IP Library › Granted Patent US 12,724,900
Granted Patent B2
US 12,724,900 · App. 18/337,151 · Granted Sep 1, 2026

Device risk-based trusted device verification and remote access processing system

Inventors: Ki Uk Lee (Seongnam-si, KR); Jong Hwa Lee (Seoul, KR); Jae Hyeok Park (Seoul, KR)
Assignee: SGA Solutions Co., Ltd.
G06F21/577G06F21/54G06F21/552
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,724,900
App. No.
18/337,151
Granted
Sep 1, 2026
Kind
B2
Abstract

A device risk-based trusted device verification and remote access processing includes: an inspection process start unit for starting a risk inspection process based on risk inspection information set in a device management server; a risk score calculation unit for performing a vulnerability check process and an additional check process corresponding to inspection items based on the risk inspection information to calculate a risk score for the user device through the check result; a trusted device confirmation unit, when a function of the risk score calculation unit is completely performed and the risk score is completely calculated, for transmitting the calculated risk score to the device management server, thereby allowing the device management server to determine whether the user device is a trusted device; and an access monitoring unit for monitoring data transmission and reception in real time between the user device and the business server upon remote access.

Claims (24)

1 . A device risk-based trusted device verification and remote access processing system comprising a computing device including at least one processor and at least one memory storing a set of executable instructions, wherein the at least one processor, upon execution of the instructions, is configured to perform the following steps:

starting, when a remote access application installed on a user device is executed, a risk inspection process based on risk inspection information set in a device management server linked with the remote access application;

calculating a risk score for the user device based on the check result by performing vulnerability check process and an additional check process corresponding to inspection items based on the risk inspection information once the risk inspection process starts;

allowing the device management server to determine whether the user device is a trusted device based on the received risk score by transmitting, once a function of the risk score calculation has been completed and the risk score has been calculated, the calculated risk score to the device management server; and

monitoring data transmission and reception in real time between the user device and a business server when the user device remotely accesses the business server linked with the remote access application while the device management server has registered the user device allowing the user device to remotely access the business server, once the user device has been identified as the trusted device,

wherein the risk inspection information, as information generated by the device management server, includes information composed of vulnerability check items and additional check items including a plurality of pieces of inspection information for verifying whether the user device is a trusted device when the remote access application installed on the user device is executed; wherein the calculating the risk score for the user device includes:

starting a vulnerability check process for the user device when the risk inspection process starts;

completing, in response to when the vulnerability check process starts, the vulnerability check process for the user device by performing at least one of the following inspections: inspection on anti-virus installation, inspection on whether anti-virus is executed, inspection on latest security patches of anti-virus, inspection on latest security patches of an operating system, inspection on latest security patches of a work program, inspection on password stability, inspection on quarterly password change, inspection on screen saver settings, inspection on shared folder settings and inspection on USB auto-run permission, which are based on some of the pieces of inspection information included in the vulnerability check item based on the risk inspection information; and

calculating scores for detailed inspections included in the vulnerability check item through a first check result based on the completed vulnerability check process when a function of the vulnerability check process is completely performed, thereby calculating a first risk score for a vulnerability of the user device by applying the calculated score to a preset risk score formula;

wherein the calculating the risk score includes:

starting an additional test process for the user device when the vulnerability check process is performed;

completing, in response to when the additional check process starts, an additional check process for the user device by performing at least one of the following inspections: inspection on whether an editing program is installed, inspection on whether a wireless LAN card is installed, inspection on whether a secure USB is installed, inspection on whether an unauthorized program is installed, inspection on web browser settings, inspection on firewall settings, inspection on user device account settings, inspection on port vulnerability, inspection on whether a security sensor is activated and inspection on whether an NTP server is synchronized, which are based on some of the pieces of inspection information included in the additional check item based on the risk inspection information; and

calculating, in response to when a function of the additional check process is completely performed, scores for detailed inspections included in the additional check item through a second check result based on the completed additional check process, thereby calculating a second risk score for a function setting of the user device by applying the calculated score to the preset risk score formula;

wherein the determining whether the user device is a trusted device through the received risk score includes:

transmitting, when the calculating the risk score is completely performed and the first risk score and the second risk score are completely calculated, the first risk score and the second risk score to the device management server; and

determining, when the device management server receives the first risk score and the second risk score and then the device management server determines a reliability level for the user device through the first risk score and the second risk score, whether the user device is a trusted device through the determined reliability level; and

wherein the device management server is configured to perform the following steps:

confirming whether each of the first risk score and the second risk score is included in any one of preset reliability score ranges when the first risk score and the second risk score are received;

processor determining a reliability level of the user device as a trusted level upon confirming that both of the first risk score and the second risk score are included in the first score range among the preset reliability score ranges; and

determining, upon confirming that each of the first risk score and the second risk score is included in at least one of a second score range or a third score range among the preset reliability score ranges, a reliability level of the user device as an intermediate level corresponding to the second score range or an untrusted level corresponding to the third score range.

2 . The device risk-based trusted device verification and remote access processing system of claim 1 , wherein, when the reliability level of the user device is determined to be the intermediate level, the device management server identifies detailed inspections less than a designated score among detailed inspections based on the vulnerability check process and detailed inspections based on the additional check process through history information based on the vulnerability check inspection process and the additional check process, and provides the user device with setting guide information for calculating the identified detailed inspections to have the designated score or higher so as to allow a user of the user device to change settings of the user device through the setting guide information, so that the reliability level of the user device is re-determined as the trusted level.

3 . The device risk-based trusted device verification and remote access processing system of claim 2 , wherein the monitoring data transmission and reception in real time between the user device and the business server includes:

determining the user device as a trusted device when the reliability level of the user device is determined as the trusted level from the device management server, thereby registering the user device to allow the user device to remotely access the business server; and

providing a monitoring server with monitoring information obtained by monitoring data transmitted and received between the business server and the user device when the user device remotely accesses the business server while the determining the user device is completely performed.

Priority Claims (1)
KR 10-2022-0155009 · Nov 18, 2022 · national
Continuity (1)
Related Publication 20240169071A1 · May 23, 2024
References Cited (16)
US 11563764B1 · Hoscheit · 2023 [cited by examiner]
US 20060212925A1 · Shull · 2006 [cited by examiner]
US 20090094164A1 · Fontaine · 2009 [cited by examiner]
US 20100146611A1 · Kuzin · 2010 [cited by examiner]
US 20180063178A1 · Jadhav · 2018 [cited by examiner]
US 20180124096A1 · Schwartz · 2018 [cited by examiner]
US 20190319987A1 · Levy · 2019 [cited by examiner]
US 20220029882A1 · Sarukkai · 2022 [cited by examiner]
US 20220255942A1 · Szigeti · 2022 [cited by examiner]
US 20220407893A1 · Maiman · 2022 [cited by examiner]
US 20230237407A1 · Chrapko · 2023 [cited by examiner]
US 20230418949A1 · Stocks · 2023 [cited by examiner]
KR 1020090121466 · 2009 [cited by applicant]
KR 1020180018197 · 2018 [cited by applicant]
KR 1020190135621 · 2019 [cited by applicant]
Office Action for Korean Patent Application No. 10-2022-0155009, dated Feb. 8, 2023. [cited by applicant]