Mobile Device Security Module for Secure Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Commercially available off-the-shelf mobile devices lack security architecture to protect proprietary data, making it difficult for them to access secure networks, particularly for soldiers in the field who need secure communication.
Innovation Solution
A system that allows non-secure mobile devices to access secure networks by downloading and activating mobile device security software, which includes encryption and decryption capabilities, and using a mobile device identifier to establish a secure connection through cellular or Wi-Fi networks, along with biometric and location validation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If commercially available off-the-shelf mobile devices are used, then ease of operation and device availability are improved, but security capability and reliability are worsened
Solution Approach 1:
The system segments security functionality from the mobile device hardware by introducing separate security components (security module, security server, security database) that can be independently deployed and managed. This allows standard mobile devices to maintain their ease of use while security functions are handled by dedicated components.
Solution Approach 2:
The patent introduces intermediary components including a security module that acts as a bridge between the mobile device and secure network, and a security server that mediates authentication and data protection. These intermediaries enable standard devices to access secure networks without compromising security.
2Reliability
If security architecture is added to mobile devices, then security capability is improved, but device complexity is worsened
Solution Approach 1:
The patent extracts complex security architecture from the mobile device itself and places it in separate components (security module, security server). This extraction allows mobile devices to remain simple while security functionality is distributed to specialized components that handle authentication, encryption, and security management.
Solution Approach 2:
The security module and security server are designed as universal components that can serve multiple mobile devices and handle various security functions (authentication, encryption, authorization). This multi-functionality reduces the need for device-specific security implementations, thereby reducing overall complexity.
3Reliability
If secure connection establishment procedures are implemented, then data protection is improved, but communication speed is worsened
Solution Approach 1:
The patent implements preliminary authentication and security setup procedures (including biometric authentication, device identification verification, and security token exchange) before actual data communication begins. This preliminary action establishes secure channels in advance, allowing subsequent data transmission to proceed efficiently with reduced overhead.
Data Source
Figure 1
Figure 2
Figure 3A~3B
AI summary
A system, method, and apparatus for establishing communications with a secure network (320) using a non-secure mobile device (105, 310) operating in a non-secure network are disclosed herein. The disclosed method involves communicating a mobile device identifier to the secure network (320). In one or more embodiments, the mobile device identifier is an Internet protocol (IP) address and/or a unique identification (ID) code. The method further involves verifying and/or validating, with a mobile device manager (130, 380) in the secure network (320), the mobile device identifier. Also, the method involves establishing a secure connection (136, 137) between the mobile device (105, 310) and the secure network (320). In addition, the method involves receiving, with the mobile device (105, 310), encrypted secure data from the secure network (320), Further, the method involves decrypting, with the mobile device (105, 310), the received encrypted secure data using previously downloaded mobile device security software.