Firmware Network Adapter Emulation for Secure VPN Connections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current VPN client software is vulnerable to attacks that compromise network security, as it may be open to reverse engineering and extraction of secrets, lacking robust protection mechanisms.

Innovation Solution

A secure VPN connection is established using a combination of hardware and Firmware components on the client's platform, where the Firmware dynamically emulates a network adapter at a bus interface port, embedding network secrets and authentication components to avoid intrusion, and operates independently of the OS software or driver.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If VPN client software is implemented using standard OS-dependent software or application, then ease of operation and compatibility are improved, but security and resistance to reverse engineering deteriorate

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the software-based VPN client with a hardware-based VPN adapter that includes a secure element. This substitution moves the VPN functionality from the software layer to the hardware layer, making it resistant to reverse engineering while maintaining operational ease through automatic connection establishment.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a secure element as an intermediary component within the VPN adapter. This secure element acts as a mediator that stores authentication credentials and manages security functions, separating the security-critical operations from the main system and protecting them from software-based attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If VPN client software is implemented using standard OS-dependent software or application, then adaptability to different platforms is improved, but vulnerability to attacks and reverse engineering increases

Engineering Contradiction:
ImproveadaptabilityVSAvoidvulnerability to attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the software-based VPN client with a hardware-based VPN adapter that includes a secure element. This substitution moves the VPN functionality from the software layer to the hardware layer, making it resistant to reverse engineering while maintaining operational ease through automatic connection establishment.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent segments the VPN system into distinct components: the VPN adapter hardware, the secure element, and the software interface. This segmentation isolates the security-critical functions in the hardware layer, protecting them from software-based attacks while maintaining platform adaptability through standard interfaces.

Inventive Principle:
Principle #1Segmentation

3Ease of manufacture

If network secrets and authentication components are stored in OS software or drivers, then ease of deployment is improved, but security against intrusion and malicious attacks deteriorates

Engineering Contradiction:
Improveease of deploymentVSAvoidsecurity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent introduces a secure element as an intermediary component within the VPN adapter. This secure element acts as a mediator that stores authentication credentials and manages security functions, separating the security-critical operations from the main system and protecting them from software-based attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the security-critical functions and credentials from the software layer and places them in a dedicated hardware secure element. This extraction removes the vulnerability of storing secrets in software while maintaining ease of deployment through automated provisioning mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS7784095B2Virtual private network using dynamic physical adapter emulation
Publication Date: 2010.08.24 INTEL CORP
  • US7784095B2 patent drawing
  • US7784095B2 patent drawing
  • US7784095B2 patent drawing

AI summary

An embodiment of the present invention is a technique to provide secure Virtual Private Network (VPN) connection. A VPN connection is established to a remote gateway via a network adapter using a Firmware on a platform. An event is generated to notify an operating system (OS) network driver through a bus interface port. A request from the OS network driver is responded to provide network information.