Customized VPN Access Control via Disposable Session Identifiers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Internet communication systems lack effective privacy protection, as they convey content in non-encrypted form, allowing personal information and conversation records to be vulnerable to hacking, even when using virtual private networks (VPNs).

Innovation Solution

A customized virtual private network (CVPN) is established through customized programming that enables secure, encrypted communication without requiring personal information, ensures only encrypted content is stored, and allows for complete deletion of conversation records, using Diffie-Hellman encryption and key-exchange methods to protect user data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If traditional VPNs are used to encrypt communications, then content privacy is improved, but personal information exposure risk increases due to access requirements

Engineering Contradiction:
Improvecontent privacyVSAvoidpersonal information exposure risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts and removes the requirement for personal information from the VPN access process. Users can access the encrypted communication network without providing phone numbers, email addresses, or other personal identifiers, thereby maintaining content privacy while eliminating personal information exposure risks

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary mechanism where temporary session identifiers replace personal information for access control. This intermediary layer allows users to connect to the encrypted network without divulging personal details, resolving the contradiction between security and privacy

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encrypted content is stored during transmission, then communication security is improved, but vulnerability to hacking increases due to storage requirements

Engineering Contradiction:
Improvecommunication securityVSAvoidvulnerability to hacking
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by implementing end-to-end encryption before content is transmitted or stored. The encryption is established in advance during the key exchange process, ensuring that even if content is stored during transmission, it remains secure and vulnerable only to the strength of the encryption itself, not to storage vulnerabilities

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the cryptographic parameters dynamically through Diffie-Hellman key exchange, generating unique session keys for each communication session. This parameter change ensures that stored encrypted content from different sessions cannot be decrypted by each other's keys, reducing vulnerability to hacking

Inventive Principle:
Principle #35Parameter changes

3Reliability

If personal information is collected for VPN access, then network authorization is improved, but privacy protection deteriorates

Engineering Contradiction:
Improvenetwork authorizationVSAvoidprivacy protection
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent uses temporary, disposable session identifiers instead of permanent personal information for network authorization. These temporary identifiers are generated for each session and discarded afterward, providing sufficient authorization reliability without compromising long-term privacy protection

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The system performs self-service authorization through cryptographic key pairs and session identifiers that automatically verify user identity without requiring personal information collection. The authorization mechanism serves itself through mathematical verification rather than human review of personal data

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If conversation records are retained for reference, then communication utility is improved, but privacy security deteriorates due to capture risk

Engineering Contradiction:
Improvecommunication utilityVSAvoidprivacy security
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent implements automatic discarding of encrypted conversation records after delivery confirmation. The system recovers the utility of communication by delivering messages while automatically discarding stored records from both sender and receiver sides, eliminating privacy security risks associated with retained conversation records

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentUS12143366B2Controlled-access encrypted-communications system
Publication Date: 2024.11.12 GHANMA TARIQ TONY
  • US12143366B2 patent drawing
  • US12143366B2 patent drawing
  • US12143366B2 patent drawing

AI summary

The invention is a method of use for a VPN, customized via programming, that controls access without requiring any personal user information, and conveys only files encrypted using Diffie-Hellman AES-256-GCM encryption processes. Conveyed files are stored only in encrypted form and can only be displayed in real time by a user, and once viewed, only the encrypted file remains. The method also includes a means of end-to-end file deletion that leaves no remnants of the deleted file behind.