Network Portal Runtime Environment for Secure Internet Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing trend of outsourcing software functions to the internet, particularly through cloud computing and software-as-a-service, has heightened the need for robust security mechanisms to protect users, as existing security measures like firewalls and virus scanners are insufficient against growing fraud attempts, leaving users uncertain about the security of their online activities.

Innovation Solution

A network portal provides a secure runtime environment, akin to a virtual machine, accessible via an interface that shields users from direct internet access, utilizing a modular structure with a login module and virtualization module, offering anonymization, content evaluation, and certificate validation, along with optional additional security features like virus scanners and user-configurable access controls, to ensure secure internet access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users access the Internet directly, then ease of operation is improved, but security protection deteriorates

Engineering Contradiction:
ImproveInternet access convenienceVSAvoidSecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a runtime environment as an intermediary between the user's terminal and the Internet. This virtual machine acts as a mediator that shields users from direct Internet exposure while maintaining access functionality. The runtime environment receives user requests, executes them in a controlled sandboxed setting, and returns results without allowing direct contact between the user's personal data and potentially malicious Internet content.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If software functions are outsourced to the Internet, then adaptability is improved, but security protection deteriorates

Engineering Contradiction:
ImproveSoftware function accessibilityVSAvoidSecurity protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the software execution environment from the user's local system by implementing a virtualized runtime environment. This segmentation allows software functions to be accessed from the Internet while isolating them from the user's personal data and system resources. The virtual machine creates distinct boundaries that enable versatile software access while maintaining security through environmental separation.

Inventive Principle:
Principle #1Segmentation

3Reliability

If firewalls and virus scanners are used, then security protection is improved, but ease of operation deteriorates

Engineering Contradiction:
ImproveSecurity protectionVSAvoidUser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary security actions by creating a secure runtime environment before any Internet access occurs. Instead of reacting to threats with firewalls and virus scanners that interrupt user operations, the system proactively establishes a protected execution context in advance. All Internet access and software execution happen within this pre-configured secure environment, eliminating the need for interruptive security checks during user operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2487857B1Method for providing secure internet access
Publication Date: 2015.10.21 DEUTSCHE TELEKOM AG

AI summary

The method involves providing an interface to an application on a network portal through a terminal, and checking authorization of a user, where the user accesses via the terminal on the network portal. A runtime environment is provided for the authorized user. The runtime environment is assigned to the interface, where the authorized user is allowed to access information available in Internet. Validity of certificates is examined for the access, where the certificates are issued for the information retrievable in the network. An independent claim is also included for a network portal for providing secure internet access.