Nested Virtual Private Network Tunnels
A network device with dual profiles and VPN clients/proxies enables double encryption, addressing latency and compatibility issues, ensuring secure data transmission with enhanced security and compatibility.
Patent Information
- Authority / Receiving Office
- GB · GB
- Patent Type
- Patents
- Current Assignee / Owner
- ARQIT LTD
- Filing Date
- 2023-10-27
- Publication Date
- 2026-07-15
Smart Images

Figure 00000001_0000 
Figure 00000002_0000 
Figure 00000003_0000
Abstract
Description
[0001] The present application relates to a network device, a system comprising the network device, a method for using the network device, a method for configuring the network device and software for carrying out the methods. 5 Background
[0002] To securely transmit over a public network, such as the internet, data can be sent over a virtual private network (VPN) network between a VPN client and a VPN server. The VPN client can encrypt the data being sent over the public network, such as the contents of the data and any information relating to a network device hosting the VPN client. The 10 communicative link between the VPN client and the VPN server over the public network is often referred to as a VPN tunnel. CXI 15 20
[0003] To improve security, it is possible to encrypt the data more than once (double encryption) by encrypting the data by a first VPN client and then sending the encrypted data to a second VPN client for further encryption. This is sometimes known as a nested VPN tunnel configuration. However, it is difficult to host two VPN clients on a single network device. Hosting two VPN clients on separate network devices can lead to latency issues and imposes a burden to have two trusted network devices, instead of one trusted network device.
[0004] Accordingly, there is a desire to provide an efficient and effective solution for double encryption on a single network device.
[0005] The embodiments described below are not limited to implementations which solve any or all of the disadvantages of the known approaches described above. Summary
[0006] This Summary is provided to introduce a selection of concepts in a simplified form that are further described below in the Detailed Description. This Summary is not intended to 25 identify key features or essential features of the claimed subject matter, nor is it intended to be used to determine the scope of the claimed subject matter; variants and alternative features which facilitate the working of the invention and / or serve to achieve a substantially similar technical effect should be considered as falling into the scope of the invention disclosed herein. 30
[0007] According to a first aspect of the invention, there is a network device comprising a first profile and a second profile each configured to run locally on the network device, wherein: the first profile comprises: a first virtual private network, VPN, client configured to encrypt data generated by the first profile to generate one-time encrypted data; and a proxy client configured to send the one-time encrypted data to the second profile; the second profile comprises: a proxy server configured to receive the one-time encrypted data from the proxy client; and a second VPN client configured to encrypt the one-time encrypted data received 5 by the proxy server to generate twice encrypted data.
[0008] According to an embodiment the first profile further comprises a user application for generating application data and the first VPN client is configured to encrypt the application data generated by the user application to generate the one-time encrypted data.
[0009] According to an embodiment the first profile further comprises a key provider 10 configured to provide a key for encrypting data generated by the first profile; and the first VPN client is configured to encrypt the data generated by the first profile with the key provided by the key provider.
[0010] According to an embodiment the second VPN client is further configured to send the twice encrypted data to a public network. 15
[0011] According to an embodiment encrypting the one-time encrypted data received by the proxy server comprises encrypting an internet protocol, IP, address of the first VPN client.
[0012] According to a second aspect of the invention there is a system comprising a first network device according to any preceding claim, wherein the system further comprises a first VPN server and a second VPN server, wherein: the first VPN server is suitable for: decrypting 20 the twice encrypted data to generate the one-time encrypted data; and sending the one-time encrypted data to the second VPN server; and the second VPN server is suitable for decrypting the one-time encrypted data received from the first VPN server to obtain the data generated by the first profile.
[0013] According to an embodiment at least one of the first VPN server and second VPN 25 server are within a secured network boundary.
[0014] According to an embodiment the second VPN server is further suitable for sending the data to another network device or another application.
