Mobile Internet Security via VPN Tunneling to Proxy Servers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Restricted mobile computing platforms hinder the effective installation and operation of traditional security software, limiting the ability to secure Internet access and protect against malicious threats.

Innovation Solution

Tunneling all Internet traffic from mobile devices through virtual private network connections to security proxies that filter, modify, and track communications, providing comprehensive security features while conforming to platform restrictions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security software is installed on mobile computing systems, then security monitoring and threat protection capabilities are improved, but platform restrictions prevent effective installation and operation of system-level security software

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidsoftware installation flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a security gateway server as an intermediary between the mobile computing system and the Internet. The gateway server runs security monitoring software that filters and monitors Internet traffic, providing security protection without requiring system-level software installation on the restricted mobile platform. This mediator approach allows security functionality to be implemented where it cannot directly run.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent shifts the security implementation from the mobile device dimension to the network dimension by establishing a virtual private network connection through a security gateway server. Instead of installing security software on the mobile platform (device dimension), the solution moves security monitoring to the network gateway dimension, bypassing platform restrictions.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If system-level security software is installed to monitor Internet traffic, then threat detection and blocking capabilities are improved, but restricted mobile platforms prevent such software from operating effectively

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsoftware deployment ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security gateway server acts as an intermediary that performs threat detection and monitoring functions. Instead of deploying system-level security software directly on the restricted mobile platform (which would be difficult to operate), the gateway server handles all security monitoring operations, making deployment simple while maintaining effective threat detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If virtual private network tunneling is implemented through security proxies, then comprehensive Internet security for all applications is achieved, but network traffic must be routed through external servers

Engineering Contradiction:
ImproveInternet security coverageVSAvoidnetwork configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security gateway server provides multiple functions including VPN tunneling, traffic filtering, security monitoring, and threat blocking through a single unified system. This multi-functional approach achieves comprehensive Internet security coverage for all applications while managing network complexity centrally at the gateway rather than分散ly at each device.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9021578B1Systems and methods for securing internet access on restricted mobile platforms
Publication Date: 2015.04.28 CA TECH INC
  • US9021578B1 patent drawing
  • US9021578B1 patent drawing
  • US9021578B1 patent drawing

AI summary

A computer-implemented method for securing Internet access on restricted mobile platforms may include identifying an attempt by a mobile computing system to establish a virtual private network connection with a security server and, in response to identifying the attempt, (1) assigning an Internet Protocol address to the mobile computing system and (2) identifying a security filter customized to filter communications for an account associated with the mobile computing system. The method may also include (1) receiving, via the virtual private network connection, a request for an Internet resource and (2) providing, via the virtual private network connection, a response to the request to the mobile computing system based at least in part on the security filter. Various other methods, systems, and computer-readable media are also disclosed.