Virtualized Client Instance for Secure Vendor Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in granting access to their private networks to third-party vendors using untrusted client hardware while maintaining network security, as these devices may execute viruses or malware, and it is impractical to control or manage the hardware used by vendors.

Innovation Solution

Implementing a virtualized client instance that provides a remote desktop capability, where the graphical interface is encoded and sent over the network to the untrusted client device, restricting public network access and allowing only specific storage service access, thereby preventing malware installation and data exfiltration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If VPN access is granted to third-party vendors using untrusted client hardware, then access to private network systems is enabled, but network security is compromised due to potential malware execution

Engineering Contradiction:
Improveaccess to private networkVSAvoidmalware execution
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

A virtualized client instance is introduced as an intermediary between the untrusted client device and the private network systems. The virtualized instance runs in a controlled environment within the network infrastructure, allowing vendor access to systems while isolating the untrusted hardware from direct network access. This mediator enables the vendor to perform troubleshooting and support functions without exposing the private network to malware risks from the untrusted client device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is segmented into distinct virtualized environments: the untrusted client device, the virtualized client instance running on network infrastructure, and the private network systems. This segmentation allows controlled interaction between components while maintaining security boundaries. The virtualized instance provides necessary access functions while containing potential security threats within its isolated environment.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple users are granted individual VPN access with administrative supervision, then network security is maintained, but device complexity and management overhead increase

Engineering Contradiction:
Improvenetwork securityVSAvoidmanagement overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The virtualized client instance serves multiple users and multiple functions through a single shared infrastructure component. Instead of requiring separate administrative supervision and individual VPN configurations for each vendor, the virtualized instance provides universal access capabilities to multiple users simultaneously. This multi-functional approach maintains network security while significantly reducing management overhead and complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Multiple user access requirements are merged into a single virtualized client instance that handles authentication and session management for multiple vendors. The virtualized environment consolidates what would otherwise require multiple separate VPN configurations and administrative oversight instances, simplifying the overall system while maintaining security through centralized control.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10846108B1Providing limited access within a private network
Publication Date: 2020.11.24 AMAZON TECH INC
  • US10846108B1 patent drawing
  • US10846108B1 patent drawing
  • US10846108B1 patent drawing

AI summary

Disclosed are various embodiments for providing limited access within a private network. A connection request is received from a client device coupled to a public network. A remote desktop environment is implemented in a private network in response to the connection request. Access to the public network through the remote desktop environment may be restricted to communicating with a particular storage service.