Portable Security Device for Secure Internet Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security solutions are inadequate for providing secure Internet access to user devices operating in unsecure network environments, such as public Wi-Fi, where they are vulnerable to eavesdropping and malware threats like browser hijacking and keylogging.

Innovation Solution

A portable security device establishes a first secure direct wireless connection with the user device and a second secure connection to a security server, functioning as an Internet gateway, using protocols like VPN to encrypt data and provide secure Internet access, while also managing user authentication and dynamically adjusting security settings based on network and device characteristics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If known security solutions (firewalls, antivirus, cloud detection) are used, then basic security protection is provided, but sufficient security in unsecure network environments is not achieved

Engineering Contradiction:
Improvesecurity protectionVSAvoideavesdropping and data theft
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a portable security device as an intermediary between the user device and the unsecure network. This device establishes secure connections (VPN tunnels) to act as a mediator that protects data from eavesdropping and malware while allowing network access. The security device intercepts and encrypts traffic before it reaches the unsecure network, resolving the contradiction by adding a protective layer without blocking necessary network functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If user devices connect directly to unsecure networks for Internet access, then network accessibility is achieved, but data transmitted is exposed to eavesdropping and malware

Engineering Contradiction:
Improvenetwork accessVSAvoidpersonal and confidential data
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The portable security device serves as an intermediary that maintains network accessibility while protecting data. It establishes secure VPN connections that allow Internet access to continue functioning normally, but all data traffic is encrypted and routed through the security device, preventing exposure to eavesdropping and malware on unsecure networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security device performs preliminary security actions by establishing encrypted connections before data transmission occurs. It proactively creates secure tunnels and implements security measures in advance, preventing data exposure before eavesdropping or malware attacks can occur, thus protecting information while maintaining ease of network access.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If security connections are established through additional network modules and protocols, then secure Internet access is provided, but device complexity increases

Engineering Contradiction:
Improvesecure connectionVSAvoidnetwork connection structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security function into a separate portable security device that can be independently deployed. Instead of integrating complex security modules into every user device, the security functionality is segmented into a dedicated device that handles encryption, VPN connections, and security protocols, thereby providing secure connections without burdening the user devices with increased complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2575318B1Portable security device and methods for providing network security
Publication Date: 2017.03.01 AO KASPERSKY LAB
  • EP2575318B1 patent drawingFigure 1
  • EP2575318B1 patent drawingFigure 2
  • EP2575318B1 patent drawingFigure 3

AI summary

Disclosed herein are systems, methods and computer program products for providing secure Internet access to a user device in an unsecure network environment, such as a public wireless network. The system includes a portable security device configured to establishing a first secure direct wireless connection with the user device and a second secure network connection through the public wireless network to a security server, which provides Internet access. The security device provides Internet browser and e-mail application, which can be used instead of unsecure applications of the user device to access Web resources through the first and second secure network connections. In addition, the security device includes a secure keyboard, which can be used by the device user instead of the unsecure keyboard of the user device to enter user authentication data for accessing the desired Web resources.