Client Server System Authentication State Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network systems are vulnerable to unauthorized access when URL information is intercepted, allowing unauthorized access to content providers.

Innovation Solution

A client-server system that includes a first terminal apparatus, a second terminal apparatus, and a server, where the server generates and transmits access information with expiration dates, and sets authentication states to permit or prohibit authentication processes based on received requests, ensuring that authentication is only executed when the state is active.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication is always executed for every access request, then security is improved, but processing time and system complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies dynamics by making the authentication process conditional rather than static. The server dynamically adjusts whether to execute authentication based on the current authentication state (first state or second state). When in the first state, authentication is executed; when in the second state, authentication is skipped. This dynamic approach resolves the contradiction by allowing the system to optimize between security and processing time based on operational context.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of authentication execution from a fixed binary choice to a state-dependent variable. By introducing an authentication state parameter that can be switched between first state (authentication permitted) and second state (authentication prohibited), the system can adapt its security level and processing behavior. This parameter change allows the system to balance security requirements with processing efficiency.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If access information is transmitted to multiple terminal apparatuses, then accessibility is improved, but security vulnerability increases

Engineering Contradiction:
ImproveaccessibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by pre-establishing an authentication state on the server before access requests are processed. The server proactively sets the authentication state (first or second state) in advance, so that when multiple terminal apparatuses receive access information, the server is already prepared to handle authentication decisions. This preliminary configuration allows secure multi-device access by having authentication control ready before potential interception or unauthorized use occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback through the authentication state mechanism that provides continuous control over access requests. When the server receives access requests from multiple terminal apparatuses, it checks the current authentication state and responds accordingly - executing authentication in the first state or skipping it in the second state. This feedback loop ensures that even if access information is intercepted and used by unauthorized devices, the server can maintain security by consistently applying the authentication state policy.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11222100B2Client server system
Publication Date: 2022.01.11 KAWAMURA YOSHIHIRO
  • US11222100B2 patent drawing
  • US11222100B2 patent drawing
  • US11222100B2 patent drawing

AI summary

A terminal apparatus (1) includes a data acquisition unit (113) that acquires data from a business server (2) by transmitting a request to access a one-time URL indicated by URL information received from the business server (2). The business server (2) includes a URL generation unit (212) that generates a one-time URL, an expiration date setting unit (213) that sets an expiration date of the one-time URL, an authentication processing unit (216) that authenticates the terminal apparatus (1), and a state setting unit (215) that sets either an authentication function active state or an authentication function inactive state within the expiration date of the one-time URL. In a case where the authentication processing unit (216) receives the access request, the authentication processing unit (216) starts an authentication process when the authentication function active state is set, and avoids executing the authentication process when the authentication function inactive state is set.