Secure Channel Wake-Up for Low-Power Mobile VPN Continuity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VPN technologies require constant communication and high energy consumption to maintain a secure channel while a mobile client is in sleep mode, leading to battery depletion and unnecessary noise on wireless networks.

Innovation Solution

A method involving shared secrets and reference keys to securely restore the VPN tunnel by exchanging wake-up messages protected by the secret, allowing the client to switch to sleep mode without maintaining a persistent communication channel, and enabling rapid re-establishment upon need.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the client maintains a persistent communication channel while in sleep mode, then the VPN tunnel remains open and service continuity is ensured, but energy consumption increases and the client generates constant noise on the wireless network

Engineering Contradiction:
Improveservice continuityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system uses periodic wake-up messages exchanged between client and server to maintain VPN tunnel validity without requiring continuous communication. The client wakes up at predetermined intervals to exchange keep-alive messages, then returns to sleep mode. This periodic action ensures service continuity while dramatically reducing energy consumption compared to maintaining a persistent open channel.

Inventive Principle:
Principle #19Periodic action

2Reliability

If the client exchanges heartbeat signals to keep the VPN tunnel open, then the tunnel remains active and service continuity is maintained, but unnecessary communication noise is generated on the wireless network

Engineering Contradiction:
Improvetunnel integrityVSAvoidcommunication noise
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

Instead of continuous heartbeat signals, the system implements periodic wake-up messages at predetermined intervals. The client wakes from sleep mode, exchanges a brief keep-alive message with the server, and returns to sleep mode. This reduces communication noise while maintaining tunnel integrity through periodic validation rather than continuous signaling.

Inventive Principle:
Principle #19Periodic action

3Adaptability or versatility

If the client frequently changes IP address due to mobility, then the client can move freely between base stations, but the VPN session must be reset and authentication procedures must be resumed

Engineering Contradiction:
Improvemobility functionalityVSAvoidsession continuity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by maintaining VPN context information and security associations in both client and server memory before IP address changes occur. When the client moves and obtains a new IP address, the pre-stored context is quickly reactivated without requiring full re-authentication. This preliminary preparation of context data enables seamless session continuity despite mobility-induced IP changes.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250220416A1Method for maintaining a secure channel between a client and a server through a wireless network; associated computer program product
Publication Date: 2025.07.03 THALES SA
  • US20250220416A1 patent drawing
  • US20250220416A1 patent drawing

AI summary

A method for maintaining a secure channel between a client and a server through a wireless network, a secret being shared between the client and the server. the method including while the client is in sleep mode and data must be transmitted from the client to the server, wake-up of the client and initiating, by the client, a procedure for restoring the secure channel by transmitting to the server a change of state wake-up message, protected by using the secret, and while the client is in sleep mode and that data must be transmitted from the server to the client, wake-up of the client by the server by means of the transmission of a paging message and launching by the client, the restoring procedure of the secure channel by transmitting to the server, a change of state wake-up message using the secret.