Home Network Terminal Access Control via Host Sensor Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Telecommuting systems face security threats as remote home network terminals lack robust security measures, making them vulnerable to hacking and data leakage, despite existing security protocols that primarily focus on network security.

Innovation Solution

A method and apparatus for controlling access to remote servers in a home network environment, which involves a computing device with a processor and memory, receiving access requests, inspecting the security environment of terminals using a host sensor, and managing access based on the inspection results, redirecting unmanaged terminals to install necessary security agents before permitting access to the remote server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If remote terminals access work servers through home networks using basic security measures (ID and password), then ease of operation is improved, but security reliability deteriorates due to vulnerability to hacking and data leakage

Engineering Contradiction:
Improveease of accessVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary security inspections on terminal environments before allowing access to work servers. Security agents inspect terminal configurations, installed applications, and security settings in advance to ensure compliance with company security policies, thereby preventing insecure access while maintaining ease of use for compliant devices

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A security inspection server acts as an intermediary between remote terminals and work servers. This intermediary component conducts security inspections and issues access control decisions, enabling the system to maintain both ease of operation for authorized devices and high security reliability by blocking unauthorized access

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If IPsec security tunneling is implemented for network security, then network security reliability is improved, but terminal security vulnerability remains because malicious programs can still access servers through the secure tunnel

Engineering Contradiction:
Improvenetwork securityVSAvoidterminal hacking risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The security solution is segmented into multiple independent layers: network-level security (IPsec tunneling) and terminal-level security (host-based security agents). This segmentation allows each layer to address specific security aspects without compromising the other, ensuring that network security does not create false sense of protection against terminal-based threats

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Security agents perform preliminary inspections of terminal environments before allowing access through the secure tunnel. They detect malicious programs, unauthorized applications, and non-compliant security settings in advance, preventing harmful factors from compromising the secure connection to work servers

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive security inspections are performed on all terminal environments, then security reliability is improved, but device complexity increases due to multiple inspection components and protocols

Engineering Contradiction:
Improveaccess securityVSAvoidinspection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security inspection server performs multiple security inspection functions through a unified platform. It conducts various types of inspections (configuration, application, security settings) using standardized protocols, reducing the need for separate inspection systems and minimizing overall device complexity while maintaining high security reliability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240171577A1Method, apparatus, and computer-readable recording medium for controlling access to remote system in home network environment
Publication Date: 2024.05.23 SGA SOLUTIONS CO LTD
  • US20240171577A1 patent drawing
  • US20240171577A1 patent drawing
  • US20240171577A1 patent drawing

AI summary

Access of a home network terminal to a work server in a telecommuting environment is effectively managed to maintain security of the terminal. According to one embodiment of the present invention, a method for controlling access to a remote system in a home network environment includes: an access request reception step of receiving a request signal according to a network protocol when an access request for a remote server, which is an access target, is performed by a terminal on a home network; a security environment inspection step of checking the security environment of the terminal through a host sensor for each protocol that has received the request signal through the access request reception step; and an access permission step of managing access to the remote server according to the security environment checked according to a result of performing the security environment inspection step.