Secure Digital Certificate for Remote Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Companies face security risks when employees remotely access corporate IT networks, as stolen devices and credentials can be used to obtain confidential information, and unauthorized access can occur from different locations with changing public IP addresses.

Innovation Solution

Implementing a secure digital certificate linked to a public IP address, which requires a Diffie-Hellman key exchange and includes additional data like a MAC address or IMEI, to authenticate user devices and prevent unauthorized access, along with schedule-based and data usage-based security measures to enhance network security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If employees are allowed to remotely access corporate IT networks from any location, then employee flexibility and productivity are improved, but security risks increase due to potential theft of devices and credentials

Engineering Contradiction:
Improveemployee flexibilityVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the authentication parameters from static credentials (username/password) to dynamic multi-factor authentication that includes device identifiers, location information, and time-based factors. This allows remote access to be enabled while implementing adaptive security measures that respond to changing access conditions, thereby maintaining productivity while mitigating security risks.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary authentication system that acts as a mediator between the employee and the corporate network. This intermediary validates multiple authentication factors (device identity, location, time) before granting access, creating a security layer that protects against credential theft while allowing legitimate remote access to proceed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If digital certificates are linked to public IP addresses to prevent unauthorized access, then network security is improved, but access flexibility deteriorates when employees travel to different locations with different IP addresses

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic authentication that adapts to changing conditions. Instead of static IP-based certificates, the system continuously evaluates multiple factors including current device identifier, real-time location data, and time-based parameters. This dynamic approach maintains security by validating the authenticity of the device and user while allowing legitimate access from varying locations and IP addresses.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent performs preliminary authentication validation by verifying device identity and authorization status before establishing the connection. This preliminary check ensures that only authenticated devices can access the network, while the subsequent connection process adapts to the actual location and IP address being used, thereby maintaining both security and flexibility.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multi-factor authentication with device identifiers and location data is implemented, then unauthorized access prevention is improved, but authentication complexity increases

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service authentication mechanisms where the employee's device automatically provides required authentication information (device identifiers, location data) without manual intervention. The authentication system automatically collects and validates these factors, reducing the perceived complexity for the user while maintaining strong security controls.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary collection and validation of authentication factors before the actual authentication process. By pre-gathering device identifiers, location information, and time data, and pre-validating device authorization status, the system streamlines the authentication flow and reduces the complexity experienced by users during the actual login process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11997219B1Network security for remote workers
Publication Date: 2024.05.28 UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
  • US11997219B1 patent drawing
  • US11997219B1 patent drawing
  • US11997219B1 patent drawing

AI summary

To protect corporate information technology (IT) networks, corporations or organizations can design their networks with secure technology. For example, before an employee can remotely access his or her company's network via a user device, a server associated with the company's network can setup an exemplary secure digital certificate for the user device. The secure digital certificate includes a public Internet Protocol (IP) address associated with a router used by the user device to access the Internet. When employee attempts to remotely access his or her company's network, the user device or a router associated with the user device can send the secure digital certificate along with a current public IP address of the router used by the user device to access the Internet. In some embodiments, if the public IP address included in the digital certificate matches the current public IP address, the user device can access the company's network.