Network Access Intermediary Using Image Projection for Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security measures are inadequate in preventing unauthorized access and data breaches, as they rely on identifying vulnerabilities beforehand and can only provide passive responses, failing to protect against undiscovered issues.
Innovation Solution
A method and device that process network resource access by generating a second access request and response in an image coding format, which is presented to the user as a projected image, making it difficult for attackers to analyze and exploit actual network resource information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network access requests are analyzed and filtered using traditional security methods, then identified vulnerabilities can be protected, but undiscovered vulnerabilities cannot be prevented and high protection cost is required
Solution Approach 1:
The patent introduces an image projection system as an intermediary between the user terminal and network resources. The projection engine converts actual network resource interfaces into projected images that are displayed to users, while the real network resources remain hidden. This intermediary layer prevents attackers from directly accessing and analyzing actual network resource information, thereby protecting against both known and unknown vulnerabilities without requiring complex vulnerability databases or high protection costs
Solution Approach 2:
The patent creates a visual copy (projected image) of the network resource interface that resembles the actual interface but contains no real sensitive information. The projection engine generates this copy by rendering the network resource's visual appearance without exposing the underlying data structure or functionality. Users interact with this safe copy instead of the real resource, preventing information leakage while maintaining usability
2Ease of operation
If network resource information is directly transmitted to user terminals, then users can access network resources, but attackers can capture and analyze the information
Solution Approach 1:
The projection engine acts as an intermediary that transforms network resource information into projected images before transmission to user terminals. These projected images maintain the visual and functional characteristics needed for user interaction, but the underlying actual network resource information remains hidden and inaccessible to attackers. The system transmits image data rather than raw network resource data, preventing information capture while preserving ease of operation
Solution Approach 2:
The patent changes the parameter of information representation from direct network resource data to projected image data. By transforming the form of transmitted information from structured network protocols and data to visual image representations, the system maintains usability for legitimate users while making the information useless for attackers who attempt to capture and analyze it. The projected images appear identical to users but contain no exploitable technical information
Data Source
AI summary
The invention relates to the technical field of network security, in particular to a method and device for processing network resource access, a server and a terminal. The purpose is to improve network security. The technical scheme is: receiving a first access request for a target network resource, generating a second access request corresponding to the first access request according to a preset corresponding relationship, and transmitting (directly or indirectly, the same below) to a target network resource server; receiving a first response returned by the target network resource server according to the second access request (directly or indirectly, the same below), and converting the first response to generate information in an image coding format as second response information content; generating a second response according to the second response information content as a response to the first access request, and transmitting (directly or indirectly) to a user terminal.


