Secretless Remote Access via Connection Agent Tunnel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote network access techniques face security vulnerabilities and inefficiencies, including the need for passwords, installation of VPN clients, and exposure of sensitive information during connection establishment.

Innovation Solution

The solution involves securely establishing secretless and remote native access sessions by modifying the remote access protocol file to include a client identifier, establishing a secure tunnel connection, authenticating the client, accessing target identity information, and obtaining a credential for secure access without requiring separate credentials or a dedicated remote access client.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VPN clients are used for remote network access, then network security is improved, but device complexity and ease of operation deteriorate due to installation requirements and credential management

Engineering Contradiction:
Improvenetwork securityVSAvoidclient installation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the credential management complexity from the client device by implementing secretless authentication. The authentication credentials are obtained dynamically by the connection agent during the tunnel establishment process, eliminating the need for users to manually configure or manage VPN credentials on their devices. This resolves the contradiction by maintaining security through credential verification while removing the operational burden of credential management from the client.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The connection agent acts as an intermediary between the client device and the network resources. It handles the complex authentication and credential retrieval processes, allowing the client to establish secure connections without directly managing credentials. The connection agent mediates the authentication process by obtaining credentials dynamically and establishing the secure tunnel, thereby simplifying the client's role while maintaining strong security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If VPN clients provide full network access, then adaptability is improved, but security deteriorates due to exposure of credentials and attack vectors

Engineering Contradiction:
Improvenetwork access flexibilityVSAvoidcredential theft risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements resource-specific authentication by obtaining separate credentials for each target resource through the connection agent. Instead of providing blanket network access with universal credentials, the system authenticates to specific resources individually. This localizes the security scope, allowing flexible access to different resources while minimizing credential exposure and attack vectors for each specific resource.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The authentication process is segmented into distinct steps: establishing a secure tunnel first, then obtaining credentials for specific target resources. This segmentation separates the transport layer security from the authentication layer, allowing the system to provide adaptable access to multiple resources while maintaining security by never exposing credentials during the initial connection phase. Each resource access is authenticated separately after the secure channel is established.

Inventive Principle:
Principle #1Segmentation

3Reliability

If passwords are required for VPN authentication, then security is improved, but ease of operation deteriorates due to credential entry requirements

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The connection agent performs self-service by automatically obtaining authentication credentials dynamically during the tunnel establishment process. Instead of requiring user input for passwords or credentials, the system autonomously retrieves the necessary authentication information through the secure tunnel. This eliminates the operational burden of credential entry while maintaining strong authentication security through the automated process.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If target resource details are required during connection establishment, then adaptability is improved, but security deteriorates due to exposure of sensitive information

Engineering Contradiction:
Improveresource access capabilityVSAvoidexposure of sensitive target details
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent performs preliminary action by establishing the secure tunnel connection before obtaining or exposing any target resource credentials or details. The secure communication channel is created first, and only after this protective layer is in place does the system proceed to authenticate to specific resources. This preliminary establishment of security infrastructure prevents exposure of sensitive target details during the connection phase while maintaining the ability to access multiple resources.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12289308B2Native remote access to target resources using secretless connections
Publication Date: 2025.04.29 CYBER ARK SOFTWARE LTD
  • US12289308B2 patent drawing
  • US12289308B2 patent drawing
  • US12289308B2 patent drawing

AI summary

Disclosed embodiments relate to systems and methods for securely establishing secretless and remote native access sessions. Techniques include identifying a client configured to participate in remote native access sessions, wherein the client has a remote access protocol file that has been modified to include an identifier associated with the client; sending a prompt to the client to establish a secure tunnel connection with a connection agent using the identifier associated with the client; and authentication the client. The techniques may further include accessing target identity information associated with one or more target resources; receiving from the client a token that identifies a target resource from among the one or more target resources; obtaining, based on the token, a credential required for secure access to the target resource; and initiating, using the credential, a remote native access session between the client and the target resource.