[0015] According to a third aspect of the invention there is a computer-implemented method for using a network device comprising a first profile and a second profile each configured to 30 run locally on the network device, the method comprising: encrypting, by a first VPN client of the first profile, data generated by the first profile to generate one-time encrypted data; sending, by a proxy client of the first profile, the one-time encrypted data to the second profile; receiving, by a proxy server of the second profile, the one-time encrypted data from the proxy client; and encrypting, by a second VPN client of the second profile, the one-time encrypted data received by the proxy server to generate twice encrypted data.
[0016] According to a fourth aspect of the invention there is a computer-implemented method for configuring a network device, the method comprising: establishing a first profile 5 and a second profile locally on the network device; configuring a VPN client on the second profile, hereinafter referred to as a second VPN client; establishing a proxy server on the second profile; establishing a proxy client on the first profile; connecting the proxy server on the second profile to the proxy client on the first profile; establishing a VPN client on the first profile, hereinafter referred to as a first VPN client, to encrypt data generated by the first 10 profile to generate one-time encrypted data.
[0017] According to a fifth aspect of the invention there is an apparatus comprising a processor unit, a memory unit and a communication interface, the processor unit connected to the memory unit and the communication unit, wherein the apparatus is configured to implement the computer-implemented method according to any of the third or fourth aspect of 15 the invention.
[0018] According to a sixth aspect of the invention there is a computer-readable medium comprising code or computer instructions stored thereon, which when executed by a processor unit, causes the processor unit to perform the computer-implemented method according to any one of the third or fourth aspect of the invention. 20
[0019] The methods described herein may be performed by software in machine readable form on a tangible storage medium e.g. in the form of a computer program comprising computer program code means adapted to perform all the steps of any of the methods described herein when the program is run on a computer and where the computer program may be embodied on a computer readable medium. Examples of tangible (or non-transitory) 25 storage media include disks, thumb drives, memory cards etc. and do not include propagated signals. The software can be suitable for execution on a parallel processor or a serial processor such that the method steps may be carried out in any suitable order, or simultaneously.
[0020] This application acknowledges that firmware and software can be valuable, 30 separately tradable commodities. It is intended to encompass software, which runs on or controls “dumb” or standard hardware, to carry out the desired functions. It is also intended to encompass software which “describes” or defines the configuration of hardware, such as HDL (hardware description language) software, as is used for designing silicon chips, or for configuring universal programmable chips, to carry out desired functions.
[0021] The preferred features may be combined as appropriate, as would be apparent to a skilled person, and may be combined with any of the aspects of the invention. Brief Description of the Drawings
[0022] Embodiments of the invention will be described, by way of example, with reference to 5 the following drawings, in which:
[0023] Figure 1 shows a first system for connecting a network device to a destination network device via a virtual private network;
[0024] Figure 2 shows the network device of the first system and components of the network device therein; 10
[0025] Figure 3 shows a second system for connecting a network device to a destination network device via a VPN; and
[0026] Figure 4 shows the network device of the second system and components of the network device therein.
[0027] Common reference numerals are used throughout the figures to indicate similar 15 features. Detailed Description
[0028] Embodiments of the present invention are described below by way of example only. These examples represent the best mode of putting the invention into practice that are currently known to the Applicant although they are not the only ways in which this could be 20 achieved. The description sets forth the functions of the example and the sequence of steps for constructing and operating the example. However, the same or equivalent functions and sequences may be accomplished by different examples.
[0029] Figure 1 shows a first system 100 for connecting a network device 110 to a destination network device 140 via a virtual private network (VPN). Figure 2 shows the 25 network device 110 of the first system 100 and components of the network device 110 therein. The first system 100 comprises: a network device 110 and a VPN server 130. The network device 110 comprises an application 112 and a VPN client 114. The application 112 and the VPN client 114 can run on a profile 116 provided by an operating system of the network device 110. 30
[0030] In a system for connecting a network device 110 to a destination network device 140 via a VPN, user(s) of the network device 110 and the destination network device 140 require data generated by the network device 110 to be sent securely from the network device 110 to the destination network device 140.
