Establishing a secure network connection with an anchor device
By integrating a network module in an anchor device to control and protect the network connection, the method enhances security beyond existing USB boot stick limitations, addressing vulnerabilities from user-controlled terminal devices and ensuring a secure network connection.
Patent Information
- Application Number
- PCT/EP2025/065878
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-28
- Filing Date
- 2025-06-06
- Publication Date
- 2026-01-02
AI Technical Summary
Existing secure network connection methods using USB boot sticks are limited to security classifications VS-NfD (Classified - For Official Use Only) or EU/NATO RESTRICTED, and terminal devices, often used in private premises, pose a weak point due to user-administrative rights, compromising network security.
Incorporating a network module in an anchor device that boots an operating system on the terminal device, positioning it between the terminal device and the network connection, ensuring the network module is controlled and protected, and establishing a secure connection via a VPN tunnel.
This approach significantly reduces security risks from terminal devices by controlling and protecting the network module, eliminating vulnerabilities and ensuring a secure connection to internal networks.
Smart Images

Figure EP2025065878_02012026_PF_FP_ABST
Abstract
Description
[0001] Establishing a secure network connection with an anchor device
[0002] Description:
[0003] The invention relates to a method for establishing a secure network connection, comprising an anchor device, an end device, and an internal network, wherein the end device is connected to the anchor device, and the anchor device provides an operating system for booting the end device. The invention further relates to a computer program for establishing a secure network connection, in particular for carrying out the method, furthermore to an anchor device for establishing a secure network connection, and also to the use of the computer program or the anchor device for establishing a secure network connection.
[0004] Such methods are known in practice, where USB boot sticks are used as mobile anchor devices and contain the operating system to be booted. Booting the operating system from the USB boot stick onto the end device means that all stored data on the end device is ignored by the booted operating system, and the end device is reduced to its peripheral elements (primarily the interfaces, in addition to input and output devices). This renders any malware installed on the end device inactive, as well as all other software programs on the end device. Furthermore, booting the operating system establishes a secure network connection, for example, using a VPN (Virtual Private Network), between the end device or a network module of the end device and the internal network. The order of the devices or connections in the direction of information flow is determined by the boot process.The chain of communication is therefore structured as follows: anchor device – terminal device – secure network connection – internal network. The terminal device can, for example, be located in a user's private office, such as that of an employee of a company or government agency, and may be a desktop PC or laptop. Using USB boot sticks, which are familiar from practical experience, the user can then access their own computer within the company or agency premises from their terminal device located in their home office and use the installed and adequately protected software programs there.
[0005] Bootable USB sticks, commonly used in practice, are available in various security levels. However, these USB bootable sticks are only designed for the security classifications VS-NfD (Classified - For Official Use Only) or EU / NATO RESTRICTED. The invention therefore aims to make the aforementioned method even more secure.
[0006] This problem is solved by a method for establishing a secure network connection, comprising an anchor device, wherein the anchor device is connectable to or is connected to an end device, wherein the anchor device provides an operating system for booting an end device, characterized in that the anchor device has a network module for establishing a network connection, wherein the anchor device (1) or the
[0007] Network module (6) with an internal network (3) via the
[0008] Network connection (8) is connectable or is connected.
[0009] The invention is based on the premise that the terminal device may be located, for example, in a user's private premises, and that the user, and often other users as well, particularly family members, possess administrative rights to the terminal device. For this reason, the company or authority has only limited means of controlling this terminal device. Thus, the terminal device represents a weak point in the communication chain, which also includes the terminal device's network module.
[0010] It was found that providing a network module in the anchor device—in addition to booting an operating system on the terminal device—leads to a significant elimination of the security risks originating from the terminal device. In this way, not only is the internal workings of the terminal device subject to the booted operating system, but the external interface or network module is also considerably easier to control and protect. As a result, the invention solves the aforementioned problem.
