Trusted Operator Mediated Access Gateway for Secure Remote Sessions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access systems for remote computing infrastructures, such as cloud computing, lack sufficient security measures, allowing malicious third parties to gain unsupervised access if they bypass authentication barriers, posing a risk to customer data and operations.

Innovation Solution

A supervised access method and system that utilizes a trusted operator with higher access rights to establish and control a shared computer session with external operators, employing a remote connection terminal service with strong authentication and ephemeral server execution to ensure secure and monitored access to remote computing infrastructure operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a bastion with strong authentication barrier is implemented to protect the client's IT system, then security is improved, but if authentication is bypassed, complete and unmonitored access is gained to the system

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a terminal service server as an intermediary component between the bastion and the client's IT system. This server acts as a mediator that receives authenticated connections from operators and provides controlled access to the target system, thereby maintaining security while enabling monitored access operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a feedback mechanism where the terminal service server continuously monitors and logs all access operations performed by external operators. This feedback loop ensures that all actions are recorded and can be reviewed, preventing unauthorized or malicious activities while maintaining accountability.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If external operators are granted access rights to perform support actions, then operational support capability is improved, but security risks increase due to potential malicious unauthorized access

Engineering Contradiction:
Improvesupport capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The terminal service server serves as an intermediary that enables external operators to perform support actions on the client's IT system without granting them direct access rights. All operations are routed through this controlled interface, which filters and monitors their actions to prevent security risks while maintaining support capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the access control architecture into multiple components: the authentication layer (bastion), the intermediary layer (terminal service server), and the target layer (client's IT system). This segmentation allows external operators to perform support actions through the controlled intermediary layer without compromising the security of the target system.

Inventive Principle:
Principle #1Segmentation

3Reliability

If authentication barriers are strengthened to prevent malicious access, then security is improved, but the complexity of the access system increases

Engineering Contradiction:
ImprovesecurityVSAvoidaccess system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication and access control functions into a unified terminal service server that handles both authentication verification and operational monitoring in a single integrated component. This reduces system complexity compared to having separate authentication and access control systems while maintaining strong security.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP4206917A1Method and system for framed access of at least one external operator to a set of operations of a computing infrastructure
Publication Date: 2023.07.05 THALES SA
  • EP4206917A1 patent drawingFigure 1
  • EP4206917A1 patent drawingFigure 2
  • EP4206917A1 patent drawingFigure 3

AI summary

The invention relates to a method and a system for providing access, by at least one external operator, to a set of operations provided by a remote computing infrastructure to a client via a communications network. The access system is operated by a trusted operator, distinct from said external operator. This method comprises receiving (40) a request from said trusted operator to establish a shared computing session with the external operator, instantiating (44) a server and a remote connection terminal service to said server, generating (46) an access gateway to said terminal service, and providing (48-56) access to said terminal service, via said access gateway, to the trusted operator and the external operator.Following the receipt (58) of a request to stop said shared computer session, the trusted operator and the external operator are disconnected (60) and the terminal service on the server is stopped (64).