[0031] It is noted that the data generated by the network device 110 can be generated by the user application 112. The application 112 can be any type of computer application. The 5 application 112 includes, but is not limited to, for example, a desktop application, a smartphone application, a tablet application. 10 15 CXI
[0032] To ensure that the data generated by the network device 110 is sent securely from the network device 110 to the destination network device 140, the data is sent from the VPN client 114 of the network device 110 to the VPN server 130 before the data is received by the destination network device 140. The VPN client 114 encrypts the data generated by the network device 110, for example, the contents of the data being sent from the network device 110 and any information relating to the properties of the network device, such as an internet protocol (IP) address of the network device 110. The VPN client 114 can send the data to an internet service provider (ISP), not shown, to route the data to the VPN server 130. The data is securely sent to the VPN server 130 because the data is sent in an encrypted format to the VPN server 130. The data can be sent from the VPN client 114 to the VPN server 130 via a public network, such as the public internet 120. Advantageously, any third-party eavesdropping on the data sent by the VPN client 114 will not be able to access the contents and information contained in the encrypted data. 20
[0033] It is noted that, optionally, the network device 110 can send data from the network device 110 to the VPN server 130 via a public internet 120. Alternatively, the network device 110 can send data from the network device 110 to the VPN server 130 via a private network, such as a local area network.
[0034] Once the VPN server 130 receives the encrypted data sent by the network device 25 110 using the VPN client 114, the VPN server 130 authenticates the encrypted data sent by the network device 110. When authenticating the encrypted data, the VPN server 130 checks if the data received by the VPN server 130 is from a trusted network device 110. This ensures that only trusted network devices 110 can send data to the VPN server 130.
[0035] The VPN sever 130 then decrypts the encrypted data sent by the network device 110. 30 Once the VPN server 130 decrypts the data sent by the network device 110, the VPN server can send the data to the destination network device 140.
[0036] It is noted that the encryption of data and decryption of the data generated by the network device 110 can be done using known encryption and decryption schemes, such examples include, but are not limited to Advanced Encryption Standard (AES), Blowfish and Camellia.
[0037] It is noted that examples of the destination network device 140 include, but are not limited to a workplace server, a server hosting a website, a personal computer, a smartphone, a laptop.
[0038] It is noted that the VPN client 114 and the VPN server 130 communicate using known VPN protocols. Examples include, but are not limited to, IPsec, WireGuard (RTM) and OpenVPN (RTM). 10 CXI 15
[0039] Figure 3 shows a second system 200 for connecting a network device 210 to a destination network device 240 via a VPN. Figure 4 shows the network device 210 of the second system and components of the network device 210 therein. The second system 200 comprises: a network device 210 and a first VPN server 230 and a second VPN server 235. The network device 210 comprises an application 212, a first VPN client 214, a proxy client 215, a proxy server 216, and a second VPN client 217. The application 212, the proxy client 215 and the first VPN client 214 can run on a first user profile 218 provided by an operating system of the network device 210. The proxy server 216 and the second VPN client 217 can run on a second user profile 218 provided by the operating system of the network device 210. 20
[0040] It noted that example network devices 210 include, but are not limited to, a smartphone, an Android (RTM) device, a network device comprising an Android (RTM) operating system.
[0041] In a system for connecting a network device 210 to a destination network device 240 via a VPN, user(s) of the network device 210 and the destination network device 240 require data generated by the network device 210 to be sent securely from the network device 210 to the destination network device 240. 25
[0042] It is also noted that the data generated by the network device 210 can be generated by the user application 212. The application 212 can be any type of computer application. The application 212 includes, but is not limited to, for example, a desktop application, a smartphone application, a tablet application.
