Secure Tunnel Relay for Mobile Device Server Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for secure access between mobile devices and application servers face challenges in maintaining security and efficiency, particularly when navigating through multiple firewalls and requiring user authentication, which can complicate data transmission and access control.

Innovation Solution

The implementation of a secure tunneling mechanism using a relay device that establishes a secure connection between mobile devices and application servers, allowing encrypted data transmission through firewalls while authenticating mobile devices and controlling access to specific data resources based on identification information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a virtual private network or management service is used to enable remote access, then secure access to corporate network resources is achieved, but the device complexity and authentication requirements increase

Engineering Contradiction:
Improvesecure accessVSAvoidauthentication requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-establishing a secure tunnel connection between the mobile device and the application server before actual data transmission begins. The tunnel is set up in advance with authentication and encryption parameters, so that when data needs to be transmitted, the secure pathway is already in place, eliminating the need for repeated authentication processes for each data transfer operation.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If ports are opened in a firewall to allow access, then remote access capability is improved, but network security is compromised

Engineering Contradiction:
Improveremote access capabilityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent employs an intermediary approach by introducing a relay device or gateway that acts as a mediator between the mobile device and the corporate network resources. Instead of opening ports directly in the firewall to allow external access, the relay device establishes a controlled connection through the firewall, mediating all data transmissions and maintaining security while enabling remote access functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies segmentation by dividing the network architecture into distinct segments: the external mobile device, the relay/gateway layer, and the internal corporate network resources. This segmentation allows the firewall to remain intact and secure while the relay device creates a separate, controlled access pathway that doesn't require opening firewall ports, thus maintaining security while enabling remote access.

Inventive Principle:
Principle #1Segmentation

3Reliability

If authentication is required for each data transmission request, then access control is strengthened, but data transmission efficiency decreases

Engineering Contradiction:
Improveaccess controlVSAvoiddata transmission efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent resolves this contradiction by performing authentication and establishing the secure tunnel in advance, before actual data transmission begins. Once the tunnel is established with proper authentication, multiple data transmissions can occur through this pre-authenticated pathway without requiring repeated authentication for each transmission, thus maintaining strong access control while significantly improving data transmission efficiency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2768202B1Secure electronic device application connection to an application server
Publication Date: 2023.10.11 MALIKIE INNOVATIONS LTD
  • EP2768202B1 patent drawingFigure 1
  • EP2768202B1 patent drawingFigure 2
  • EP2768202B1 patent drawingFigure 3

AI summary

The present disclosure presents a system, method and apparatus for creating a secure tunnel between a mobile device and a server. The server can be configured to receive authentication information from the mobile device. The server can be further configured to establish a secure tunnel between the server and mobile device through at least one firewall in response to verification of the authentication information, the secure tunnel allowing the mobile device direct access to at least one application associated with the server. Additionally, the server can be configured to provide, to the mobile device, data associated with the at least one application.