Virtual Gateway for Secure Network Terminal Connection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for securing mobile terminals' connections to computer networks are inadequate, as they often require hardware-specific and operating system-dependent approaches, which are not portable and fail to effectively prevent malicious data transmission, especially in environments where terminals connect from various geographical locations.
Innovation Solution
A software-based method that creates a virtual gateway by duplicating communication interfaces, assigning compatible addresses, and redirecting data streams through a virtual machine, allowing for filtering and processing of data streams, thereby providing enhanced security and access control without relying on hardware-specific solutions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware-specific and operating system-dependent solutions are used to secure mobile terminal connections, then security protection is provided, but portability and adaptability across different environments are lost
Solution Approach 1:
The patent creates a virtual copy of the terminal's communication interface (network interface card) as a virtual network interface. This virtual interface replicates the functionality of the physical interface, allowing security filtering to be implemented in software without affecting the hardware. The virtual interface can be deployed across different operating systems and hardware platforms, providing portable security protection.
Solution Approach 2:
The patent introduces a virtual network interface as an intermediary layer between the terminal application and the physical network interface. All network traffic must pass through this virtual interface, which acts as a mediator that can filter and control data streams. This intermediary approach enables security functionality to be implemented independently of the underlying hardware and operating system specifics.
2Reliability
If firewall and anti-virus software are installed on the terminal or gateway server, then data filtering and security are improved, but implementation becomes complex and device-specific
Solution Approach 1:
Instead of implementing complex firewall and anti-virus software on the terminal or gateway server, the patent creates a simplified virtual network interface that provides the essential filtering functionality. This virtual interface contains the necessary security logic in a portable format, eliminating the need for complex software installations on multiple devices while maintaining data filtering capabilities.
Solution Approach 2:
The patent extracts the essential security filtering functionality from complex firewall and anti-virus software systems and consolidates it into a standalone virtual network interface. This extracted functionality is sufficient for securing mobile terminal connections without requiring the full complexity of traditional security software suites.
3Adaptability or versatility
If removable devices with integrated software are used to configure connection parameters, then security configuration becomes flexible, but hardware dependency and compatibility issues arise
Solution Approach 1:
The patent replaces the mechanical/hardware-based removable device approach with a software-based virtual network interface. Instead of using physical removable devices to configure connection parameters, the virtual interface is created and configured through software operations. This substitution eliminates hardware dependency while maintaining configuration flexibility, as the virtual interface can be created, modified, and deployed through software without requiring physical media or hardware changes.
Data Source
Figure 1
AI summary
The present invention relates to a method of securing the connection of a terminal (1) to a communication network (2), especially of computing type, in which said terminal (1) is connected to said network (2) across at least one communication interface (3, 4) in such a way as to send and receive at least one data stream, comprising steps of (i) creating a virtual gateway (6) for controlling said data stream; (ii) creating a virtual interface (30, 40) at the level of said gateway by duplicating said communication interface (3, 4); (iii) configuring said communication interface (3, 4) so as to render it unavailable in relation to said network (2), in such a way that said stream is redirected to said virtual interface (30, 40); (iv) controlling said data stream at the level of said gateway (60) and routing the controlled data stream towards said terminal (1). The invention also relates to a computer program device implementing the method.