[0043] To ensure that the data generated by the network device 210 is sent securely from 30 the network device 210 to the destination network device 240, the data is sent from a first VPN client 214 of the network device 210 to a second VPN client 217 of the network device 210. The data is then sent to a first VPN server 230 and then a second VPN server 235 before the data is received by the destination network device 240. The first VPN client 214 can also be referred to as an inner VPN client 214. The second VPN client 217 can also be referred to as an outer VPN client 217. The first VPN server 230 can also be referred to as an outer VPN server 230. The second VPN server 235 can also be referred to as an inner VPN server 235. This is because the outer VPN client 217 and the outer VPN server 230 encrypts 5 the data sent between the inner VPN client 214 and the inner VPN server 235 via the VPN tunnel between the outer VPN client 217 and the outer VPN server 230. Accordingly, the data and presence of the inner VPN client 214 and the inner VPN server 235 is unknown to a third party eavesdropping data sent between the outer VPN client 217 and the outer VPN server 230. 10
[0044] It is noted that, collectively, the communication path between which the data is sent between the outer VPN client 214 and the outer VPN server 230 can be referred to as an outer VPN tunnel. Collectively, the communication path between which the data is sent between the inner VPN client 214 and the inner VPN server 235 can be referred to as an inner VPN tunnel. 15 CXI 20
[0045] Referring to the network device 210, the network device 210 comprises a first profile 218 and a second profile 219. The first profile 218 and second profile 219 can be user profiles of an operating system of the network device 210. For example, the first profile 218 can be a work profile of the operating system of the network device 210 and the second profile 219 can be a personal profile of the operating system of the network device 210. Vice versa, in another example, the first profile 218 can be a personal profile of the operating system of the network device 210 and the second profile 219 can be a work profile of the operating system of the network device 210.
[0046] The first profile 218 and the second profile 219 can generate separate data from an application 212 of the network device 210. The first profile 218 and second profile 219 can 25 share system settings, these include but are not limited to, network configuration settings and user interface settings,
[0047] It is noted that, the first profile 218 and second profile 219 can be created using a device management application or a unified endpoint management application of the network device 210. It is noted that, the first profile 218 and second profile 219 can be configured to 30 be running locally on the network device 210.
[0048] The first profile 218 comprises an application 212 for generating data. The first profile 218 further comprises an inner VPN client 214 and a proxy client 215. The inner VPN client 214 encrypts the data generated by the network device 210 within the first profile 218. The data encrypted by the inner VPN client 214 is referred to as one-time encrypted data. The 35 data can comprise, for example, contents of the data being sent from the network device 210 and / or information relating to the properties of the network device 210, such as an IP address of the network device 210. The data can be generated by an application 212 of the network device 210.
[0049] Optionally, the network device 210 can further comprise a key provider 213. The key 5 provider 213 can be separate from the inner VPN client 214. The key provider can provide a key for encrypting the data generated by the network device 210 within the first profile 218. For example, the key provider 213 can provide the key to the inner VPN client 214 using a key providing interface. Key providing interface can include the European Telecommunications Standards Institute 014 key providing interface standard. 10
[0050] The inner VPN 214 can then send the one-time encrypted data to the proxy client 215. The proxy client 215 is configured to send the one-time encrypted data from the first profile 218 to the second profile 219.
[0051] The second profile 219 comprises an outer VPN client 217 and a proxy server 216. The proxy server 216 is configured to receive the one-time encrypted data from the proxy 15 client 215 of the first profile. The proxy server 216 then sends the one-time encrypted data to the outer VPN client 217.
[0052] It is noted that, the proxy client 215 and the proxy server 216 can communicate using transmission control protocol (TCP) or user datagram protocol (UDP). It is noted that the proxy client 215 and the proxy server 216 can communicate using SOCKS5 protocol or 20 Shadowsocks protocol.
[0053] The outer VPN client 217 encrypts the received by the proxy server 216. The onetime encrypted data further encrypted by the outer VPN client 217 is referred to as twice encrypted data. In other words, the original data generated by the first profile is double encrypted by the network device 210; firstly by the inner VPN client 214 and secondly by the 25 outer VPN client 217. Accordingly, the contents of the one-time encrypted data is protected from view by a third party eavesdropping the twice encrypted data. Furthermore, the presence of the inner VPN tunnel created by the inner VPN client 214 and the inner VPN server 235 is also protected from a third party eavesdropping the twice encrypted data. Advantageously, the proxy client 215 and proxy server 216 facilitates data to be routed between the first profile 30 218 and the second profile 219. Advantageously, by sending the data through both the inner and outer VPN clients and servers, the data is double encrypted.
