Secure Remote Access Controller via Cloud Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote access solutions for control systems, such as VPN connections and port forwarding, require complex user configuration and introduce security risks, making it difficult to provide secure and easy-to-use remote access for end-users.

Innovation Solution

A method and system that uses a controller with a remote access agent to authenticate and register with an authentication service, allowing secure remote access through a communication network, which includes sending endpoint requests, receiving authentication and connection service information, and establishing a session request to facilitate secure communication between the controller and an electronic device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If VPN connections or port forwarding are used for remote access, then remote access capability is provided, but device complexity and security risks increase

Engineering Contradiction:
Improveremote access capabilityVSAvoiduser configuration complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a cloud-based connection service as an intermediary between the controller and remote devices. The connection service receives connection requests, retrieves controller information from a database, and establishes connections without requiring users to configure VPNs or port forwarding. This mediator approach eliminates complex user configuration while maintaining remote access capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service through automated controller registration where the controller automatically provides its information to the connection service, and automated connection establishment where the connection service handles all connection setup without user intervention. This self-service mechanism reduces device complexity from the user's perspective.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If VPN connections or port forwarding are used for remote access, then remote access capability is provided, but security risks increase

Engineering Contradiction:
Improveremote access capabilityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The cloud-based connection service acts as a secure intermediary that terminates all external connections to the controller. This architecture prevents direct exposure of the controller to the internet, eliminating security risks associated with port forwarding and VPN configurations. The connection service validates and manages all connections, providing security while maintaining ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If authentication services are implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsetup complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary authentication actions during controller registration. The controller is pre-authenticated and its information is stored in the connection service database before any remote access attempts. This preliminary authentication eliminates the need for complex real-time authentication setup while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication process is automated through self-service mechanisms where the controller automatically registers with the connection service and provides authentication credentials. The connection service automatically manages authentication for all subsequent connections without requiring users to configure or understand authentication settings.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9391966B2Devices for providing secure remote access
Publication Date: 2016.07.12 SNAP ONE LLC
  • US9391966B2 patent drawing
  • US9391966B2 patent drawing
  • US9391966B2 patent drawing

AI summary

A method for providing secure remote access by a controller is described. The method includes sending one or more endpoint requests. The method also includes receiving authentication service endpoint information and connection service endpoint information. The method further includes requesting authentication based on the authentication service endpoint information. Requesting authentication includes requesting license validation. The method also includes sending one or more registration messages based on the connection service endpoint information. The method further includes receiving a session request. The method additionally includes determining controller candidate link information. The method also includes sending the controller candidate link information. The method further includes receiving an automation message based on the controller candidate link information.