Mutually Authenticated Secure Channel Gateway

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users behind firewalls face difficulties in establishing remote desktop connections due to the challenge of discovering the current network address of the remote computer, and existing secure remote access solutions may not adequately prevent unauthorized interception of data.

Innovation Solution

A mutually authenticated secure channel system is established through a remote access gateway server that facilitates secure connections between a client device and a remote device, using digital identity certificates and a remote activation gateway index server to ensure encrypted communication without the gateway possessing session keys, thus preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a remote access gateway server forwards secure connection requests between client and remote device, then secure remote access is enabled, but the gateway may possess session keys that could be intercepted

Engineering Contradiction:
Improvesecure remote accessVSAvoiddata interception
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the session key management function from the gateway server. The gateway forwards connection requests and acknowledgments but does not possess or store the session keys. Instead, the client and remote device establish direct encrypted communication using keys generated locally, eliminating the gateway's ability to intercept or decrypt data.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The gateway acts as a simple intermediary that facilitates connection establishment without becoming part of the secure communication path. It forwards packets between client and remote device but does not participate in key management or data encryption, ensuring it cannot intercept or compromise the secure channel.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If users connect through a gateway server, then remote access is facilitated, but network address discovery becomes more difficult behind firewalls

Engineering Contradiction:
Improveremote access connectionVSAvoidnetwork address discovery
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The gateway server serves as an intermediary that resolves network address discovery issues. Clients can connect to the gateway using publicly known addresses, and the gateway dynamically establishes connections to remote devices behind firewalls. This eliminates the need for clients to directly discover or know the internal network addresses of remote devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary connection establishment through the gateway before actual data transfer. The gateway pre-establishes secure channels and manages the connection state, allowing clients to access remote devices without needing to perform complex network address discovery or penetration through firewalls.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8782414B2Mutually authenticated secure channel
Publication Date: 2014.07.15 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8782414B2 patent drawing
  • US8782414B2 patent drawing
  • US8782414B2 patent drawing

AI summary

A system and methods for establishing a mutually authenticated secure channel between a client device and remote device through a remote access gateway server. The remote access gateway server forwards secure connection requests and acknowledgements between the client and the remote device such that the remote access gateway does not possess any or all session keys necessary to decrypt communication between the client device and remote device.