Secure Edge Remote Access for Private Network Microsegments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional remote access tools expose corporate networks to unnecessary risks and operational overhead due to inherent vulnerabilities in VPN connections and cumbersome key management, especially when dealing with a large number of endpoint devices.

Innovation Solution

A method involving a secure edge device and a secure lobby node that conditionally enables access to endpoint devices within a private network, allowing one-hop traffic through a secure connection, with granular access control at layers 3 and 4, using a 4096 RSA-encrypted connection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a VPN tunnel is used to allow inbound connections for remote access, then remote access capability is improved, but network security and operational complexity worsen due to exposed perimeter and key management overhead

Engineering Contradiction:
Improveremote access capabilityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Instead of allowing inbound connections from the internet to the corporate network (traditional VPN approach), the patent inverts the architecture by having the secure gateway initiate outbound connections to a cloud service. This reversal eliminates the need for open perimeter ports and inbound connection rules, fundamentally changing the security model from trust-based perimeter defense to zero-trust architecture where connections are initiated from within the protected network.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces a cloud-based secure gateway service as an intermediary between endpoint devices and the corporate network. This mediator handles authentication, connection establishment, and traffic routing, eliminating the need for direct VPN tunnels through the corporate perimeter. The gateway acts as a controlled entry point that manages all remote access traffic without exposing the network to direct internet connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional VPN key management is implemented for 100s or 1000s of endpoint devices, then security is improved, but operational overhead and time consumption worsen

Engineering Contradiction:
ImprovesecurityVSAvoidoperational overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements self-service capabilities where the secure gateway automatically performs authentication, connection establishment, and device discovery without requiring manual intervention. The system autonomously manages cryptographic keys, establishes secure channels, and routes traffic based on predefined policies, eliminating the need for IT personnel to manually configure and manage VPN connections for hundreds or thousands of devices.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The cloud-based secure gateway provides universal access management for all endpoint devices through a single unified service. Instead of requiring separate VPN configurations for each device or user, the gateway handles authentication and connection management for the entire fleet of endpoint devices through centralized credential verification and automated connection establishment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If a public static IP is used for remote access, then ease of connection is improved, but network exposure and security vulnerabilities worsen

Engineering Contradiction:
Improveconnection accessibilityVSAvoidnetwork exposure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the public IP address requirement from the remote access architecture by moving the secure gateway to a cloud service provider's infrastructure. The gateway maintains a public presence at the cloud provider's data center rather than requiring a public IP at the corporate network edge. This extraction eliminates the security vulnerability of exposing the corporate network to direct internet access while preserving remote connectivity through the cloud-based gateway.

Inventive Principle:
Principle #2Taking out (Extraction)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enables secure, efficient, and granular remote access to endpoint devices without exposing the entire network, reducing operational overhead and security risks, while allowing secure monitoring, updating, and troubleshooting from a remote location.

Implementation Method 1

using a 4096 RSA-encrypted connection

Methodology Applied
Scientific EffectRSA encryption:

Data Source

PatentUS12537800B2Apparatus and method for remote access to communication systems
Publication Date: 2026.01.27 BYOS INC
  • US12537800B2 patent drawing
  • US12537800B2 patent drawing
  • US12537800B2 patent drawing

AI summary

According to an aspect, there is provided a method for conditionally enabling access to endpoint devices of a microsegment within a private network from a management console which is external to the private network. A secure edge device discovers all of the endpoint devices within the microsegment and identifies which endpoint devices are connectable devices. A secure lobby node conveys to the management console information identifying all of the endpoint devices and which endpoint devices are connectable devices. Thus, a user of the management console can easily learn what endpoint devices are in the microsegment and which endpoint devices are connectable devices, such that the user can then choose to remotely connect to one or more of the connectable devices. Notably, the secure lobby node and the secure edge device enable one-hop traffic between the management console and any of the connectable devices of the microsegment.