[0011] The term "between" preferably refers to the arrangement of an element between two other elements in the direction of information flow. Conveniently, the term "between" does not imply a geometric arrangement. An element between two other elements can be positioned directly or indirectly between them. In particular, "between" does not mean that the respective element must be directly adjacent to the other elements. Rather, further elements may lie between them.
[0012] The term "network connection" preferably refers to a connection between computers according to a communication protocol. The communication protocol is preferably assigned to layer 3 of the OSI reference model and is, in particular, part of the TCP / IP protocol suite. The term "anchor device" preferably refers to an electronic device or a device comprising an electronic component. The anchor device can be mobile or non-mobile and / or integrated. Mobile anchor devices can be, for example, a USB flash drive, a smartphone, a tablet, a smartwatch, or a laptop. Non-mobile anchor devices might be, for example, a desktop PC or a 19" rack. In particular, the comparison between the non-mobile 19" rack and the laptop shows that the difference between "mobile" and "non-mobile" lies primarily in whether the devices are designed for mobile use or not. Suitability for mobile use is preferably less important in this context.for wearable use. Integrated anchor devices can be retrofitted or factory-installed in a mobile or non-mobile device and may include, for example, an SSD (Solid State Drive). The anchor device ideally includes a processor and / or RAM and / or data storage.
[0013] Preferably, the anchor device comprises a housing. The housing advantageously encloses the network module and / or the data storage – at least partially and preferably completely. It is preferred that the operating system, computer program, or bootloader is stored on the data storage. The data storage can be partitioned or comprise several physically completely separate storage modules.
[0014] The term "terminal device" preferably refers to an electronic device or a device with an electronic component. The terminal device preferably includes input devices and / or output devices for use by a user. The terminal device advantageously includes a keyboard and / or a touchscreen and / or a display. The terminal device is advantageously designed for work, and in particular for office work. The terminal device is especially preferably a laptop or PC. The term "internal network" preferably refers to a component of a computer network or intranet of a company or public authority. The internal network is advantageously protected from an external network, such as the internet, by at least one monitoring device, in particular a gateway and / or a firewall.
[0015] The term "network module" preferably refers to an interface for wired or wireless communication with other devices or devices outside the anchor device. Advantageously, the network module includes a network card, especially for Ethernet, and / or an antenna, especially a WLAN antenna and / or a Bluetooth antenna and / or a cellular antenna. The network module may consist of hardware and / or software components.
[0016] According to a preferred embodiment, the operating system is stored on an encrypted data storage device—in particular, on an encrypted data storage device of the anchor device. This provides an additional, effective enhancement of the security function. The anchor device expediently comprises the data storage device with the operating system stored thereon. It is possible that the anchor device does not contain the operating system itself, and in particular that the operating system is made available to the terminal device via a network connection. It is highly preferred that the terminal device boots the—preferably freely selectable—operating system from the anchor device or the data storage device of the anchor device. This results in the most extensive elimination of potential threats originating from the terminal device, because, in particular, all storage contents of the terminal device, and thus also malware, are disregarded. It is especially preferred that the operating system is selected by a user or administrator.The user can select the operating system to boot. For example, the booted operating system might be Windows, MacOS, iOS, or Android. This allows for great flexibility in using the method according to the invention, enabling the user to work within their familiar environment. The user, administrator, or customer can advantageously make configuration decisions for the operating system to be booted.
[0017] According to a highly preferred embodiment, the network connection is established by the anchor device or the network module. Preferably, the network connection is arranged between the internal network and the terminal device, and more preferably between the internal network and the anchor device or the network module. It is highly advantageous for the anchor device to be located between the terminal device and the network connection. Advantageously, the network connection is arranged between the anchor device and the internal network. This arrangement of the network connection between the internal network and the anchor device ensures that the terminal device is not involved in establishing the network connection, so that, in particular, a network module of the terminal device is not used in establishing the network connection. This allows for the most comprehensive elimination of potential hazards originating from the terminal device.It is particularly preferred that the information flow follows the following chain: terminal device - anchor device - network connection - internal network. This chain is not necessarily exhaustive, so that further components and / or connections may be interposed.
