Virtual Gateway for Secure Network Terminal Connection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for securing mobile terminals' connections to computer networks are inadequate, as they often require hardware-specific and operating system-dependent approaches, which are not portable and fail to effectively prevent malicious data transmission, especially in environments where terminals connect from various geographical locations.

Innovation Solution

A software-based method that creates a virtual gateway by duplicating communication interfaces, assigning compatible addresses, and redirecting data streams through a virtual machine, allowing for filtering and processing of data streams, thereby providing enhanced security and access control without relying on hardware-specific solutions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware-specific and operating system-dependent solutions are used to secure mobile terminal connections, then security protection is provided, but portability and adaptability across different environments are lost

Engineering Contradiction:
Improvesecurity protectionVSAvoidportability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a virtual copy of the terminal's communication interface (network interface card) as a virtual network interface. This virtual interface replicates the functionality of the physical interface, allowing security filtering to be implemented in software without affecting the hardware. The virtual interface can be deployed across different operating systems and hardware platforms, providing portable security protection.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a virtual network interface as an intermediary layer between the terminal application and the physical network interface. All network traffic must pass through this virtual interface, which acts as a mediator that can filter and control data streams. This intermediary approach enables security functionality to be implemented independently of the underlying hardware and operating system specifics.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If firewall and anti-virus software are installed on the terminal or gateway server, then data filtering and security are improved, but implementation becomes complex and device-specific

Engineering Contradiction:
Improvedata filtering capabilityVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of implementing complex firewall and anti-virus software on the terminal or gateway server, the patent creates a simplified virtual network interface that provides the essential filtering functionality. This virtual interface contains the necessary security logic in a portable format, eliminating the need for complex software installations on multiple devices while maintaining data filtering capabilities.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent extracts the essential security filtering functionality from complex firewall and anti-virus software systems and consolidates it into a standalone virtual network interface. This extracted functionality is sufficient for securing mobile terminal connections without requiring the full complexity of traditional security software suites.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If removable devices with integrated software are used to configure connection parameters, then security configuration becomes flexible, but hardware dependency and compatibility issues arise

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidhardware dependency
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical/hardware-based removable device approach with a software-based virtual network interface. Instead of using physical removable devices to configure connection parameters, the virtual interface is created and configured through software operations. This substitution eliminates hardware dependency while maintaining configuration flexibility, as the virtual interface can be created, modified, and deployed through software without requiring physical media or hardware changes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP2502399B1Method and devices for securing the connection of a terminal to a computer network
Publication Date: 2015.07.01 SAAD
  • EP2502399B1 patent drawingFigure 1

AI summary

The present invention relates to a method of securing the connection of a terminal (1) to a communication network (2), especially of computing type, in which said terminal (1) is connected to said network (2) across at least one communication interface (3, 4) in such a way as to send and receive at least one data stream, comprising steps of (i) creating a virtual gateway (6) for controlling said data stream; (ii) creating a virtual interface (30, 40) at the level of said gateway by duplicating said communication interface (3, 4); (iii) configuring said communication interface (3, 4) so as to render it unavailable in relation to said network (2), in such a way that said stream is redirected to said virtual interface (30, 40); (iv) controlling said data stream at the level of said gateway (60) and routing the controlled data stream towards said terminal (1). The invention also relates to a computer program device implementing the method.