Encrypted VPN Hotspot with Isolated Zones for Data Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtual private networks (VPNs) are vulnerable to data privacy breaches, as they often allow unauthorized access to sensitive data and metadata, requiring complex user configurations to mitigate risks such as tracking and advertising software accessing browsing history.

Innovation Solution

A system and method for establishing encrypted zones of control on computing devices, allowing users to define specific criteria for network interactions, creating isolated VPNs that prevent data sharing across zones, and enabling the extension of these encrypted VPNs to wireless hotspots for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If existing virtual private networks are used to extend private network through public network, then network connectivity is improved, but data privacy and security deteriorate due to vulnerabilities allowing unauthorized access to sensitive data and metadata

Engineering Contradiction:
Improvenetwork connectivityVSAvoiddata privacy breach
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the network communication into separate encrypted zones, where each zone isolates specific data traffic. This segmentation prevents unauthorized applications from accessing all network data, as each zone operates independently with its own encryption parameters, thus maintaining connectivity while protecting privacy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements different security and encryption properties for different zones of network traffic. Each zone can have customized encryption parameters and access controls tailored to specific data types or applications, allowing sensitive data to receive enhanced protection while less sensitive traffic maintains standard connectivity.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If applications are given access to data caches and memory for network communications, then communication functionality is improved, but unauthorized access to sensitive information increases

Engineering Contradiction:
Improvecommunication functionalityVSAvoidunauthorized data access
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent segments data caches and memory into zone-specific protected areas. Each encrypted zone has its own isolated data storage space, preventing applications authorized for one zone from accessing data in other zones. This maintains communication functionality within each zone while blocking unauthorized cross-zone access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces encrypted zones as intermediary layers between applications and data caches. These zones act as mediators that control and filter access requests, allowing legitimate communication operations while blocking unauthorized attempts to access sensitive information stored in data caches and memory.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If tracking techniques such as beacons are used for advertising purposes, then user experience personalization is improved, but privacy protection deteriorates due to browsing history exposure

Engineering Contradiction:
Improveadvertising personalizationVSAvoidbrowsing history privacy
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent segments browsing traffic into encrypted zones that prevent advertising software from accessing browsing history data. Tracking techniques like beacons operate only within their own isolated zones and cannot access or transmit information from other zones, thus allowing personalized advertising within constraints while protecting overall browsing privacy.

Inventive Principle:
Principle #1Segmentation

4Object-affected harmful factors

If complex functionality is disabled to prevent privacy breaches, then security is improved, but user expertise requirements and system complexity increase

Engineering Contradiction:
Improveprivacy protectionVSAvoidconfiguration complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements automated encrypted zone management that reduces the need for complex user configurations. The system automatically creates, manages, and configures encrypted zones based on data sensitivity and access requirements, eliminating the need for users to manually disable complex functionalities while maintaining strong privacy protection.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11165825B2System and method for creating encrypted virtual private network hotspot
Publication Date: 2021.11.02 GEN DIGITAL INC
  • US11165825B2 patent drawing
  • US11165825B2 patent drawing
  • US11165825B2 patent drawing

AI summary

System and method for extending zones of control through a hotspot for communications to and from computing devices based on specific criteria corresponding to zones of control. An encrypted virtual private network (VPN) for a browsing session may be established at a first computing device and remote server computers matching the parameters of the established zone. Then, a user of the first computing device may further establish a wireless hotspot network suited to allow additional remote computing devices to piggy-back on the one or more established encrypted virtual private networks. Thus, other connected devices using the hotspot connection to reach a broader computer network (e.g., the Internet) are then also taking advantage of the encrypted VPN being provided by the host of the hotspot. Each connected computing device may then also have various communications isolated through zonal control from the hotspot device.