[0018] According to a highly preferred embodiment, a guard device, particularly in the form of a firewall and / or gateway, is positioned between the network connection and the internal network. This increases the security of the internal network to be protected. The guard device can, for example, be or include a SINA box (SINA, Secure Inter-Network Architecture), which separates the internal network from the external network. The information flow may, in particular, follow the following sequence: end device - anchor device - network connection - guard device - internal network. A SINA box is an IPsec VPN gateway that securely connects protected or government-classified networks against attacks and manipulation. With SINA, different locations with networks requiring protection can be connected highly securely and cost-effectively via potentially insecure networks, such as the internet.
[0019] In computer science, a gateway is a component that establishes a connection between two systems. An IT system that does not directly know its communication partner uses its gateway. IPsec is an extension of the Internet Protocol (IP) that adds encryption and authentication mechanisms. This gives the Internet Protocol the ability to transport IP packets cryptographically securely over public and insecure networks. IPsec thus enables the secure transmission of information in IP-based data networks, ensuring in particular the confidentiality, integrity, and authenticity of the information transmitted using the IP protocol.
[0020] The Secure Inter-Network Architecture (SINA) is a product family developed by the German Federal Office for Information Security (BSI) in cooperation with secunet Security Networks AG for the transmission and processing of sensitive information in insecure networks. Communication between SINA systems is based on the security principle of a Virtual Private Network (VPN). All data traffic between locations, and even down to the individual workstation, is end-to-end cryptographically protected according to the IPSec standard. The SINA components themselves are secured by comprehensive mechanisms on the operating system platform (SINA-Linux).
[0021] SINA is designed and developed as a high-security solution. Therefore, its VPN functions are embedded in a specially minimized and hardened Linux operating system (SINA Linux) and enhanced with additional security features. The cryptographic methods comply with the current IPsec standard. SINA comprises a constantly growing family of modular components for securing a wide variety of application scenarios, such as connecting locations, using mobile workstations, or running work sessions with varying security requirements on a single computer.
[0022] Through the extensive use of Free / Libre Open Source Software (FLOSS) and numerous coordinated security mechanisms (including VPN-based network encryption (VPN - Virtual Private Network), local data encryption, operating system encapsulation, and interface control), flexible, scalable, and highly secure solutions are realized. (Sources, accessed on June 24, 2024:
[0023] The internal network can contain one or more PCs and / or one or more servers and / or one or more databases. For example, if a user accesses an assigned internal PC within the internal network from their terminal device, the information flow can proceed through the following chain of devices: terminal device - anchor device - network connection - sentencing device - internal PC (personal computer).
[0024] Preferably, the anchor device is a mobile device. This allows for greater practicality when establishing a secure network connection. For example, if the end device is also mobile, the user can establish a secure network connection even while traveling. Furthermore, the mobility of the mobile device allows for convenient handling, so that, for example, an administrator only needs to expend minimal logistical effort to equip a large number of employees with anchor devices. The mobility of the anchor device is also advantageous when handling an authentication system. If the anchor device is mobile, it can also be owned by the user or employee, so that existing electronic devices belonging to the user can be used as anchor devices for the process. This significantly reduces the hardware requirements.
[0025] It is highly desirable for the anchor device to have a display, ideally a smartphone, tablet, laptop, or smartwatch. Anchor devices with a display generally offer a wide range of functions. A touchscreen is advantageous, as it eliminates the need for a keyboard, allowing for a particularly compact and portable design.
