Methods for using a proxy server for data exchange
The method employs a token-based system for data exchange between network terminals, reducing proxy server load and latency while enhancing security, by using a token with a meeting point number and expiration time for authentication and data exchange.
Patent Information
- Application Number
- DE102016107673
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2016-04-26
- Publication Date
- 2025-05-08
- Estimated Expiration
- 2036-04-26
AI Technical Summary
Existing proxy server systems face challenges in managing exchange points for data exchange between network terminals, leading to potential overloading and increased latency due to the need for extensive authentication and management of exchange points.
A method utilizing a token generated by the proxy server for data exchange between network terminals, where the token contains a meeting point number and expiration time, allowing clients to authenticate and exchange data directly via the proxy server without extensive management of exchange points.
This approach reduces the load on proxy servers, minimizes the risk of overloading from attacks, and decreases latency by allowing direct data exchange between clients using the token, while maintaining security through authentication and secret information.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The invention relates to a solution for using a proxy server arranged in a network for data exchange between network clients, or rather, clients of the respective network. Said clients are software-based applications, namely client applications, which are processed by network terminals, exchanging data between these network terminals.
[0002] In the wake of developments such as IoT (Internet of Things) or smart homes, it is becoming increasingly necessary for data to be exchanged between network end devices that, for security reasons or for operational reasons, cannot exchange data directly with each other when using corresponding applications, or can only do so to a very limited extent. In these cases, comprehensive data exchange between network end devices takes place via server devices or server systems acting as proxy servers. Such systems are subject to very stringent requirements. In particular, they must be available, preferably around the clock, and be able to simultaneously process a large number of simultaneous requests from network end devices that wish to use them for data exchange.
[0003] Due to latencies that occur with greater distances between proxy servers and the network end devices using them, proxy servers that offer corresponding applications requiring data exchange between network end devices, such as servers providing a service via a web portal, are increasingly being deployed in multiple configurations and spatially distributed within the network to reduce the distances to the network devices they use. However, this has the disadvantage of increasing the latency between the systems or proxy servers, thus making synchronous operation more difficult.
[0004] To prevent misuse, it is common practice for network end devices to be authenticated to the proxy server before being authorized to use its resources. If a network end device is successfully authenticated using the authentication credentials transmitted by it or its user, the proxy server authorizes it to use its resources. In the context of the following descriptions, this means that it can exchange data with other clients via the proxy server. For this purpose, after the successful authentication of a client logging on to the proxy server, the relevant proxy server generates a data record that designates an exchange point. The corresponding exchange point or the data designating it is stored on the proxy server.Each client accessing this exchange point is enabled by the proxy server to exchange data with other clients using the same exchange point - again after authentication if necessary.
[0005] Typically, the aforementioned exchange points stored on a proxy server are valid for a limited period of time, meaning they are deleted by the proxy server after a certain period of unused time. In existing systems, measures must be taken to prevent system overload. For example, attackers could request a large number of exchange points, thereby overloading the system's memory and ultimately the system itself. Another disadvantage is that determining which exchange points are to be deleted after their expiration date requires considerable computing time when there are a large number of such exchange points. This, too, can lead to a very heavy system load if a proxy server is used extensively.
[0006] The object of the invention is to provide a solution that avoids the aforementioned disadvantages. To this end, a method is to be specified whose implementation reduces the risk of proxy server overload due to attacks in the form of a large number of requests directed to a particular server. Furthermore, the method is intended to support the design of systems in which data exchange between network terminals takes place via a proxy server with a view to reducing latencies. The method should preferably be designed in such a way that it is itself protected against manipulation.
[0007] The object is achieved by a method having the features of patent claim 1 and in a further embodiment according to the subclaims.
[0008] As already explained, the presented method relates to a method for using a proxy server arranged in a network for data exchange between clients of the network, i.e., between client applications processed by network terminals. In this context, the invention proposes that the data exchange between the clients takes place via the proxy server using a token consisting of data.
