Mobile Device Resource Request Encryption via Proxy Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices face security risks when transmitting resource requests and responses, particularly for enterprise applications, due to the lack of strong security protection in system processes handling these messages, and the exposure of target addresses in resource requests can lead to malicious attacks.
Innovation Solution
Implementing application-specific encryption credentials and a transmission path identifier to encrypt resource requests and responses, using a proxy server to mask the application server address, and employing an encryption server to decrypt and forward requests and encrypt responses, ensuring secure communication and protecting sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If resource requests and responses are transmitted without encryption, then the system process can efficiently handle messages for multiple applications, but security protection is insufficient and target addresses are exposed to malicious attacks
Solution Approach 1:
The patent introduces an encryption server as an intermediary component between the system process and application servers. The system process sends encrypted resource requests to the encryption server, which decrypts them, processes the requests, and returns encrypted responses. This intermediary mechanism provides strong security protection without requiring the system process to directly implement complex encryption logic, thus resolving the contradiction between security and complexity.
Solution Approach 2:
The patent implements preliminary encryption of resource requests before they are sent to the system process. The application encrypts its resource requests using encryption credentials obtained from the encryption server, and the system process simply forwards these pre-encrypted requests. This preliminary action ensures security is established before the message enters the system process, maintaining both security and efficiency.
2Reliability
If application-specific encryption credentials are implemented, then security of resource transmissions is enhanced, but the complexity of the communication protocol increases
Solution Approach 1:
The patent creates a universal encryption server that serves multiple applications with different security requirements through a single standardized interface. The encryption server handles key generation, credential distribution, and decryption for all applications, providing application-specific security through a universal mechanism. This reduces protocol complexity by consolidating encryption functions into a single multi-functional component rather than requiring separate encryption logic for each application.
3Ease of operation
If the application server address is exposed in resource requests, then the system process can route requests correctly, but the address becomes vulnerable to malicious attacks
Solution Approach 1:
The encryption server acts as an intermediary that receives encrypted resource requests containing application server addresses, decrypts them to extract routing information, processes the requests, and returns encrypted responses. This intermediary approach allows the address to be exposed only to the trusted encryption server for routing purposes, while keeping it protected from other system processes and external attackers, thus resolving the contradiction between routing capability and security.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
Systems, methods, and software can be used to process a resource request. In some aspects, a method, comprising: transmitting, from a mobile device, an encrypted request to a proxy server, wherein the encrypted request comprises a Hypertext Transfer Protocol (HTTP) request, the HTTP request is addressed to an application server that provides service to an application on the mobile device, and the encrypted request is encrypted using an application-specific credential that is associated with the application; and receiving, at the mobile device, an encrypted response in response to the encrypted request, wherein the encrypted response comprises an HTTP response generated by the application server.