Secure Remote Maintenance Proxy for IT Error Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge lies in providing a secure remote maintenance and support system for IT systems that balances ease of access for technicians with the need to prevent security breaches and reduce operational costs, particularly in environments like retail and entertainment where sensitive data is handled, while adhering to standards like PCI DSS.
Innovation Solution
A system utilizing a data center as a proxy between client terminals and site devices, enabling authorized technicians to monitor and resolve errors without direct access, using secure tunnels for communication, and centralizing authentication and permission management to ensure secure, remote access without compromising system security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If technicians are given high-level privilege access to remote systems for easier maintenance, then ease of operation is improved, but security vulnerability increases
Solution Approach 1:
The patent implements a server as an intermediary that sits between technicians and remote systems. The server receives authenticated requests from technicians, establishes secure tunnel connections, and mediates all access to remote systems. This intermediary architecture allows technicians to perform maintenance tasks with full functionality while the server enforces authentication, authorization, and security policies, preventing direct unauthorized access to remote systems.
2Reliability
If centralized control is implemented to secure remote access, then security is improved, but capital costs and operating costs increase
Solution Approach 1:
The patent designs the server to perform multiple functions: authentication, authorization, session management, tunnel establishment, and system monitoring. By consolidating these security and access management functions into a single multi-functional server, the system achieves centralized control and improved security without requiring separate infrastructure components for each function, thereby reducing overall capital and operating costs.
3Productivity
If direct access is provided to remote systems, then productivity is improved, but risk of security breaches increases
Solution Approach 1:
The server acts as a mediator that enables productive maintenance operations while preventing security breaches. It establishes secure tunnel connections that allow technicians to execute commands, transfer files, and diagnose issues on remote systems with full operational capability. Simultaneously, the server logs all activities, enforces access policies, and prevents unauthorized actions, maintaining security without impeding maintenance productivity.
Solution Approach 2:
The system implements feedback mechanisms where the server continuously monitors technician activities, authenticates each action, and provides real-time control over access permissions. This feedback loop allows the system to maintain high productivity by enabling rapid response to system issues while simultaneously detecting and preventing potential security breaches through continuous oversight and logging of all remote access activities.
Data Source
AI summary
A remote, secure maintenance and support system, method, network entity and computer program product are provided. The system can include site terminal(s) and/or a site server (collectively “site device(s)”), a data center in communication with the site device(s) over a first secure tunnel, and at least one client terminal in communication with the data center over a second secure tunnel. The site device(s) can be configured to periodically transmit to the data center one or more error messages over the first secure tunnel. The data center can, in turn, be configured to make the error messages accessible to at least one authorized technician operating one of the client terminals. The client terminal can be configured to retrieve at least one of the error messages over the second secure tunnel and to take an action associated with resolving the error message.


