Secure Remote Access Controller via Cloud Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing remote access solutions for control systems, such as VPN connections and port forwarding, require complex user configuration and introduce security risks, making it difficult to provide secure and easy-to-use remote access for end-users.
Innovation Solution
A method and system that uses a controller with a remote access agent to authenticate and register with an authentication service, allowing secure remote access through a communication network, which includes sending endpoint requests, receiving authentication and connection service information, and establishing a session request to facilitate secure communication between the controller and an electronic device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If VPN connections or port forwarding are used for remote access, then remote access capability is provided, but device complexity and security risks increase
Solution Approach 1:
The patent introduces a cloud-based connection service as an intermediary between the controller and remote devices. The connection service receives connection requests, retrieves controller information from a database, and establishes connections without requiring users to configure VPNs or port forwarding. This mediator approach eliminates complex user configuration while maintaining remote access capability.
Solution Approach 2:
The system implements self-service through automated controller registration where the controller automatically provides its information to the connection service, and automated connection establishment where the connection service handles all connection setup without user intervention. This self-service mechanism reduces device complexity from the user's perspective.
2Ease of operation
If VPN connections or port forwarding are used for remote access, then remote access capability is provided, but security risks increase
Solution Approach 1:
The cloud-based connection service acts as a secure intermediary that terminates all external connections to the controller. This architecture prevents direct exposure of the controller to the internet, eliminating security risks associated with port forwarding and VPN configurations. The connection service validates and manages all connections, providing security while maintaining ease of operation.
3Reliability
If authentication services are implemented, then security is improved, but device complexity increases
Solution Approach 1:
The system performs preliminary authentication actions during controller registration. The controller is pre-authenticated and its information is stored in the connection service database before any remote access attempts. This preliminary authentication eliminates the need for complex real-time authentication setup while maintaining security.
Solution Approach 2:
The authentication process is automated through self-service mechanisms where the controller automatically registers with the connection service and provides authentication credentials. The connection service automatically manages authentication for all subsequent connections without requiring users to configure or understand authentication settings.
Data Source
AI summary
A method for providing secure remote access by a controller is described. The method includes sending one or more endpoint requests. The method also includes receiving authentication service endpoint information and connection service endpoint information. The method further includes requesting authentication based on the authentication service endpoint information. Requesting authentication includes requesting license validation. The method also includes sending one or more registration messages based on the connection service endpoint information. The method further includes receiving a session request. The method additionally includes determining controller candidate link information. The method also includes sending the controller candidate link information. The method further includes receiving an automation message based on the controller candidate link information.


