Address Conversion Device for Cloud Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud computing services, especially IaaS, there is a risk of unauthorized access and information leakage due to shared IP addresses, which complicates user identification and service provision, and using private lines does not always prevent unauthorized access.
Innovation Solution
An address converting device that uses conversion tables to transform transmission source and recipient IP addresses for each communication path, ensuring that only genuine users can access cloud services by verifying user identification and authentication information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If shared IP addresses are used in cloud computing services, then resource utilization and accessibility are improved, but security and user identification become compromised
Solution Approach 1:
The patent segments the shared IP address space by creating path-specific conversion tables that associate different IP addresses with different communication paths. Each path (e.g., from different user terminals) has its own converted IP address mapping, allowing the system to maintain shared resource access while uniquely identifying each user's communication path through the converted address.
Solution Approach 2:
The patent introduces an address converting device as an intermediary between user terminals and cloud services. This intermediary performs IP address conversion based on communication path identification, acting as a mediator that preserves user identification accuracy while enabling shared IP address usage in cloud computing environments.
2Reliability
If private lines are used for cloud service access, then transmission security is improved, but unauthorized access prevention remains insufficient
Solution Approach 1:
The patent applies preliminary anti-action by performing IP address conversion before packets reach the cloud service, proactively preventing unauthorized access attempts. The address converting device converts IP addresses based on predetermined path-specific tables, creating a pre-established security barrier that blocks unauthorized access before it can affect the cloud service.
Solution Approach 2:
The address converting device serves as an intermediary security layer that enhances protection against unauthorized access. By converting IP addresses based on communication path identification, it creates an additional verification mechanism that works in conjunction with private line transmission security to prevent unauthorized access more effectively than either method alone.
3Reliability
If IP address conversion is performed for each communication path, then security and user identification are improved, but device complexity and processing overhead increase
Solution Approach 1:
The patent achieves universality by designing an address converting device that handles multiple communication paths through a unified mechanism. The device uses a single conversion table structure that can accommodate path-specific mappings, allowing it to securely manage multiple users and paths without requiring separate complex systems for each, thus reducing overall device complexity while maintaining security.
Data Source
AI summary
A device for converting an address, the device includes: a memory; and a processor coupled to the memory and configured to: receive a request packet of contents from a first information processing device; convert a first transmission source address included in the request packet to a second transmission source address by using a conversion table corresponding to a communication path of the request packet; and transmit the request packet to a second information processing device which determines whether to provide the contents based on the second transmission source address included in the request packet.