[0054] The outer VPN client 217 can send the twice encrypted data to an ISP, not shown, to route the data to the outer VPN server 230 via, for example, the public internet 220. The twice encrypted data is securely sent to the outer VPN server 230 because the twice encrypted data is sent, for example via the public internet 220, in an encrypted format to the outer VPN server 230. Advantageously, any third-party eavesdropping on the twice encrypted data sent by the outer VPN client 217 will not be able to have access to the contents and information contained in the one-time encrypted data or the data generated by the first profile. 5
[0055] Once the outer VPN server 230 receives the twice encrypted data sent by the network device 210 using the outer VPN client 217, the outer VPN server 230 authenticates the encrypted data sent by the network device 210. When authenticating the encrypted data, the outer VPN server 230 checks if the data received by the VPN server 230 is from a trusted network device 210. This ensures that only trusted network devices 210 can send data to the 10 VPN server 230. 15 CXI
[0056] The outer VPN server 230 then decrypts the twice encrypted data sent by the network device 210 to generate the one-time encrypted data. Once the outer VPN server 230 decrypts the twice encrypted data sent by the network device 210, the outer VPN server 230 can send the one-time encrypted data to the inner VPN server 235. Once the inner VPN server 235 then decrypts the one-time encrypted data received rom the outer VPN server 230 to generate the original data generated by the first profile of the network device 210. This decrypted data is subsequently securely sent to a destination network device 240 that requires the data generated by the first profile of the network device 210.
[0057] Advantageously the routing of data between the proxy client 215 on the first profile 20 218 and the proxy server 216 on the second profile 219 allows double encryption of the data generated by the first profile on a single network device. Advantageously, the proxy client 215 and proxy server 216 routing data between the first profile 218 and second profile 219 provides is compatible with any network device that can provide this arrangement; additional software is not required to achieve double encryption of data generated by a network device. 25 Advantageously, the proxy client 215 and proxy server 216 routing data between the first profile 218 and second profile 219 provides is compatible with any operating system that can provide a plurality of profiles, wherein each profile can create a proxy client and / or server.
[0058] It is noted that, optionally, the network device 210 can also send data from the network device 210 to the outer VPN server 230 via the public internet 220. Alternatively, the 30 network device 210 can send data from the network device 210 to the outer VPN server 230 via a private network, such as a local area network.
[0059] It is noted that in the illustrated embodiment of Figure 3, the outer VPN server 230 and the inner VPN server 235 are in direct communication. However, the outer VPN server 230 can receive the twice encrypted data and then, after decrypting, indirectly send the one-35 time encrypted data to the inner VPN server 235. For example, the outer VPN server 230 can send the one-time encrypted data to the inner VPN server 235 via the public internet 220. Similarly, it is noted that in the illustrated embodiment of Figure 3, the inner VPN server 235 and the destination network device 240 are in direct communication. However, the inner VPN server 235 can receive the one-time encrypted data and then, after decrypting, indirectly send 5 the data to the destination network device 240.
[0060] It is noted that, at least one of the outer VPN server 230, the inner VPN server 235 and the destination network device 240 can be within a secured network boundary. It is noted that the secured network boundary can be a separation between a secured private network and a public network of the second system 200. For example, the secured network boundary 10 of the second system can comprise a secured private network comprising at least one the outer VPN server 230, the inner VPN server 235 and the destination network device 240 and a public network comprising the network device 210 and the public internet 220. In the illustrated embodiment of Figure 3, the secured private network comprises the outer VPN server 230, the inner VPN server 235 and the destination network device. However, the 15 invention is not limited to such arrangements. The secured network boundary can be configured such that the secured private network can only be accessed by authorised parties. For example, the VPN servers of the second system 200 can be privately managed and hosted within the secured private network such that they can only be accessed from specific locations. Alternatively, VPN servers of the second system 200 can be accessed by VPN 20 servers that are less restricted and accessible from any location.
[0061] It is noted that, optionally, the outer VPN server 230 and / or the inner VPN server 235 are cloud based. Alternatively, the outer VPN server 230 and / or the inner VPN server 235 can be within a local area network comprising the network device 210.
