Encrypted Remote Work Media Image for Secure Terminal Boot

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote work technologies fail to ensure the security of terminals used for remote work, as they lack effective encryption and user authentication, leading to risks of information leakage and malware threats.

Innovation Solution

A method and apparatus that create a secure remote work environment by encrypting media images with user-specific information, ensuring only authorized access, and configuring the terminal to boot securely, using a VPN certificate and encrypted OS components, while preventing access to unauthorized networks and deleting temporary files.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a Live CD with open OS is used for remote work, then the terminal can be protected from malware threats, but data stored in the medium is not encrypted and may be leaked if the medium is lost

Engineering Contradiction:
Improvemalware protectionVSAvoiddata leakage
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent changes the encryption state parameter of the media image from unencrypted to encrypted. The system encrypts the media image containing the OS and software before providing it to the user, so that even if the medium is lost, the data cannot be accessed without the decryption key. This resolves the contradiction by maintaining malware protection while adding encryption to prevent data leakage.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If VPN encryption is implemented at the network level, then data transmission security is improved, but the security of the terminal itself remains vulnerable to malware and unauthorized access

Engineering Contradiction:
Improvenetwork securityVSAvoidterminal vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the security protection into multiple layers: (1) media image encryption to protect the terminal from malware, (2) VPN encryption to protect network transmission, and (3) runtime security controls. By combining these segmented security measures, the system achieves both network security and terminal security, resolving the contradiction between the two.

Inventive Principle:
Principle #1Segmentation

3Reliability

If a private terminal is recommended for remote work, then security is improved compared to public terminals, but the terminal can still be compromised by malware and cannot guarantee information security

Engineering Contradiction:
Improveterminal securityVSAvoidinformation leakage
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies preliminary action by encrypting the media image before it is used in the terminal. The encryption is performed in advance during media image creation, and the encrypted image is then provided to the user. This preliminary encryption ensures that even if the terminal is compromised or the medium is lost, the information cannot be leaked without the decryption key, thus preventing information leakage while maintaining terminal security.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If network encryption is used for remote work, then data transmission is protected, but the complexity of the security system increases

Engineering Contradiction:
Improvedata transmission securityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security functions into an integrated system: media image encryption, VPN network encryption, and runtime security controls are combined into a unified remote work security solution. The encryption key management and security policies are integrated, reducing the operational complexity despite the enhanced security features. This merging approach maintains data transmission security while managing system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11784978B2Method for establishing remote work environment to ensure security of remote work user terminal and apparatus using the same
Publication Date: 2023.10.10 ELECTRONICS & TELECOMM RES INST
  • US11784978B2 patent drawing
  • US11784978B2 patent drawing
  • US11784978B2 patent drawing

AI summary

Disclosed herein are a method for establishing a remote work environment for ensuring the security of a user terminal for remote work and an apparatus using the method. The method, performed by the apparatus, includes acquiring media image creation information from a user; creating a certificate for VPN access based on the media image creation information and creating a media image using the media image creation information and the certificate for VPN access; and providing the media image to the user such that the user is able to create a medium for remote work. The user terminal for remote work is booted through the medium for remote work, thereby configuring a runtime environment for remote work in which security is ensured.