Secure Tunnel Relay for Mobile Device Server Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for secure access between mobile devices and application servers face challenges in maintaining security and efficiency, particularly when navigating through multiple firewalls and requiring user authentication, which can complicate data transmission and access control.
Innovation Solution
The implementation of a secure tunneling mechanism using a relay device that establishes a secure connection between mobile devices and application servers, allowing encrypted data transmission through firewalls while authenticating mobile devices and controlling access to specific data resources based on identification information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a virtual private network or management service is used to enable remote access, then secure access to corporate network resources is achieved, but the device complexity and authentication requirements increase
Solution Approach 1:
The patent applies preliminary action by pre-establishing a secure tunnel connection between the mobile device and the application server before actual data transmission begins. The tunnel is set up in advance with authentication and encryption parameters, so that when data needs to be transmitted, the secure pathway is already in place, eliminating the need for repeated authentication processes for each data transfer operation.
2Ease of operation
If ports are opened in a firewall to allow access, then remote access capability is improved, but network security is compromised
Solution Approach 1:
The patent employs an intermediary approach by introducing a relay device or gateway that acts as a mediator between the mobile device and the corporate network resources. Instead of opening ports directly in the firewall to allow external access, the relay device establishes a controlled connection through the firewall, mediating all data transmissions and maintaining security while enabling remote access functionality.
Solution Approach 2:
The patent applies segmentation by dividing the network architecture into distinct segments: the external mobile device, the relay/gateway layer, and the internal corporate network resources. This segmentation allows the firewall to remain intact and secure while the relay device creates a separate, controlled access pathway that doesn't require opening firewall ports, thus maintaining security while enabling remote access.
3Reliability
If authentication is required for each data transmission request, then access control is strengthened, but data transmission efficiency decreases
Solution Approach 1:
The patent resolves this contradiction by performing authentication and establishing the secure tunnel in advance, before actual data transmission begins. Once the tunnel is established with proper authentication, multiple data transmissions can occur through this pre-authenticated pathway without requiring repeated authentication for each transmission, thus maintaining strong access control while significantly improving data transmission efficiency.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present disclosure presents a system, method and apparatus for creating a secure tunnel between a mobile device and a server. The server can be configured to receive authentication information from the mobile device. The server can be further configured to establish a secure tunnel between the server and mobile device through at least one firewall in response to verification of the authentication information, the secure tunnel allowing the mobile device direct access to at least one application associated with the server. Additionally, the server can be configured to provide, to the mobile device, data associated with the at least one application.