[0062] It is noted that the encryption of data and decryption of the data generated by the 25 network device 210 can be done using known encryption and decryption schemes, such examples include, but are not limited to Advanced Encryption Standard (AES), Blowfish and Camellia.
[0063] It is noted that examples of the destination network device 240 include, but are not limited to a workplace server, a server hosting a website, a personal computer, a smartphone, 5 a laptop.
[0064] It is noted that the VPN client 214 and the VPN server 230 communicate using known VPN protocols. Examples include, but are not limited to, IPsec, WireGuard (RTM) and OpenVPN (RTM).
[0065] It is noted that the illustrated embodiments show two profiles - a first profile 218 and 10 a second profile 219. However, the disclosure is not limited to two profiles. The network device 210 can comprise any plurality of profiles joined by an equal corresponding number of proxy client 215 and proxy server 216 pairs routing data between the plurality of profiles. Naturally, a corresponding number of VPN servers would be required to decrypt the encrypted data sent by the networking device 210. 15
[0066] Figure 5 shows a computing system 2000, on which any of the above-described methods may be performed. In particular, the Computing system 2000 may comprise a single computing device or components such as a laptop, tablet, desktop or other computing device. Alternatively functions of system 2000 may be distributed across multiple computing devices.
[0067] The Computing system 2000 may include one or more controllers such as controller 20 2005 that may be, for example, a central processing unit processor (CPU), a graphics processing unit (GPU) a chip or any suitable processor or computing or computational device such as an FPGA mentioned, an operating system 2015, a memory 2020 storing executable code 2025, storage 2030 which may be external to the system or embedded in memory 2020, one or more input devices 2035 and one or more output devices 2040. 25
[0068] One or more processors in one or more controllers such as controller 2005 may be configured to carry out any of the methods described here. For example, one or more processors within controller 2005 may be connected to memory 2020 storing software or instructions that, when executed by the one or more processors, cause the one or more processors to carry out a method according to some embodiments of the present invention. 30 Controller 2005 or a central processing unit within controller 2005 may be configured, for example, using instructions stored in memory 2020, to perform the method as described above.
[0069] Input devices 2035 may be or may include a mouse, a keyboard, a touch screen or pad or any suitable input device. It will be recognized that any suitable number of input 5 devices may be operatively connected to computing system 2000 as shown by block 2035. Output devices 2040 may include one or more displays, speakers and / or any other suitable output devices. It will be recognized that any suitable number of output devices may be operatively connected to computing system 2000 as shown by block 2040. The input and output devices may for example be used to enable a user to select information, e.g., images 10 and graphs as shown here, to be displayed 15 CXI 20 25 30
[0070] In the embodiments described above, all or parts of the method may be performed by a server. The server may comprise a single server or network of servers. In some examples, the functionality of the server may be provided by a network of servers distributed across a geographical area, such as a worldwide distributed network of servers, and a user / operator of the method may be connected to an appropriate one of the network servers based upon, for example, a user location.
[0071] The embodiments described above are fully automatic. In some examples a user or operator of the system may manually instruct some steps of the method to be carried out.
[0072] In the described embodiments of the invention parts of the system may be implemented as a form of a computing and / or electronic device. Such a device may comprise one or more processors which may be microprocessors, controllers or any other suitable type of processors for processing computer executable instructions to control the operation of the device in order to gather and record routing information. In some examples, for example where a system on a chip architecture is used, the processors may include one or more fixed function blocks (also referred to as accelerators) which implement a part of the method in hardware (rather than software or firmware). Platform software comprising an operating system or any other suitable platform software may be provided at the computing-based device to enable application software to be executed on the device.