[0009] According to the invention, the relevant token is generated by the proxy server after a first client has registered with the proxy server. The token is then transmitted to the first client registered with the proxy server, and from this first client, it is transmitted to one or more clients in preparation for a subsequent data exchange using a direct messaging channel. All clients subsequently logging into the proxy server using this token are then able to exchange data with each other via the proxy server.
[0010] The method according to the invention is therefore based on the idea of freeing the proxy server(s) of a network from the management of exchange points for data exchange between network terminals or between client applications running on such network terminals. This alone reduces the load on the respective proxy server. Furthermore, it prevents the proxy server in question from being blocked by an attack resulting from a large number of requests. Instead of storing and managing data on exchange points on the respective proxy server, the network terminals are enabled to exchange data via the proxy server using a token in their possession, which the network terminals use to register with the proxy server for data exchange.Each client is provided with information in the form of a token, which contains all the necessary data and which the respective client must provide the next time it accesses the proxy server. This information, as explained in more detail later, is preferably not forgeable, so that no unauthorized access to the proxy server can be gained.
[0011] The token in question is exchanged via a narrowband direct messaging channel, which is not itself designed for the transmission of large amounts of data with the actual payload, between the network terminal devices subsequently involved in the data exchange or, after its receipt from the proxy server generating the token, is transmitted to the other clients by the first client that logs on to the proxy server for this purpose.
[0012] The token mentioned repeatedly above is, as already explained, a data sequence. This sequence encodes at least one meeting point number and preferably an expiration time at which the token becomes invalid. Further details on the design of the token will be provided later, particularly in connection with the explanation of a specific embodiment.
[0013] In the context of an advantageous, practical implementation, the method relates to a network in which several proxies are distributed across a geographical area. The method is designed such that the proxy server used in the context of a data exchange between two or more network terminals is one of several proxy servers distributed within the network. The first client to which this proxy server transmits the token it has generated transmits to the other clients, together with the token or as part of the token, data that uniquely identifies the proxy server to be used for the subsequent data exchange between the clients.
[0014] If it is possible to use one of several proxy servers, the method is preferably designed such that the first client selects the proxy server to be used for data exchange with the other clients from a list containing the addresses of several proxy servers distributed throughout the network. Different procedural and system designs are conceivable for the type and location of implementation of said list containing the addresses of the proxy servers available within a specific network application for data exchange between clients communicating with each other when using the application, and thus also for the type of access to this list.
[0015] It is particularly preferred that the corresponding address list be maintained by a central directory service or compiled by such a directory service for retrieval by a client. Given that a key objective of the proposed method is to reduce latencies during data exchange between clients via a proxy server, the directory service can provide the address list in such a way that it flexibly compiles the list depending on the location of a requesting client, so that addresses of proxy servers located near the client retrieving the list are, in a kind of ranking, placed at the top of the list.However, it is also possible that the first client itself, i.e. a corresponding application running on a network terminal, selects the nearest proxy server for the network terminal in question from a list of proxy server addresses received from the directory service.
[0016] Another possibility is for the list of proxy server addresses to be part of a respective network application that uses a proxy server for data exchange. For example, it is conceivable that such a list could be integrated directly into an app, allowing a smartphone, as the first client, to exchange data with network end devices in a smart home environment, such as cameras or radiator thermostats, as additional clients via a proxy server on this list.
[0017] Regardless of whether the list of addresses of proxy servers usable for data exchange is maintained by a central directory service or provided as an integral part of an app or other network application, it is of course necessary for the process to function correctly that the list in question be kept up to date. The list must therefore be updated regularly, i.e., synchronized with the actual conditions. However, it is not harmful if the list temporarily or occasionally does not correspond to the actual conditions.In the worst case, this simply results in a client, or rather the first client, attempting to request the token required to perform the procedure from a proxy server selected from the list, but the proxy server in question may be temporarily unavailable or even no longer available due to the list not actually being up to date. In this case, the first client would simply contact another proxy server, identified by another list entry, to request the corresponding token.