[0026] Preferably, the anchor device comprises at least one authentication system, wherein the authentication system may include at least one biometric recognition device. This simplifies the authentication process for the user. The authentication system may include secret recognition and / or physical token recognition and / or a biometric recognition device. It is particularly preferred that the authentication system includes secret recognition, for example, the recognition of a character string and, in particular, the recognition of a PIN. This results in relatively secure authentication.
[0027] The biometric recognition device may include a camera and / or a microphone and / or a fingerprint scanner and / or an eye scanner. It is particularly preferred that the biometric recognition device includes facial recognition, fingerprint recognition, voice recognition and / or eye recognition.
[0028] It is advantageous for the operating system to boot or the network connection to be established only after the user has been identified by the authentication system via authentication. This authentication should preferably be at least two-factor or three-factor authentication.
[0029] According to one embodiment, the mobile anchoring device can be a USB flash drive (USB - Universal Serial Bus) and, in particular, can be designed without a biometric recognition device. The anchoring device—preferably mobile—can include a device for entering a PIN (PIN - Personal Identification Number)—in particular, a keypad—and / or a reader for reading a token stored on a memory element. The memory element can, for example, be a smart card. A USB flash drive generally refers to a compact electronic device that connects to another device, such as a PC (PC - Personal Computer), via the Universal Serial Bus. The USB connector and the housing are directly connected and form a single mechanical unit without a connecting cable. A USB flash drive is a compact, portable storage device for computers and the like.It is plugged into a free USB port or connected to a computer or similar device via a USB (Universal Serial Bus) interface and permanently stores data. USB flash drives are available with different storage capacities and using various USB standards. USB flash drive sizes are standardized in certain increments and cannot be customized. Examples of sizes are: 8 GB, 16 GB, 32 GB, 64 GB, 128 GB, 256 GB, and 1 TB. The most important components of a flash drive are the non-volatile flash memory, the memory controller, the USB connector, and the casing.
[0030] USB flash drives are ideal for flexible data exchange, even between different operating systems, i.e., for data transport. They can be loaded and ejected from a running system. A computer is a device (hardware) that, with the aid of logic circuits and corresponding programs (software), can perform calculations, process digital tasks, or control processes. Examples of computers include quantum computers, mainframes, personal computers, desktops, laptops, notebooks, smartphones, tablets, mobile devices, control units of technical devices or systems, control units of household appliances such as washing machines, or control units of vehicles, especially for autonomous driving.
[0031] It is advantageous for the network connection to be established—preferably via an external network—and to preferably include encryption, a tunnel, and, more preferably, a VPN tunnel. This further enhances the security of the network connection. The term "encrypted" preferably refers to the sharing of confidential information between a sender and a receiver, particularly between the user and the internal network. The term "tunnel" preferably refers to an inner communication protocol encapsulated within an outer communication protocol. For example, an OSI layer 2 communication protocol is encapsulated within data packets of a layer 3 communication protocol, with the data packets and the outer communication protocol being encrypted. The tunnel or VPN tunnel is expediently encrypted.In particular, the tunnel's external communication protocol is encrypted.
[0032] Preferably, the anchor device and the terminal device are connected by a cable, preferably a USB cable. This necessitates close proximity between the terminal device and the anchor device, requiring the user to be in possession (not necessarily the owner) of the anchor device and to exercise actual control over it. This effectively turns the anchor device into a token, thereby increasing the security of the authentication process. Examples of well-known USB standards include "USB 1.0 / 1.1" (transfer rate 12 Mbps), "USB 2.0" (transfer rate 480 Mbps), "USB 3.0" (also called Gen1) (transfer rate 5 Gbps), "USB 3.1" (also called Gen2) (transfer rate 10 Gbps), "USB 3.2" (also called Gen 2x2) (transfer rate 20 Gbps), and "USB 4.0" (also called Gen3x2) (transfer rate 40 Gbps). Another standard is "Thunderbolt 3" (transfer rate 40 Gbps).This device also uses USB Type-C connectors and sockets and is therefore compatible with all USB Type-C devices. For example, the suffixes "Type-A," "Type-B," "Type-C," "Micro," etc., describe the form factor of the connectors and sockets of USB interfaces. The term "USB" is not limited to the variants known at the time of this invention; rather, it also includes future USB variants and preferably comparable interfaces. According to a particularly preferred embodiment, a computer program is installed on the anchor device, wherein the computer program preferably initiates the booting of the operating system on the terminal device and, in particular, includes a bootloader. The computer program on the anchor device provides a certain degree of control over the anchor device and, through the booting process, also control over the terminal device. It is preferred that the anchor device, its data storage, or the computer program includes a bootloader.The computer program conveniently establishes the network connection via the network module.
