Tunnel Proxy Server for Secure Remote Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing software systems face challenges in providing secure remote access to diverse computing systems across various deployments, including on-premise and cloud environments, due to the complexity and time-consuming nature of managing point-to-point connections.

Innovation Solution

A connectivity software system that enables secure remote connections by using a tunnel proxy server to establish connections between a remote connectivity frontend and secure computer systems, with features such as authentication, automatic application launching, and entity-defined constraints for access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If point-to-point connection methods are used for remote access, then secure connectivity to individual systems is achieved, but management complexity and time consumption increase significantly

Engineering Contradiction:
Improvesecure connectivityVSAvoidconnection management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a remote connectivity server as an intermediary component that mediates between user devices and target systems. This server manages connection requests, authenticates users, and establishes connections to multiple systems, eliminating the need for vendors to directly manage complex point-to-point connections to each customer system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The remote connectivity server provides universal access capabilities to multiple different systems through a single platform. It supports various connection types (RDP, SSH, HTTPS, custom protocols) and can connect to diverse system architectures (cloud, on-premises, hybrid), making the connection management system adaptable to different deployment scenarios without requiring separate solutions for each system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple connection types are supported for diverse system deployments, then compatibility is improved, but system complexity increases

Engineering Contradiction:
Improveconnection type compatibilityVSAvoidsystem architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The remote connectivity server is designed as a universal platform that natively supports multiple connection types including RDP, SSH, HTTPS, and custom protocols. This multi-functional design allows a single system to handle diverse connection requirements without requiring separate specialized systems for each protocol or deployment type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system architecture segments connection management into distinct modules or handlers for different connection types. Each connection type can be processed by its specialized handler while benefiting from the central coordination provided by the remote connectivity server, allowing independent management and optimization of each protocol without increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If vendor support engineers need access to customer systems, then technical support capability is improved, but security risks increase

Engineering Contradiction:
Improvetechnical support capabilityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The remote connectivity server acts as a secure intermediary between support engineers and customer systems. It implements authentication mechanisms that verify engineer identities and authorize access based on specific requirements. The server establishes encrypted connection tunnels that protect data in transit, and maintains audit logs of all access activities for security monitoring and compliance purposes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements localized access controls where each support engineer receives specific authorization for particular customer systems or functions based on their role and the support ticket requirements. Access rights are granted on a need-to-know basis rather than universal access, minimizing the security footprint and potential impact of any single compromised account.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250088498A1Systems and methods for connecting to secure computer systems
Publication Date: 2025.03.13 SAP SE
  • US20250088498A1 patent drawing
  • US20250088498A1 patent drawing
  • US20250088498A1 patent drawing

AI summary

Embodiments of the present disclosure include techniques for securely connecting computer systems. In one embodiment, the system allows many users to connect with many different secure computer systems having many different connection types. A user selects an entity and is presented with connection types for the selected entity for the entities target systems. The user selects a connection type and corresponding target, and a tunnel proxy server is configured to connect the user to the selected target. In some embodiments, the connection type is associated with other information. In one embodiment, an application associated with the connection type is automatically launched.