Secure Boot Thin Client Language Switching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data communication systems face challenges in maintaining security across unsecured networks, particularly when accessing remote secure networks from public or untrusted environments, and in managing secure connections and key updates in distributed systems.

Innovation Solution

The implementation of a thin client system utilizing a secure boot device to establish secure connections over unsecured networks, enabling secure access to network-based services, and managing encryption keys and software updates within a secure network framework.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical network segregation is used to maintain security, then data security is improved, but device complexity and maintenance cost increase

Engineering Contradiction:
Improvedata securityVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network into multiple Virtual Private Networks (VPNs) that can coexist on a single physical infrastructure. Each VPN provides isolated logical networks for different security requirements, eliminating the need for separate physical networks while maintaining security boundaries through virtualization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal physical network infrastructure that supports multiple VPNs and security levels simultaneously. This multi-functional approach allows a single network to serve multiple security purposes, replacing the need for separate dedicated networks for different security zones.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If data is transmitted in plaintext format for ease of access, then ease of operation is improved, but security is compromised

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent dynamically changes the encryption parameter state of data based on the destination VPN and security requirements. Data can be transmitted in encrypted form across unsecured networks and automatically decrypted only within authorized VPN contexts, allowing plaintext accessibility only where security clearance is verified.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If access to public networks is provided for remote connectivity, then adaptability is improved, but security risks increase

Engineering Contradiction:
Improveremote access capabilityVSAvoidsecurity threats
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces VPN gateways and encryption layers as intermediary components between public networks and private data. These intermediaries act as security buffers that allow remote access through public networks while preventing direct exposure of sensitive data to unsecured environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies preliminary encryption and authentication measures before data leaves the secure environment. By pre-securing data with encryption keys and access controls before transmission over public networks, the system prevents security threats from compromising the data during transit or at remote access points.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS12321458B2Methods and systems for providing and controlling cryptographic secure communications terminal operable in a plurality of languages
Publication Date: 2025.06.03 UNISYS CORP
  • US12321458B2 patent drawing
  • US12321458B2 patent drawing
  • US12321458B2 patent drawing

AI summary

Methods and systems for switching between multiple languages of a remote desktop client operating on a secure boot device are disclosed. A method includes initiating an operating system from the secure boot device and receiving credentials including a user identification and a password. The method also includes booting, from the secure boot device, the operating system in a first language and receiving a selection of a second language different from the first language within a user interface of the operating system. The method further includes performing a desktop reset to execute the operating system in the second language.