Sealed Remote Box for Secure Confidential Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing purely software solutions for accessing confidential data from remote locations are insecure, costly to deploy, require frequent maintenance updates, and are prone to malfunctions due to compatibility issues with remote user workstations, failing to meet security, ergonomic, integration, and economic constraints.
Innovation Solution
A computer system utilizing a specially configured remote box with an encrypted tunnel link on a public network, where the remote box is a locked 'black box' containing an electronic card with an encryption circuit, operating system, and user identification means, allowing secure access and processing of confidential data without exposing the data to unauthorized access or leaks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If a purely software solution is used for remote access to confidential data, then deployment cost is reduced, but security is compromised due to uncontrolled remote user workstations
Solution Approach 1:
A dedicated remote box acts as an intermediary device between the user and the confidential data server. This black box contains a controlled operating system and encryption hardware, mediating all access requests while preventing direct access to the data. The intermediary enforces security policies and encrypts communications, resolving the contradiction by providing both accessibility and security control.
Solution Approach 2:
The patent replaces the software-based security model with hardware-based security enforcement. Encryption circuits and secure hardware components within the remote box provide cryptographic protection, replacing reliance on software security measures that are vulnerable to workstations. This substitution of mechanical/hardware security for software security resolves the contradiction between cost and security.
2Ease of manufacture
If a purely software solution is used for remote access, then initial deployment is simpler, but maintenance costs increase due to compatibility issues and frequent updates
Solution Approach 1:
The remote box contains a self-contained operating system and hardware configuration that operates independently of the user's workstation environment. This self-service capability allows the device to maintain consistent functionality without requiring updates or compatibility adjustments based on external workstation changes, reducing maintenance costs while keeping initial deployment straightforward.
Solution Approach 2:
The remote box is designed as a standardized, replaceable unit with fixed functionality. Rather than investing in complex software solutions requiring ongoing maintenance and updates, the system uses simple, standardized hardware units that can be deployed uniformly across multiple locations. This approach trades initial hardware investment for long-term maintenance simplicity, resolving the contradiction between deployment simplicity and maintenance cost.
3Adaptability or versatility
If remote user workstations are used directly, then user flexibility is improved, but security control is lost due to unmonitored access points
Solution Approach 1:
The system segments the access control function from the user workstation by introducing dedicated remote boxes. Each box is a separate, controlled unit that maintains user flexibility for accessing confidential data while isolating the security control function in a dedicated device. This segmentation allows users to work flexibly from different locations while the remote box enforces security policies consistently, resolving the contradiction between flexibility and control.
Solution Approach 2:
The remote box serves as an intermediary that mediates between user flexibility and security control. It allows users to access confidential data from various locations and workstations while enforcing security policies, encryption, and monitoring at the intermediary level. This resolves the contradiction by maintaining user flexibility while restoring security control through the mediating device.
4Reliability
If encryption hardware is added to remote boxes, then security is improved, but device complexity increases
Solution Approach 1:
The patent merges the encryption hardware, operating system, and security functions into a single integrated remote box unit. By combining these elements into one standardized device rather than distributing them across multiple components or workstations, the system improves security while managing complexity through integration. The merged design allows standardized deployment and simplifies the overall system architecture despite the advanced security capabilities.
Data Source
Figure 1
AI summary
The invention relates to a computer system for accessing confidential data by means of at least one remote unit (4), the data being stored in a secured centralised computer system (3) comprising a means for processing said data intended for producing results, a computer link (2) being established between said unit and the computer means, the unit being a microcomputer operating under the dependency of a local operating system. According to the invention, the system is such that the computer link is an encrypted tunnel link over a public network, said unit only supporting remote administration, said unit not being operable if the computer link is not restored and, during the access thereof to the data, said unit only receiving display information associated with the process performed on the data and produced by the centralised computer system, the microcomputer of the remote unit also including an electronic encryption circuit, the operating system as well as the information required for the operation of said unit being stored in encrypted form, said unit being sealed and containing the electronic card and the inputs/outputs, including one input/output of (an) identification means (6) connected to at least one identification means and one input/output of a computer network (7) intended for the encrypted tunnel link.