Address Conversion Device for Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing services, especially IaaS, there is a risk of unauthorized access and information leakage due to shared IP addresses, which complicates user identification and service provision, and using private lines does not always prevent unauthorized access.

Innovation Solution

An address converting device that uses conversion tables to transform transmission source and recipient IP addresses for each communication path, ensuring that only genuine users can access cloud services by verifying user identification and authentication information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If shared IP addresses are used in cloud computing services, then resource utilization and accessibility are improved, but security and user identification become compromised

Engineering Contradiction:
Improveresource utilizationVSAvoiduser identification accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the shared IP address space by creating path-specific conversion tables that associate different IP addresses with different communication paths. Each path (e.g., from different user terminals) has its own converted IP address mapping, allowing the system to maintain shared resource access while uniquely identifying each user's communication path through the converted address.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an address converting device as an intermediary between user terminals and cloud services. This intermediary performs IP address conversion based on communication path identification, acting as a mediator that preserves user identification accuracy while enabling shared IP address usage in cloud computing environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If private lines are used for cloud service access, then transmission security is improved, but unauthorized access prevention remains insufficient

Engineering Contradiction:
Improvetransmission securityVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by performing IP address conversion before packets reach the cloud service, proactively preventing unauthorized access attempts. The address converting device converts IP addresses based on predetermined path-specific tables, creating a pre-established security barrier that blocks unauthorized access before it can affect the cloud service.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The address converting device serves as an intermediary security layer that enhances protection against unauthorized access. By converting IP addresses based on communication path identification, it creates an additional verification mechanism that works in conjunction with private line transmission security to prevent unauthorized access more effectively than either method alone.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If IP address conversion is performed for each communication path, then security and user identification are improved, but device complexity and processing overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidaddress conversion system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent achieves universality by designing an address converting device that handles multiple communication paths through a unified mechanism. The device uses a single conversion table structure that can accommodate path-specific mappings, allowing it to securely manage multiple users and paths without requiring separate complex systems for each, thus reducing overall device complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10637777B2Address converting device, information processing system, and method of providing service
Publication Date: 2020.04.28 FSAS TECH INC
  • US10637777B2 patent drawing
  • US10637777B2 patent drawing
  • US10637777B2 patent drawing

AI summary

A device for converting an address, the device includes: a memory; and a processor coupled to the memory and configured to: receive a request packet of contents from a first information processing device; convert a first transmission source address included in the request packet to a second transmission source address by using a conversion table corresponding to a communication path of the request packet; and transmit the request packet to a second information processing device which determines whether to provide the contents based on the second transmission source address included in the request packet.