Secretless Remote Access via Connection Agent Tunnel
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing remote network access techniques face security vulnerabilities and inefficiencies, including the need for passwords, installation of VPN clients, and exposure of sensitive information during connection establishment.
Innovation Solution
The solution involves securely establishing secretless and remote native access sessions by modifying the remote access protocol file to include a client identifier, establishing a secure tunnel connection, authenticating the client, accessing target identity information, and obtaining a credential for secure access without requiring separate credentials or a dedicated remote access client.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If VPN clients are used for remote network access, then network security is improved, but device complexity and ease of operation deteriorate due to installation requirements and credential management
Solution Approach 1:
The patent extracts the credential management complexity from the client device by implementing secretless authentication. The authentication credentials are obtained dynamically by the connection agent during the tunnel establishment process, eliminating the need for users to manually configure or manage VPN credentials on their devices. This resolves the contradiction by maintaining security through credential verification while removing the operational burden of credential management from the client.
Solution Approach 2:
The connection agent acts as an intermediary between the client device and the network resources. It handles the complex authentication and credential retrieval processes, allowing the client to establish secure connections without directly managing credentials. The connection agent mediates the authentication process by obtaining credentials dynamically and establishing the secure tunnel, thereby simplifying the client's role while maintaining strong security.
2Adaptability or versatility
If VPN clients provide full network access, then adaptability is improved, but security deteriorates due to exposure of credentials and attack vectors
Solution Approach 1:
The patent implements resource-specific authentication by obtaining separate credentials for each target resource through the connection agent. Instead of providing blanket network access with universal credentials, the system authenticates to specific resources individually. This localizes the security scope, allowing flexible access to different resources while minimizing credential exposure and attack vectors for each specific resource.
Solution Approach 2:
The authentication process is segmented into distinct steps: establishing a secure tunnel first, then obtaining credentials for specific target resources. This segmentation separates the transport layer security from the authentication layer, allowing the system to provide adaptable access to multiple resources while maintaining security by never exposing credentials during the initial connection phase. Each resource access is authenticated separately after the secure channel is established.
3Reliability
If passwords are required for VPN authentication, then security is improved, but ease of operation deteriorates due to credential entry requirements
Solution Approach 1:
The connection agent performs self-service by automatically obtaining authentication credentials dynamically during the tunnel establishment process. Instead of requiring user input for passwords or credentials, the system autonomously retrieves the necessary authentication information through the secure tunnel. This eliminates the operational burden of credential entry while maintaining strong authentication security through the automated process.
4Adaptability or versatility
If target resource details are required during connection establishment, then adaptability is improved, but security deteriorates due to exposure of sensitive information
Solution Approach 1:
The patent performs preliminary action by establishing the secure tunnel connection before obtaining or exposing any target resource credentials or details. The secure communication channel is created first, and only after this protective layer is in place does the system proceed to authenticate to specific resources. This preliminary establishment of security infrastructure prevents exposure of sensitive target details during the connection phase while maintaining the ability to access multiple resources.
Data Source
AI summary
Disclosed embodiments relate to systems and methods for securely establishing secretless and remote native access sessions. Techniques include identifying a client configured to participate in remote native access sessions, wherein the client has a remote access protocol file that has been modified to include an identifier associated with the client; sending a prompt to the client to establish a secure tunnel connection with a connection agent using the identifier associated with the client; and authentication the client. The techniques may further include accessing target identity information associated with one or more target resources; receiving from the client a token that identifies a target resource from among the one or more target resources; obtaining, based on the token, a credential required for secure access to the target resource; and initiating, using the credential, a remote native access session between the client and the target resource.


