Local Proxy Server for Secure Mobile Data Flow Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies lack an effective method for securely managing and securing communications in intelligent mobile terminals, particularly after they are released to users, as there is no straightforward way to manage security across multiple terminals or fleets.
Innovation Solution
Implementing a local proxy server on the terminal, which processes data streams using a configuration memory, applying specific processing operations such as encryption and malicious code detection, and securing data flows between terminal components, with the option to store data securely using cryptographic tools, and managing these processes through a microcircuit card.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a terminal is released into the wild without centralized security management, then ease of operation is improved, but security reliability deteriorates as the terminal becomes vulnerable to user actions and external threats
Solution Approach 1:
The patent introduces a proxy server as an intermediary component that mediates between the terminal and external networks. This proxy server acts as a security gateway that filters and controls all data flows, allowing the terminal to remain easy to use while providing robust security through centralized management of security policies and real-time monitoring of communications.
2Reliability
If security management is implemented at each individual terminal, then security reliability is improved, but device complexity increases due to the need for separate security configurations
Solution Approach 1:
The patent implements a universal security management system where a single proxy server provides security services to multiple terminals. The proxy server handles security configurations, policy enforcement, and threat detection for all connected terminals, eliminating the need for separate security implementations at each device and reducing overall system complexity while maintaining high security reliability.
3Reliability
If data flows are secured through encryption and analysis, then security reliability is improved, but use of energy increases due to processing requirements
Solution Approach 1:
The patent extracts the computationally intensive security processing functions from the terminal and relocates them to the proxy server. The terminal only needs to establish encrypted connections and send data through the proxy, while the proxy server performs the heavy lifting of traffic analysis, pattern recognition, and threat detection. This extraction significantly reduces the energy consumption at the terminal while maintaining comprehensive security.
4Reliability
If all data flows are monitored and processed for security, then security reliability is improved, but productivity decreases due to processing overhead
Solution Approach 1:
The patent implements partial monitoring where the proxy server focuses its analysis on suspicious or unusual data flows rather than uniformly processing all traffic. The system uses intelligent filtering to identify and closely monitor only those flows that exhibit characteristics of potential threats, while allowing normal, verified traffic to pass through with minimal processing. This approach maintains high security reliability for critical flows while preserving overall data flow efficiency and productivity.
Data Source
Figure 1
Figure 2
AI summary
To manage the security of communications to and from a mobile device, including voice communications (since mobile devices are capable of Voice over IP (VoIP) communications), a local proxy server is installed on the device. This management is further secured by protecting the proxy server's configuration through security mechanisms. These mechanisms include, for example, those associated with security domains. This security is managed centrally via a server that generates and distributes the configurations, using the same read/write mechanisms.