[0033] The aforementioned problem is solved by a computer program for establishing a secure network connection, in particular for carrying out a method according to the invention, wherein the computer program is configured to be installed on an anchor device, to boot an operating system from the anchor device onto the terminal device, to control a network module of the anchor device, and to establish a network connection across an external network between the network module and an internal network, such that the anchor device is located between the terminal device and the network connection or the internal network. The expression "across an external network" refers in particular to a tunnel or a tunnel connection.
[0034] The aforementioned problem is solved by an anchor device for establishing a secure network connection, in particular for carrying out a process according to the invention, wherein the anchor device comprises a network module and a computer program, wherein the computer program or the anchor device is configured to boot an operating system on an end device and to establish a network connection across an external network between the network module and an internal network, so that the anchor device is located between the end device and the internal network.
[0035] The aforementioned problem is solved by using a computer program or an anchor device according to the invention for establishing a secure network connection, in particular for establishing a secure network connection according to a method according to the invention.
[0036] The aforementioned problem is solved by a system for establishing a secure network connection, in particular according to the method according to the invention, comprising an anchoring device and in particular an anchoring device according to the invention, wherein the anchoring device is connectable to or connected to an end device, wherein the anchoring device provides an operating system for booting for an end device - preferably freely selectable -, wherein the anchoring device has a network module for establishing a network connection, wherein the anchoring device or the network module is connectable to or is connected to an internal network via the network connection.
[0037] The invention is explained below with reference to an exemplary embodiment in a single figure. It shows
[0038] Figure 1 shows a block diagram of the inventive method and system for establishing a secure network connection.
[0039] Figure 1 schematically depicts an anchor device 1 according to the invention in the form of a smartphone. The anchor device 1 conventionally comprises a network module 6, which in this embodiment has a mobile communication interface and a WLAN interface, and may also include wired interfaces. The anchor device 1 preferably includes its own operating system, not shown in Figure 1, which may, for example, be an Android operating system.
[0040] Wireless Local Area Network (WLAN) refers to a local wireless network, usually referring to a standard from the IEEE 802.11 family. Technically, WLAN and Wi-Fi refer to two different things: WLAN refers to the wireless network itself, while Wi-Fi refers to certification by the Wi-Fi Alliance based on the IEEE 802.11 standard.
[0041] Furthermore, the anchor device 1 preferably includes a bootable operating system 4, which can be booted on a wide variety of end devices 2. The operating system 4 might, for example, be a Windows operating system and can be selected and configured entirely according to the user's or administrator's preference. The operating system inherent to the anchor device 1 should not be confused with the bootable operating system 4, both of which can be stored on a data storage device of the anchor device 1.
[0042] It is advantageous for the anchor device 1 to include a computer program 9. The computer program 9 preferably includes a bootloader with which the operating system 4 can be booted on a user's terminal device 2. Furthermore, the computer program 9 advantageously includes a program component that establishes a network connection 8 between the anchor device 1 and an internal network 3. It is possible for the anchor device 1 to make the bootable operating system 4 available to the terminal device 2 only after the network connection 8 has been established and via this network connection 8, so that the bootable operating system 4 does not need to be stored on a data storage device of the anchor device 1.