[0018] As already explained, the data representing the token comprises at least one meeting point number, under which the clients possessing the token are able to exchange data, with the data being routed via the proxy server previously selected for this purpose. The proposed method also preferably provides for such a meeting point number to be valid only for a limited period, for example, a maximum period of inactivity during which no data is exchanged via the proxy server. Accordingly, with a corresponding method design, the token also includes data that defines such an expiration time for the meeting point number. For security reasons, namely in particular to prevent manipulation of the token and thus of the method, secret information is preferably also a further component of the token.This secret information is information exclusively associated with and known only to the selected proxy server providing the token. This can, for example, be randomly determined when the proxy is started or permanently embedded in the configuration. It can also be changed regularly if necessary. The only crucial factor here is that the secret information in question is unambiguous and thus that the token containing it is, in a sense, unique. The exact manner in which this secret information is determined is essentially irrelevant to the process. It must only be ensured that it is long enough that the information cannot be guessed by trial and error. The secret information consists of 64 random bits, for example.
[0019] Furthermore, it is particularly preferred that the token be cryptographically secured against manipulation using a hash function, for example, the SHA-256 hash function of the SHA-2 family. For the latter, the use of other hash algorithms is of course also possible. The method is preferably designed such that the secret information itself is hashed first, allowing the hash algorithm to be pre-initialized, saving time during operation.
[0020] Additional security for the process, or rather, the protection of the proxy server against attacks, is achieved by requiring the first client to request the token from the selected proxy server to authenticate itself based on a previously completed registration. To do this, the client must first transmit its authentication credentials to the selected proxy server. After successful authentication, the proxy server transmits the token it generated to the client, thereby authorizing the client to use the proxy server for the purpose of exchanging data with other clients. Client authentication can be achieved, for example, using a username and password, an OAuth2 token, or an LDAP system. Depending on the implementation of the process, any other authentication method can of course also be used.
[0021] The implementation also determines whether the authorization credentials that the first client transmits to the proxy server when requesting the token for data exchange are verified by the proxy server itself or by a separate authentication server interacting with it. Both options are equivalent in this respect. It should also be noted that, for the security of the process, it is sufficient if the first client requesting the token for data exchange from the proxy server authenticates itself to this proxy server in the manner described above.The authentication of other clients using the proxy server as authorized clients during data exchange with the first client and with each other, on the other hand, is carried out using a tamper-proof token, which also functions as an authentication feature. To receive this token, the first client has authenticated itself to the proxy server using other suitable authentication features. Communication between the system components, i.e., between the clients and the respective proxy server used for data exchange between them, should be confidential, for example, via a TLS connection.
[0022] The proposed method has the following advantages. A system operating according to it can scale horizontally very easily. This means that the system's performance can be increased as required by adding new proxy servers and entering them into the list, which is preferably maintained by a directory service. Since there is no communication between the proxy servers, the system can scale linearly. Performance can also be reduced by removing proxies. The method ensures that clients automatically switch to other proxies or proxy servers in this case. Furthermore, an exact time or a time synchronized between the proxy server used for data exchange and the clients is not necessary for the method to operate.It is only necessary to ensure that the time is sufficiently accurate to detect the expiration of a time stamp, particularly characterized by the meeting point number. Finally, the system can continue to operate even if the system is partitioned, since the individual proxy servers do not need to communicate with each other.
[0023] In the following, a possible sequence of the method according to the invention is to be described in the form of an exemplary embodiment with the aid of the Fig. 1 shown sequence diagram.
[0024] The method flow illustrated in the sequence diagram relates to a data exchange between two clients - Client A and Client B - within the framework of a network application via a proxy server. The example presented assumes that the said network application can be used via several proxy servers distributed throughout the network. According to the example, it is further provided that a directory service, also hosted on a server, maintains a list of addresses of the proxy servers that can be used in connection with the network application for data exchange between clients. The underlying system also includes an authentication server for checking the authentication features passed from Client A to the selected proxy server when retrieving the token that can be used for data exchange.