[0073] Various functions described herein can be implemented in hardware, software, or any combination thereof. If implemented in software, the functions can be stored on or transmitted over as one or more instructions or code on a computer-readable medium. Computer-readable media may include, for example, computer-readable storage media. Computer-readable storage media may include volatile or non-volatile, removable or non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data. A computer-readable storage media can be any available storage media that may be accessed by a computer. By way of example, and not limitation, such computer-readable storage media may comprise RAM, ROM, EEPROM, flash memory or other memory devices, CD-ROM or other optical disc storage, magnetic disc storage or other magnetic storage devices, or any other medium that 5 can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer. Disc and disk, as used herein, include compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk, and blu-ray disc (BD). Further, a propagated signal is not included within the scope of computer-readable storage media. Computer-readable media also includes communication media 10 including any medium that facilitates transfer of a computer program from one place to another. A connection, for instance, can be a communication medium. For example, if the software is transmitted from a website, server, or other remote source using a coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of communication medium. Combinations of the 15 above should also be included within the scope of computer-readable media.
[0074] Alternatively, or in addition, the functionality described herein can be performed, at least in part, by one or more hardware logic components. For example, and without limitation, hardware logic components that can be used may include Field-programmable Gate Arrays (FPGAs), Program-specific Integrated Circuits (ASICs), Program-specific Standard Products 20 (ASSPs), System-on-a-chip systems (SOCs), Complex Programmable Logic Devices (CPLDs), etc.
[0075] Although illustrated as a single system, it is to be understood that a computing device may be a distributed system. Thus, for instance, several devices may be in communication by way of a network connection and may collectively perform tasks described 25 as being performed by the computing device. Although illustrated as a local device it will be appreciated that the computing device may be located remotely and accessed via a network or other communication link (for example using a communication interface).
[0076] The term 'computer' is used herein to refer to any device with processing capability such that it can execute instructions. Those skilled in the art will realise that such processing 30 capabilities are incorporated into many different devices and therefore the term 'computer' includes PCs, servers, mobile telephones, personal digital assistants and many other devices.
[0077] Those skilled in the art will realise that storage devices utilised to store program instructions can be distributed across a network. For example, a remote computer may store an example of the process described as software. A local or terminal computer may access 35 the remote computer and download a part or all of the software to run the program. Alternatively, the local computer may download pieces of the software as needed, or execute some software instructions at the local terminal and some at the remote computer (or computer network). Those skilled in the art will also realise that by utilising conventional techniques known to those skilled in the art that all, or a portion of the software instructions 5 may be carried out by a dedicated circuit, such as a DSP, programmable logic array, or the like.
[0078] It will be understood that the benefits and advantages described above may relate to one embodiment or may relate to several embodiments. The embodiments are not limited to those that solve any or all of the stated problems or those that have any or all of the stated 10 benefits and advantages. Variants should be considered to be included into the scope of the invention.
[0079] Any reference to 'an' item refers to one or more of those items. The term 'comprising' is used herein to mean including the method steps or elements identified, but that such steps or elements do not comprise an exclusive list and a method or apparatus may contain 15 additional steps or elements.
[0080] As used herein, the terms "component" and "system" are intended to encompass computer-readable data storage that is configured with computer-executable instructions that cause certain functionality to be performed when executed by a processor. The computerexecutable instructions may include a routine, a function, or the like. It is also to be 20 understood that a component or system may be localized on a single device or distributed across several devices.
[0081] Further, as used herein, the term "exemplary" is intended to mean "serving as an illustration or example of something".
[0082] Further, to the extent that the term "includes" is used in either the detailed description 25 or the claims, such term is intended to be inclusive in a manner similar to the term "comprising" as "comprising" is interpreted when employed as a transitional word in a claim.
[0083] The figures illustrate exemplary methods. While the methods are shown and described as being a series of acts that are performed in a particular sequence, it is to be understood and appreciated that the methods are not limited by the order of the sequence. 30 For example, some acts can occur in a different order than what is described herein. In addition, an act can occur concurrently with another act. Further, in some instances, not all acts may be required to implement a method described herein. 31 10 24
[0084] Moreover, the acts described herein may comprise computer-executable instructions that can be implemented by one or more processors and / or stored on a computer-readable medium or media. The computer-executable instructions can include routines, sub-routines, programs, threads of execution, and / or the like. Still further, results of acts of the methods can 5 be stored in a computer-readable medium, displayed on a display device, and / or the like.
