Secure Remote Support Automation via Key Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for remote support of Internet-connected devices behind firewalls or network address translation lack secure and simplified methods for authenticating remote technicians, ensuring traceability, and managing access rights, leading to potential security vulnerabilities and complexities in managing asset control.

Innovation Solution

A secure remote support automation process using public/private key pairs for authentication and access control, where a remote support server initiates a secure connection through a firewall, enabling scheduled tasks with predefined access levels and logging, and escalating tasks if not completed within a time frame, ensuring secure and controlled access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional remote access methods (rlogin, password-based authentication) are used, then remote support can be provided, but security is compromised due to unencrypted transmission and weak authentication

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a key distribution center (KDC) as an intermediary that mediates authentication between remote support personnel and protected systems. The KDC generates and distributes temporary encryption keys without exposing the master password, thereby enhancing security while simplifying the authentication process for end users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the authentication complexity from the end user by implementing automated key management and background authentication processes. The system handles key generation, distribution, and validation automatically, removing the burden of complex password management from users while maintaining strong security.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If strong security measures (firewalls, encryption) are implemented, then system protection is improved, but remote support access becomes more complex and difficult to manage

Engineering Contradiction:
Improvesystem protectionVSAvoidaccess management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the key distribution center automatically generates, distributes, and manages encryption keys without requiring manual intervention from system administrators. The system autonomously handles key rotation, expiration, and revocation, reducing administrative complexity while maintaining robust security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary authentication and key distribution actions before remote support sessions are initiated. By pre-establishing secure channels and distributing temporary keys in advance, the system simplifies the actual support process while maintaining strong security controls throughout.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If remote technicians are granted high-level access for troubleshooting, then support effectiveness is improved, but security risks increase due to potential misuse or unauthorized changes

Engineering Contradiction:
Improvesupport effectivenessVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic access control where encryption keys and authorization levels are temporarily granted for the duration of the support session and automatically revoked afterward. This dynamic key management allows technicians to have high-level access when needed while automatically limiting access afterward, balancing support effectiveness with security risk mitigation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies different authorization levels and encryption keys to different users and sessions based on specific needs. Each remote support technician receives customized access rights appropriate to their task requirements, rather than uniform high-level access for all users, thereby enabling effective support while minimizing security risks through granular control.

Inventive Principle:
Principle #3Local quality

4Reliability

If automated key distribution and session management are implemented, then security and traceability are improved, but system complexity increases

Engineering Contradiction:
ImprovetraceabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal key distribution center that handles multiple functions including key generation, distribution, validation, and session management through a single centralized system. This multi-functional approach improves traceability and security while avoiding the need for multiple separate systems, thereby limiting the increase in overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8838965B2Secure remote support automation process
Publication Date: 2014.09.16 BARRACUDA NETWORKS INC
  • US8838965B2 patent drawing
  • US8838965B2 patent drawing
  • US8838965B2 patent drawing

AI summary

Secure Remote Support Automation Process wherein a remote support server receives a support task request and schedules a predefined task to a predefined actor who also has a predefined escalation policy and notifies the support actor of the scheduled task along with a key, a key seed, or a credential to use in authentication. The method enabling privileged access to an Internet security appliance using public/private key pairs through a firewall and network address translation by a support server and an assigned support task actor.