[0043] In this embodiment, the user may possess the anchor device 1 and the terminal device 2. The terminal device 2 is, for example, a desktop PC and may be located in the user's home office. The user in this embodiment is an employee of a security agency that maintains a large intranet. The internal network 3 is a component of this agency's intranet and may include one or more internal servers 10, one or more databases, and one, several, or many internal PCs 11. In this embodiment, one of the internal PCs 11 is a workstation assigned to the user.
[0044] The internal network 3 of this embodiment is preferably closed off or protected from the outside by a guard device 7. The guard device 7 can, in particular, comprise a firewall and / or a gateway. It is highly preferred that the network connection 8 is established between the anchor device 1 or its network module 6 on the one hand and the guard device 7 on the other.
[0045] A firewall is a security system that protects a network or an individual computer from unauthorized access via data connections from the outside, especially via the internet. More broadly, a firewall is also a component of a comprehensive security concept. Every firewall security system is based on a software component.
[0046] It is advantageous that the network connection 8 is configured as a tunnel. The tunnel nature of the network connection 8 is symbolically indicated in Figure 1, where the associated data packets of the network connection 8 have an inner communication protocol encapsulated within an outer communication protocol. It is expedient that the outer communication protocol includes encryption. Most preferably, the network connection 8 is a VPN tunnel, such that the network connection 8 runs through or over the external network 5.
[0047] In this embodiment, the user received the anchor device 1 from the administrator of the security agency that operates the internal network s. The administrator, in turn, preferably received the anchor device 1 directly from the system provider of the computer program 9, so that the anchor device 1 is guaranteed to be uncompromised.
[0048] If the user wishes to access the internal network 3, its services, or their assigned internal PC 11, the user first switches on the anchor device 1 (unless it was already operational) and is authenticated by the operating system of the anchor device 1. Alternatively or cumulatively, the user is authenticated by the computer program 9. Preferably, the computer program 9 or the anchor device 1 is configured such that the authentication steps of the operating system of the anchor device 1 and of the computer program 9 complement each other to form an authentication with at least two factors – preferably including at least one biometric factor.
[0049] Before, during, or after switching on the anchor device 1 or the computer program 9, the user of this embodiment connects the terminal device 2 to the anchor device 1. This is done, for example, via a USB4 connection cable. In a further step, the user can then start up the terminal device 2, whereby, due to the connected anchor device 1, the bootloader of the computer program 9 ensures that the operating system 4 on the terminal device 2 is booted—instead of the conventional operating system of the terminal device 2. The operating system booted in this way is subsequently designated by the reference symbol 4'.
[0050] The booted operating system 4' expediently takes over all resources, and in particular the processors, of the terminal device 2. Preferably, the booted operating system 4' can also take over free memory space on the terminal device 2, so that any memory content on the terminal device 2 is ignored by the booted operating system 4'. This renders all programs installed on the terminal device 2 ineffective, which applies in particular to any malware that may be installed. It is preferred that, due to the booted operating system 4', the terminal device 2 is essentially reduced to its processors, the booted operating system 4' along with the memory space it occupies, and the input and output devices of the terminal device 2.
[0051] Preferably after the booted operating system 4' has been provided – but alternatively also before or during this process – the anchor device 1 or the computer program 9 establishes the network connection 8 to the internal network 3 or the guard device 7 via the network module 6. Preferably, the anchor device 1 and the guard device 7 establish the network connection 8 in the form of an encrypted VPN tunnel. The user then has access to the services of the internal network 3 and, for example, of their assigned internal PC 11 via the end device 2.
[0052] Due to the use of the network module 6 of the anchor device 1, the network module of the terminal device 2 is not even used, thus circumventing this vulnerability of the terminal device 2. In this way, a very secure connection is created between the internal network 3 and the privately owned terminal device 2, which naturally represents a vulnerability in the network architecture of companies and public authorities. The invention has therefore solved the aforementioned problem in a very efficient and user-friendly manner.
