Secure Remote Configuration for Network Terminals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VPN configurations for remote devices, such as network probes, require physical access for customization and secure key distribution, which is impractical for large deployments, especially when access is restricted by firewalls and the need to ensure identity verification of the device receiving configuration settings.

Innovation Solution

A method where a server establishes a connection with a terminal, using an identifier-derived communication port to redirect requests, generates and transmits control data, and upon confirmation of a trusted terminal, configures and transmits customized parameters, ensuring secure and unique identification and access rights for each device, even behind firewalls.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical access is required to configure terminals with unique identifiers and key pairs, then security and unique identification are ensured, but deployment efficiency and scalability deteriorate due to manual configuration requirements

Engineering Contradiction:
ImprovesecurityVSAvoiddeployment efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The terminal automatically generates a connection request with its identifier and communicates with the server to receive customized configuration parameters without requiring manual physical configuration. The terminal serves itself by initiating the configuration process and receiving unique credentials automatically.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The terminal is pre-configured with a generic identifier and shared key pair before deployment. This preliminary configuration enables the terminal to autonomously initiate communication with the server and request customized configuration parameters, eliminating the need for physical setup.

Inventive Principle:
Principle #10Preliminary action

2Ease of manufacture

If generic configuration is used for all terminals, then deployment simplicity is maintained, but security deteriorates due to lack of unique identification and authentication

Engineering Contradiction:
Improvedeployment simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

Each terminal receives customized configuration parameters including a unique identifier and private key pair specific to that terminal. The server generates and transmits terminal-specific credentials based on the terminal's generic identifier, ensuring local uniqueness while maintaining centralized management.

Inventive Principle:
Principle #3Local quality

3Reliability

If manual configuration methods are used, then configuration security can be controlled, but operation complexity increases due to physical access requirements and manual procedures

Engineering Contradiction:
Improveconfiguration securityVSAvoidoperation complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The manual physical configuration process is replaced by an automated electronic communication system. The terminal uses its generic identifier to establish communication with the server, which then automatically transmits customized configuration parameters, eliminating the need for physical access and manual configuration procedures.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Productivity

If remote configuration is implemented without physical access, then deployment scalability improves, but security deteriorates due to potential interception and identity verification issues

Engineering Contradiction:
Improvedeployment scalabilityVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The server acts as a trusted intermediary between terminals and the configuration system. The server verifies terminal identities using generic identifiers, generates unique configuration parameters including private key pairs, and securely transmits them to terminals. This intermediary mechanism ensures security in remote configuration by centralizing trust and verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The server creates unique copies of configuration credentials for each terminal based on the terminal's generic identifier. Each terminal receives a customized copy of the configuration parameters including a unique private key pair, ensuring that while the process is remote and automated, each terminal has its own secure credentials.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11431707B2Method, device and server for the secure distribution of a configuration to a terminal
Publication Date: 2022.08.30 ORANGE SA
  • US11431707B2 patent drawing
  • US11431707B2 patent drawing
  • US11431707B2 patent drawing

AI summary

Distributing a configuration to a first terminal, including establishing, on initiative of the first terminal, a connection between the first terminal and a server, which is configured to redirect connection requests received by the server on a communication port to the first terminal. The communication port is derived from an identifier of the first terminal received in a message establishing the connection. When the identifier of the terminal is associated with a plurality of terminals, the method includes generating and storing control data in association with the identifier of the terminal, transmitting, via the connection, a control message to the first terminal, which includes the control data, receiving, from a second terminal, a confirmation message including the control data and an identifier of the second terminal, and when the second terminal is a trusted terminal, and transmitting customized parameters to the first terminal to access the server.