Mobile Device Container VPN Isolation via Cryptographic Token

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Establishing a secure connection between a mobile device container and multiple virtual private networks (VPNs) is challenging due to the need for strict isolation and authentication, while ensuring that third parties cannot unauthorizedly access or interfere with the communication within the connection.

Innovation Solution

A system comprising a mobile device container, multiple VPNs, and a cryptographic token that provides VPN profiles through a communication link, allowing the mobile device container to access and store VPN profiles securely, using cryptographic processes and authentication mechanisms to establish a secure connection, even across multiple VPN hops.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If strict isolation is implemented between mobile device container and other portions of the mobile device, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The mobile device is divided into isolated containers, with each container having its own cryptographic token for VPN profile storage. This segmentation allows strict isolation between different portions of the mobile device while maintaining manageable complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A communication link acts as an intermediary between the mobile device container and the cryptographic token, enabling secure interaction without direct access. This mediator maintains security isolation while facilitating necessary data exchange for VPN profile access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic token is used to store VPN profiles, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The cryptographic token autonomously manages VPN profile storage and retrieval without requiring manual intervention. The token automatically provides VPN profiles to authorized containers through the communication link, maintaining security while simplifying user operation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The communication link serves as an automated intermediary that handles the complex authentication and data exchange between the container and cryptographic token, shielding the user from operational complexity while maintaining strong security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple VPN connections are established through the container, then adaptability is improved, but reliability deteriorates due to potential unauthorized access

Engineering Contradiction:
ImproveadaptabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

Each VPN connection is associated with its own isolated container and cryptographic token, creating independent security zones. This segmentation allows multiple VPN connections with different security requirements while preventing unauthorized access between containers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each container-cryptographic token pair has customized security properties tailored to its specific VPN connection requirements. This local quality approach allows different security configurations for different VPNs while maintaining overall system security.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11838272B2VPN establishment
Publication Date: 2023.12.05 MATERNA VIRTUAL SOLUTION GMBH
  • US11838272B2 patent drawing
  • US11838272B2 patent drawing
  • US11838272B2 patent drawing

AI summary

The present invention relates to a system for establishing a secure connection between a mobile device container and a number of virtual private networks.