Claims
Patent claims:
1. Method for establishing a secure network connection (8), comprising an anchor device (1), wherein the anchor device (1) is connectable to or is connected to an end device (2), wherein the anchor device (1) provides an operating system (4) for booting a / the end device (2), preferably freely selectable, characterized in that the anchor device (1) has a network module (6) for establishing a network connection (8), wherein the anchor device (1) or the network module (6) is connectable to or is connected to an internal network (3) via the network connection (8).
2. Method according to claim 1, wherein the operating system (4) is stored on an encrypted data storage device - in particular on an encrypted data storage device of the anchor device (1).
3. Method according to claim 1 or 2, wherein the network connection (8) is established by the anchor device (1), wherein the network connection (8) is preferably arranged between the internal network (3) and the terminal device (2) and further preferably between the internal network (3) and the anchor device (1).
4. Method according to any one of claims 1 to 3, wherein the anchor device (1) is a mobile device and preferably comprises a display - in particular a touchscreen.
5. Method according to any one of claims 1 to 4, wherein the anchor device (1) comprises at least one authentication system and preferably at least one biometric authentication system.
6. Method according to any one of claims 1 to 5, wherein the network connection (8) is established - preferably via an external network (5) - wherein the network connection (8) preferably has encryption, wherein the network connection (8) preferably comprises a tunnel and further preferably a VPN tunnel.
7. Method according to any one of claims 1 to 6, wherein the anchor device (1) and the terminal device (2) are connected by a connecting cable, the connecting cable preferably being a USB cable.
8. Method according to any one of claims 1 to 7, wherein a computer program (9) is installed on the anchor device, wherein the computer program (9) preferably causes the operating system (6) to boot on the terminal device (2) and in particular has a bootloader.
9. Computer program (9) for establishing a secure network connection (8), in particular for carrying out a method according to one of claims 1 to 8, wherein the computer program (9) is configured, - to be installed on an anchor device (1 ) - to boot an operating system (6) from the anchor device (1) to the terminal device (2), - to control a network module (6) of the anchor device (1), - to establish a network connection (8) across an external network (5) between the network module (6) and an internal network (3), so that the anchor device (1) is located between the terminal device (2) and the network connection (8) or the internal network (3).
10. Anchor device (1 ) for establishing a secure network connection (8), in particular for carrying out a method according to one of claims 1 to 8, wherein the anchor device (1 ) comprises a network module (6) and a computer program (9) - in particular a computer program according to claim 9 - wherein the computer program (9) or the anchor device (1 ) is configured, - to boot an operating system (4) on an end device (2) and - to establish a network connection (8) across an external network (5) between the network module (6) and an internal network (3), so that the anchor device (1) is located between the terminal device (2) and the network connection (8) or the internal network (3).
11. Use of a computer program (9) according to claim 9 or an anchor device (1 ) according to claim 10 for establishing a secure network connection (8), in particular for carrying out a method according to any one of claims 1 to 8.
12. System for establishing a secure network connection (8), in particular according to a method according to one of claims 1 to 8, comprising an anchoring device (1 ) and in particular an anchoring device (1 ) according to claim 10, wherein the anchoring device (1 ) is connectable to an end device (2) or is connected, wherein the anchor device (1) provides an operating system (4) for booting a terminal device (2) - preferably freely selectable - characterized in that the anchor device (1) has a network module (6) for establishing a network connection (8), wherein the anchor device (1) or the network module (6) can be connected to an internal network (3) via the network connection (8).
Citation Information
Patent Citations
Portable memory card for use with a data processing unit, especially a PC, so that it boots into a particular configuration, said card memory containing a boot image, an operating system and an application program
DE10319778A1
device for establishing a secure connection between a host computer and a network
DE202009010078U1
Portable virtual private network device
US20060036854A1
Method and apparatus of implementing a VPN tunnel
US20170366529A1