Mutually Authenticated Secure Channel Gateway
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users behind firewalls face difficulties in establishing remote desktop connections due to the challenge of discovering the current network address of the remote computer, and existing secure remote access solutions may not adequately prevent unauthorized interception of data.
Innovation Solution
A mutually authenticated secure channel system is established through a remote access gateway server that facilitates secure connections between a client device and a remote device, using digital identity certificates and a remote activation gateway index server to ensure encrypted communication without the gateway possessing session keys, thus preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a remote access gateway server forwards secure connection requests between client and remote device, then secure remote access is enabled, but the gateway may possess session keys that could be intercepted
Solution Approach 1:
The patent extracts the session key management function from the gateway server. The gateway forwards connection requests and acknowledgments but does not possess or store the session keys. Instead, the client and remote device establish direct encrypted communication using keys generated locally, eliminating the gateway's ability to intercept or decrypt data.
Solution Approach 2:
The gateway acts as a simple intermediary that facilitates connection establishment without becoming part of the secure communication path. It forwards packets between client and remote device but does not participate in key management or data encryption, ensuring it cannot intercept or compromise the secure channel.
2Ease of operation
If users connect through a gateway server, then remote access is facilitated, but network address discovery becomes more difficult behind firewalls
Solution Approach 1:
The gateway server serves as an intermediary that resolves network address discovery issues. Clients can connect to the gateway using publicly known addresses, and the gateway dynamically establishes connections to remote devices behind firewalls. This eliminates the need for clients to directly discover or know the internal network addresses of remote devices.
Solution Approach 2:
The system performs preliminary connection establishment through the gateway before actual data transfer. The gateway pre-establishes secure channels and manages the connection state, allowing clients to access remote devices without needing to perform complex network address discovery or penetration through firewalls.
Data Source
AI summary
A system and methods for establishing a mutually authenticated secure channel between a client device and remote device through a remote access gateway server. The remote access gateway server forwards secure connection requests and acknowledgements between the client and the remote device such that the remote access gateway does not possess any or all session keys necessary to decrypt communication between the client device and remote device.


