Multi-wrapped VPN for Android Without Root

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Android-based devices have limited virtual private network (VPN) capabilities, requiring elevated permissions for VPN installation and operation, which restricts the use of secure data transmission solutions.

Innovation Solution

A multi-wrapped VPN system is implemented on communication devices, comprising a software stack with application-layer and link-layer VPN software, which encrypts and decrypts data without needing root permissions, enabling secure data transmission across public or private networks using existing devices and software.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional VPN software is installed on Android-based devices, then data transmission security is improved, but device complexity and permission requirements increase

Engineering Contradiction:
Improvedata transmission securityVSAvoidpermission requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a multi-layered VPN architecture where application-layer VPN software is nested within link-layer VPN software. The application-layer VPN (first VPN) encrypts data at the application level, then the link-layer VPN (second VPN) encapsulates and encrypts this already-encrypted data at the network link level. This nested structure allows each layer to provide security without requiring root permissions, as the combined layers achieve security that would otherwise require elevated privileges.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent divides the VPN functionality into two separate software components: application-layer VPN software and link-layer VPN software. Each component performs a specific encryption function at its respective layer in the network stack. This segmentation allows the system to achieve comprehensive security without requiring a single complex VPN solution that would need root permissions, as each simpler component can operate within standard permission constraints.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multi-wrapped VPN is implemented, then data protection is improved, but ease of operation deteriorates due to complex configuration

Engineering Contradiction:
Improvedata protectionVSAvoidconfiguration simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines multiple VPN encryption operations into a unified multi-wrapped VPN system where the application-layer VPN and link-layer VPN work together seamlessly. The configuration process merges the setup of both VPN layers into a single integrated system that automatically handles the complex interactions between layers, presenting a simplified user interface while maintaining multi-layer security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an intermediary configuration mechanism that manages the complex multi-layer VPN setup process. This intermediary layer handles the coordination between application-layer and link-layer VPN configurations, automatically managing the intricate details of multi-wrapped encryption while presenting a simplified interface to users, thus bridging the gap between complex security requirements and ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If root permissions are required for VPN operation, then VPN capability is improved, but adaptability deteriorates due to device compatibility issues

Engineering Contradiction:
ImproveVPN capabilityVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a nested VPN architecture where application-layer VPN software is embedded within link-layer VPN software. This nesting allows the system to achieve strong VPN capabilities through layered encryption without requiring root permissions at any single layer. The outer link-layer VPN provides the necessary network-level protection while the inner application-layer VPN adds application-specific security, and this nested structure can operate within standard Android permission constraints across different devices.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent creates a universal multi-wrapped VPN solution that functions across diverse Android devices without requiring root access. The application-layer VPN and link-layer VPN are designed to work together in a multi-functional system that adapts to different device configurations and Android versions. This universal approach allows the same VPN architecture to provide secure data transmission across various devices with different permission models and system configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9219709B2Multi-wrapped virtual private network
Publication Date: 2015.12.22 SAIFE INC
  • US9219709B2 patent drawing
  • US9219709B2 patent drawing
  • US9219709B2 patent drawing

AI summary

The invention includes a system for transmitting multi-wrapped VPN enabled-data across a communication network from a device to another destination device within a remote protected network. The device comprises a software stack, hardware layer, application-layer VPN software, link-layer VPN software, and user-based application software. Next, the device is coupled to a communication network. Next, the system includes a link-layer VPN aggregator and an application-layer VPN aggregator. Finally, the system includes a protected network that includes the destination device. The invention includes embodiments for configuring a device to transmit multi-wrapped VPN enabled-data and processes for transmitting multi-wrapped VPN enabled-data across a communication network from a device to another destination device within a remote protected network. Finally, the invention includes inverse processes so the destination device can transmit data back through the communication network and to the device.