IP Library Granted Patent US 12676894
Granted Patent B2
US 12676894 · App. 18/559,424 · Granted Jul 7, 2026

Software defined remote access for zero-trust support

Inventors: Reinhard Frank (Münich, DE); Florian Zeiger (Höhenkirchen-Siegertsbrunn, DE)
Assignee: SIEMENS AKTIENGESELLSCHAFT
H04L63/20H04L63/0209
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12676894
App. No.
18/559,424
Granted
Jul 7, 2026
Kind
B2
Abstract

Various embodiments of the teachings herein include an automated method for data access to a device by an external client, allowing the device to communicate with an internal communication network while the external client communicates with an external communication network. An example method includes: sending a communication access request from the external client for the device to a software implemented application access point; configuring a corresponding software implemented connector using the application access point, so the connector acts as an endpoint for a communication tunnel to the device; configuring a corresponding software implemented policy decision point using the application access point as an interface to the external network for arriving of application data traffic of the external client, so the policy decision point is set up to validate, accept, and forward the access request of the external client to the connector; and accessing the device via the communication tunnel.

Claims (26)

1 . A method for data access to a device by an external client, allowing the device to communicate with an internal communication network while the external client communicates with an external communication network, the method comprising:

sending a communication access request from the external client for the device to a software implemented application access point to check and authorize or reject access requests from external clients to devices;

configuring a corresponding software implemented connector using the application access point, so the connector acts as an endpoint for a communication tunnel to the device;

configuring a corresponding software implemented policy decision point using the application access point as an interface to the external network for arriving of application data traffic of the external client, so the policy decision point is set up to validate, accept, and forward the access request of the external client to the connector; and

accessing the device via the communication tunnel using the external client;

wherein checking the access request the application access point includes performing a context matching with a device digital twin of the device.

2 . A method according to claim 1 , wherein the device digital twin is set up with process related data of the device, configuration data of the device, and operational technology (OT) parameters of the device.

3 . A method according to claim 1 , wherein the device digital twin is set up to:

interact with the application access point to validate external clients' connection requests; and

in case of a successful request-validation to notify the device and to schedule the configuration, setup, and activation of a software implemented policy enforcement point on the device.

4 . A method according claim 3 , wherein the policy enforcement point acts as a communication tunnel endpoint, created on-demand, and locally on the device after prior validation of the access request of the external client.

5 . A communication network system, the system comprising:

an internal communication network;

an external communication network;

an external client communicating with the external network;

a device communicating with the internal network;

a software implemented application access point to check and authorize or reject a connection access requests from the external clients to the device;

a software implemented connector of the internal network to be configured by the application access point, so the connector acts as an endpoint for a communication tunnel to the device;

a software implemented policy decision point of the internal network to be configured by the application access point as an interface to the external network for arriving of application data traffic of the external client, and to validate, accept, and forward access requests of the external client to the connector; and

a device digital twin of the device;

wherein the application access point is further set up to check the access request by performing a context matching with the device digital twin.

6 . A system according to claim 5 , wherein the device digital twin is set up with process related data of the device, configuration data of the device, and operational technology (OT) parameters of the device.

7 . A system according to claim 5 , further comprising:

a software implemented policy enforcement point (PEP) on the device;

wherein the device digital twin is set up to interact with the application access point to validate external clients' connection requests, and in case of a successful request validation to notify the device and to schedule the configuration, setup, and activation of the policy enforcement point.

8 . A system according claim 7 , wherein the policy enforcement point acts as a communication tunnel endpoint, created on-demand, and locally on the device after prior validation of the access request of the external client.