Secure Remote Desktop via Segmented Input-Output Paths

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure communication systems in protected installations, such as industrial control systems, face challenges in allowing remote monitoring and control while maintaining high security against unauthorized access, particularly due to the limitations of one-way links that prevent data from entering or leaving the facility.

Innovation Solution

A method and system that enable secure communication by receiving an encrypted stream of symbols from a remote user terminal, decrypting it using a corresponding key, and generating a graphical output for display on the terminal, while maintaining a secure input and output path to prevent unauthorized access, using hardware-based encryption and decryption to ensure only authorized access to the secure installation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a one-way link is used to prevent data from entering or leaving a protected facility, then security against unauthorized access is improved, but the ability to transmit information or commands from external network back into the monitored facility deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The communication system is segmented into separate input and output paths. The output path uses a one-way link for secure data transmission from the protected facility to external networks, while the input path uses a separate mechanism (decoder with digital signature verification) to allow controlled commands to enter the facility. This segmentation allows each path to be optimized for its specific security requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A decoder device acts as an intermediary between external networks and the protected facility for input commands. The decoder verifies digital signatures and controls relay actuation, serving as a trusted mediator that ensures only authorized commands can enter the facility while maintaining the one-way link security for output data transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If remote desktop functionality is enabled for controlling predefined functions, then ease of operation is improved, but the risk of unauthorized access deteriorates

Engineering Contradiction:
Improveremote control capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Before allowing remote control commands to enter the protected facility, the system performs preliminary verification of digital signatures on the input commands. This preliminary security check ensures that only authenticated and authorized commands are processed, preventing unauthorized access while enabling convenient remote operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides feedback to remote users by transmitting graphical output from the protected facility back to external networks through the one-way link. This feedback mechanism enables remote desktop functionality where users can see the results of their commands while the one-way link maintains security by preventing any feedback loop that could enable unauthorized control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3010199B1Secure remote desktop
Publication Date: 2020.09.02 WATERFALL SECURITY SOLUTIONS LTD
  • EP3010199B1 patent drawingFigure 1
  • EP3010199B1 patent drawingFigure 2~3
  • EP3010199B1 patent drawingFigure 4A~4B

AI summary

A method for communication includes receiving in a secure installation (22) via a network (30) from a remote user terminal (32) an input comprising a stream of symbols that has been encrypted using a preselected encryption key. The encrypted stream of symbols is decoded in the secure installation using a decryption key corresponding to the preselected encryption key, to produce a clear stream of symbols. A computer program running on a processor (58) in the secure installation is used in processing the symbols in the clear stream and generating a graphical output in a predefined display format in response to processing the symbols. The graphical output is outputted from the secure installation to the network in an unencrypted format for display on the remote user terminal.