[0085] The order of the steps of the methods described herein is exemplary, but the steps may be carried out in any suitable order, or simultaneously where appropriate. Additionally, steps may be added or substituted in, or individual steps may be deleted from any of the methods without departing from the scope of the subject matter described herein. Aspects of 10 any of the examples described above may be combined with aspects of any of the other examples described to form further examples without losing the effect sought.
[0086] It will be understood that the above description of a preferred embodiment is given by way of example only and that various modifications may be made by those skilled in the art. What has been described above includes examples of one or more embodiments. It is, of 15 course, not possible to describe every conceivable modification and alteration of the above devices or methods for purposes of describing the aforementioned aspects, but one of ordinary skill in the art can recognize that many further modifications and permutations of various aspects are possible. Accordingly, the described aspects are intended to embrace all such alterations, modifications, and variations that fall within the scope of the appended 20 claims.
Claims
15 10251. A network device comprising a first profile and a second profile provided by an operating system of the network device, wherein each profile is configured to run locally on the network device, wherein:5 the first profile comprises:a first virtual private network, VPN, client configured to encrypt data generated by the first profile to generate one-time encrypted data; and a proxy client configured to send the one-time encrypted data to the second profile;10 the second profile comprises:a proxy server configured to receive the one-time encrypted data from the proxy client; anda second VPN client configured to encrypt the one-time encrypted data received by the proxy server to generate twice encrypted data.
152. A network device according to claim 1, wherein the first profile further comprises a user application for generating application data and the first VPN client is configured to encrypt the application data generated by the user application to generate the one-time encrypted data.
203. A network device according to any preceding claim, wherein:the first profile further comprises a key provider configured to provide a key for encrypting data generated by the first profile; and25the first VPN client is configured to encrypt the data generated by the first profile with the key provided by the key provider.
4. A network device according to any preceding claim, wherein the second VPN client is30 further configured to send the twice encrypted data to a public network.
5. A network device according to any preceding claim, wherein encrypting the one-time encrypted data received by the proxy server comprises encrypting an internet protocol, IP, address of the first VPN client.
6. A system comprising a first network device according to any preceding claim, wherein the system further comprises a first VPN server and a second VPN server, wherein:the first VPN server is suitable for:15 1025decrypting the twice encrypted data to generate the one-time encrypted data; andsending the one-time encrypted data to the second VPN server; and the second VPN server is suitable for decrypting the one-time encrypted data5 received from the first VPN server to obtain the data generated by the first profile.
7. A system according to claim 6, wherein at least one of the first VPN server and second VPN server are within a secured network boundary.10 8. A system according to claims 6-7, wherein the second VPN server is further suitable forsending the data to another network device or another application.
9. A computer-implemented method for using a network device comprising a first profile and a second profile provided by an operating system of the network device, wherein each15 profile is configured to run locally on the network device, the method comprising: encrypting, by a first VPN client of the first profile, data generated by the first profile to generate one-time encrypted data;sending, by a proxy client of the first profile, the one-time encrypted data to the second profile;20 receiving, by a proxy server of the second profile, the one-time encrypted data fromthe proxy client; andencrypting, by a second VPN client of the second profile, the one-time encrypted data received by the proxy server to generate twice encrypted data.25 10. A computer-implemented method for configuring a network device, the methodcomprising:establishing a first profile and a second profile provided by an operating system of the network device, wherein each profile is configured to run locally on the network device;30 configuring a VPN client on the second profile, hereinafter referred to as a secondVPN client;establishing a proxy server on the second profile;establishing a proxy client on the first profile;connecting the proxy server on the second profile to the proxy client on the first35 profile;establishing a VPN client on the first profile, hereinafter referred to as a first VPN client, to encrypt data generated by the first profile to generate one-time encrypted data.
11. An apparatus comprising a processor unit, a memory unit and a communication interface, the processor unit connected to the memory unit and the communication unit, wherein the apparatus is configured to implement the computer-implemented method according to5 any of claims 9 to 10.
12. A computer-readable medium comprising code or computer instructions stored thereon, which when executed by a processor unit, causes the processor unit to perform the computer-implemented method according to any one of claims 9 to 10.15 1025