Mobile Device Resource Request Encryption via Proxy Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices face security risks when transmitting resource requests and responses, particularly for enterprise applications, due to the lack of strong security protection in system processes handling these messages, and the exposure of target addresses in resource requests can lead to malicious attacks.

Innovation Solution

Implementing application-specific encryption credentials and a transmission path identifier to encrypt resource requests and responses, using a proxy server to mask the application server address, and employing an encryption server to decrypt and forward requests and encrypt responses, ensuring secure communication and protecting sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If resource requests and responses are transmitted without encryption, then the system process can efficiently handle messages for multiple applications, but security protection is insufficient and target addresses are exposed to malicious attacks

Engineering Contradiction:
Improvesecurity protectionVSAvoidcommunication security mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an encryption server as an intermediary component between the system process and application servers. The system process sends encrypted resource requests to the encryption server, which decrypts them, processes the requests, and returns encrypted responses. This intermediary mechanism provides strong security protection without requiring the system process to directly implement complex encryption logic, thus resolving the contradiction between security and complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary encryption of resource requests before they are sent to the system process. The application encrypts its resource requests using encryption credentials obtained from the encryption server, and the system process simply forwards these pre-encrypted requests. This preliminary action ensures security is established before the message enters the system process, maintaining both security and efficiency.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If application-specific encryption credentials are implemented, then security of resource transmissions is enhanced, but the complexity of the communication protocol increases

Engineering Contradiction:
Improvesecurity of resource transmissionsVSAvoidcommunication protocol
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal encryption server that serves multiple applications with different security requirements through a single standardized interface. The encryption server handles key generation, credential distribution, and decryption for all applications, providing application-specific security through a universal mechanism. This reduces protocol complexity by consolidating encryption functions into a single multi-functional component rather than requiring separate encryption logic for each application.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If the application server address is exposed in resource requests, then the system process can route requests correctly, but the address becomes vulnerable to malicious attacks

Engineering Contradiction:
Improverequest routingVSAvoidmalicious attacks on target address
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The encryption server acts as an intermediary that receives encrypted resource requests containing application server addresses, decrypts them to extract routing information, processes the requests, and returns encrypted responses. This intermediary approach allows the address to be exposed only to the trusted encryption server for routing purposes, while keeping it protected from other system processes and external attackers, thus resolving the contradiction between routing capability and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3439266B1Processing resource requests on a mobile device
Publication Date: 2020.11.18 BLACKBERRY LTD
  • EP3439266B1 patent drawingFigure 1~2
  • EP3439266B1 patent drawingFigure 3
  • EP3439266B1 patent drawingFigure 4

AI summary

Systems, methods, and software can be used to process a resource request. In some aspects, a method, comprising: transmitting, from a mobile device, an encrypted request to a proxy server, wherein the encrypted request comprises a Hypertext Transfer Protocol (HTTP) request, the HTTP request is addressed to an application server that provides service to an application on the mobile device, and the encrypted request is encrypted using an application-specific credential that is associated with the application; and receiving, at the mobile device, an encrypted response in response to the encrypted request, wherein the encrypted response comprises an HTTP response generated by the application server.