Portable Storage Device Secure Remote Connection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face security risks when accessing online services over untrusted networks, such as public wireless access points, as their data can be intercepted by malicious users, and existing solutions like VPNs require installation on the remote device and connect to a single network point.

Innovation Solution

A method and system that allow users to create an ad hoc VPN using a portable storage device, generating shared encryption keys between a trusted computing device and a portable storage device, enabling secure connections over untrusted networks without requiring a VPN client on the remote device, and allowing connections to multiple trusted computers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a VPN client is installed on the remote device to create a secure connection, then data security is improved, but device complexity and installation requirements increase

Engineering Contradiction:
Improvedata securityVSAvoidVPN client installation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the VPN client functionality from the remote device and relocates it to the portable storage device. The portable storage device contains the VPN client software that can be inserted into different computers to establish secure connections, eliminating the need to install VPN clients on each remote device while maintaining data security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The portable storage device acts as an intermediary between the user's trusted computer and the untrusted network. It contains the necessary VPN client software and encryption keys to create a secure tunnel, mediating the connection without requiring modification of the remote computer's operating system or installation of specialized software.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a VPN connects to a single network point, then connection security is improved, but adaptability to multiple trusted computers decreases

Engineering Contradiction:
Improveconnection securityVSAvoidconnection to multiple trusted computers
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The portable storage device is designed with universal functionality to work with multiple different trusted computers. It contains a database of trusted computer identifiers and can establish secure VPN connections to any of these computers, providing adaptability across different devices while maintaining the security benefits of a dedicated VPN connection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If data is sent over an untrusted network, then accessibility to online services is improved, but data security deteriorates due to potential interception

Engineering Contradiction:
Improveaccess to online servicesVSAvoiddata interception
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The portable storage device serves as an intermediary that establishes an encrypted tunnel between the user's computer and the destination server. All data traffic passes through this secure tunnel, which is protected by encryption keys stored in the portable device, preventing interception while allowing access to online services over untrusted networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system uses temporary encryption keys and one-time passwords that are generated and exchanged during the VPN connection setup. These cryptographic credentials are discarded after use, providing secure temporary protection for data transmission without requiring long-term exposure of security credentials.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentEP2433388B1Method and system for a secure remote connection using a portable storage device
Publication Date: 2017.03.29 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP2433388B1 patent drawingFigure 1
  • EP2433388B1 patent drawingFigure 2
  • EP2433388B1 patent drawingFigure 3

AI summary

As provided herein, when using an untrusted network connection, a secure online environment can be created for a remote machine by connecting to a trusted computer with a trusted network connection. A proxy server is installed on a first computing device and shared encryption keys are generated for the first device and a portable storage device. A connection is initiated between a second computing device (e.g., remote device), connected to an untrusted network, and the first computing device, comprising initiating a proxy server protocol from the portable storage device (e.g., attached to the second device), using the second computing device. A secure connection between the first and second devices is created using the encryption keys.