Client System Authentication via Virtual Address Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a public cloud environment, authenticating application servers using IP addresses and domain names is challenging due to dynamic changes in IP addresses and domain names assigned by software-defined networking, making it difficult to achieve dynamic scale-out and registration of application servers for SaaS services.

Innovation Solution

A client system authentication method involving the acquisition of a shared key, generation of a virtual address using identification information and the shared key, and transmission of registration request information to an authentication server to receive an authentication key, allowing for secure authentication and service access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IP addresses and domain names are used to authenticate application servers, then authentication can be performed using existing identification methods, but authentication fails when IP addresses and domain names are dynamically changed by software-defined networking

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidadaptability to dynamic IP changes
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by pre-registering application servers with the authentication server before they are actually deployed or before their IP addresses change. The registration process stores server identification information and authentication credentials in advance, creating a baseline authentication record that remains valid even when network parameters change dynamically.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamics by enabling the authentication system to adapt to changing IP addresses and domain names. The authentication server maintains registered server identities independently of their current network parameters, allowing servers to be re-authenticated with new IP addresses without requiring re-registration, thus making the system flexible to dynamic cloud environments.

Inventive Principle:
Principle #15Dynamics

2Stability of the object's composition

If application servers are authenticated using fixed IP addresses, then authentication stability is maintained, but dynamic scale-out cannot be achieved until IP addresses are registered

Engineering Contradiction:
Improveauthentication stabilityVSAvoidscale-out speed
Core Design Contradiction:
Stability of the object's compositionVSProductivity

Solution Approach 1:

The patent enables preliminary registration of application servers with the authentication server before they are fully deployed or before their IP addresses are assigned. This pre-registration process stores server identification information in advance, allowing servers to be quickly added to the system without waiting for IP address allocation and registration, thus accelerating scale-out operations while maintaining authentication stability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication server automatically manages the registration and authentication processes without requiring manual intervention for each server addition. The system self-updates authentication records when servers register themselves or when IP addresses change, enabling rapid scale-out while maintaining stable authentication through automated processes.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If IP addresses are dynamically assigned by software-defined networking, then cloud flexibility and scalability are improved, but traditional authentication methods become ineffective

Engineering Contradiction:
Improvecloud scalabilityVSAvoidauthentication reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent makes the authentication system dynamic by decoupling authentication from fixed network parameters. The authentication server stores server identities and credentials independently of IP addresses, allowing servers to change their network parameters dynamically while maintaining valid authentication. This enables cloud scalability with dynamic IP assignment while preserving authentication reliability through adaptive verification processes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces an intermediary authentication server that mediates between application servers and the authentication verification process. This intermediary maintains a registry of authorized servers and their identification information, serving as a stable reference point that validates servers regardless of their dynamically changing IP addresses, thus enabling both cloud flexibility and secure authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10728232B2Method for authenticating client system, client device, and authentication server
Publication Date: 2020.07.28 SAMSUNG SDS CO LTD
  • US10728232B2 patent drawing
  • US10728232B2 patent drawing
  • US10728232B2 patent drawing

AI summary

Provided are a client system authentication method, a client device, and an authentication server. The client system authentication method includes acquiring a shared key to be shared between a client system and an authentication server in cooperation with the authentication server, generating a virtual address of the client system using identification information of the client system and the shared key, transmitting registration request information including the virtual address to the authentication server, and receiving an authentication key for the client system from the authentication server.