a reverse proxy server as an intermediary between users and enterprise network devices. The proxy server handles authentication and credential management, allowing users to access devices without directly sharing credentials or requiring physical presence. The proxy acts as a secure mediator that verifies user identity and manages device access tokens, thereby maintaining security while enabling remote access.
2Ease of operation
If screen sharing is used for remote access, then users can access devices remotely, but responsiveness decreases and file transfer capabilities are limited
Solution Approach 1:
The reverse proxy server serves as an intermediary that enables direct device access while managing security credentials. Instead of screen sharing that creates a bottleneck, the proxy allows users to directly interact with device interfaces through a web browser, maintaining full responsiveness and native file transfer capabilities while the proxy handles authentication in the background.
3Adaptability or versatility
If credentials are shared for every device-user combination, then users can access multiple devices, but credential management becomes cumbersome and security is compromised
Solution Approach 1:
The reverse proxy server provides universal authentication that works across multiple devices and users. Instead of creating unique credentials for each device-user combination, the proxy implements a single sign-on mechanism where users authenticate once and gain access to multiple devices. The proxy manages device-specific credentials centrally, allowing flexible device access without requiring separate credential sets for each combination.
Solution Approach 2:
The proxy server mediates between users and multiple devices, handling credential translation and management. Users present a single set of credentials to the proxy, which then manages the appropriate device credentials behind the scenes. This intermediary approach eliminates the need for users to manage multiple credential sets while maintaining secure access to diverse devices.
4Ease of operation
If enterprises share credentials for troubleshooting, then users can access devices for maintenance, but security concerns increase and enterprises become reluctant to share credentials
Solution Approach 1:
The reverse proxy server acts as a secure intermediary that eliminates the need for enterprises to share credentials. Users authenticate through the proxy, which then manages device access on behalf of the enterprise. The proxy verifies user identity and credentials, and handles device authentication transparently, allowing troubleshooting access without enterprises needing to expose their credential sets to external users.
Data Source
AI summary
Methods are provided for a proxy infrastructure that serves as a bridge between an enterprise network and a computing machine of a user ensuring a chain of trust. The methods involve obtaining, from a client device, a request to navigate to one or more target devices of a remote enterprise network and locally authenticating the client device based on at least one of an identity of the client device and user credentials. The methods further involve generating a connection request for the client device to navigate to the one or more target devices based on the client device being locally authenticated and providing the connection request to a proxy service executing in the remote enterprise network. The proxy service authenticates an access to the one or more target devices based on device credentials while hiding the device credentials from the client device.