[0025] Accordingly, the method according to the invention proceeds as follows. If client A does not know the list of possible proxies or proxy servers, it obtains an address list of the proxy servers that can be used for data exchange with other clients during the execution of the aforementioned network application, such as a smart home application, from a directory service. The corresponding directory service can be addressed or accessed by client A itself due to appropriate coding in the network application.Client A either selects the first proxy server in the list, identified by its network address, or determines the proxy server through which it will run the network application or handle data exchange with the other client(s) B (assuming here, with a different client B), according to a set of rules implemented as part of the network application. This set of rules can be used to ensure that Client A uses the proxy server closest to its current location when launching the network application for data exchange.
[0026] Once selected, Client A contacts the relevant proxy server to request the token to be used for data exchange with Client B. In the process, Client A must first authenticate itself to this proxy server. To do so, it transmits appropriate authentication credentials, such as a username and password, to the proxy server it has contacted. In the example shown, the proxy server forwards these authorization credentials to a special authentication server for verification.
[0027] If the authentication credentials are recognized as correct by this authentication server, meaning that Client A is authenticated by the authentication server, the server informs the proxy server, which then transmits the token requested by Client A to Client A, thus authorizing it to use the proxy server for data exchange with the other Client B. Otherwise, if authentication fails, the process is aborted.
[0028] The token transmitted by the proxy server to Client A contains unique secret information associated with the proxy server, data on the validity period or expiration date of the token, and a meeting point number. However, the token and the information it contains are not transmitted by the proxy server to Client A in plain text, but rather in the form of a hash value generated by applying a hash function to the corresponding data sequence. After successful authentication and receipt of the token or the hash value representing the token from the proxy server, Client A transmits this token (hash value) along with information identifying the proxy server to be used for data exchange to Client B via a direct messaging channel.Both clients A, B can then exchange data with each other via the proxy server using the token for authentication against the proxy server until the maximum validity period of the token expires.
Claims
[1] Method for using a proxy server arranged in a network for the data exchange between clients A, B of the network, namely between client applications processed by network terminals, characterized by that the data exchange between the clients A, B takes place via the proxy server using a token which is generated by the proxy server after a first client A has registered with the proxy server, is transmitted to the first client A registered with it and is transmitted from this first client A to one or more clients B, that the token consists of data which comprise at least one meeting point number and that all clients A, B which log on to the proxy server using the said token are enabled to exchange data with one another via the proxy server using the token under the meeting point number contained therein, the data being routed via the proxy server. [2] Method according to claim 1, characterized by that the token is transmitted from the first client A receiving it from the proxy server to one or more other clients B using a direct messaging channel. [3] Method according to claim 1 or 2, characterized by that the proxy server used for data exchange is one of several proxy servers distributed in the network and that the first client A transmits to the other client(s) B, together with the token or as a component thereof, data which identify the proxy server to be used for data exchange between clients A, B. [4] Method according to claim 3, characterized by that the first client selects the proxy server to be used for data exchange with the other clients B from a list containing addresses of several of the proxy servers distributed in the network. [5] Method according to claim 4, characterized bythat the list of addresses of selectable proxy servers distributed throughout the network is provided via a directory service accessible by clients A, B of the network. [6] Method according to claim 1, characterized by that the token contains data that determines a validity period or an expiration time of the token. [7] Method according to claim 6, characterized by that the token contains secret information uniquely associated with the proxy server that generated it. [8] Method according to claim 6 or 7, characterized by that the token is transmitted in the form of a hash value of the data it contains from the proxy server to the first client A and from there to the other client(s) B, which hash value is formed by the proxy server by applying a hash function to the token generated by it. [9] Method according to claim 1 or 8, characterized bythat the first client A must authenticate itself when logging on to the proxy server to request a token, whereby the authentication features transmitted by it for this purpose are checked by the proxy server itself or by an authentication server interacting with it and a token is only transmitted by the proxy server to the first client A if it is successfully authenticated as being authorized to use the proxy server as a result of the check of the authentication features transmitted by it.
Citation Information
Patent Citations
System and method for information sharing using visual tags
US20130221083A1
Global link providing modification rights to a shared folder
US20140067865A1