Client System Authentication via Virtual Address Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In a public cloud environment, authenticating application servers using IP addresses and domain names is challenging due to dynamic changes in IP addresses and domain names assigned by software-defined networking, making it difficult to achieve dynamic scale-out and registration of application servers for SaaS services.
Innovation Solution
A client system authentication method involving the acquisition of a shared key, generation of a virtual address using identification information and the shared key, and transmission of registration request information to an authentication server to receive an authentication key, allowing for secure authentication and service access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IP addresses and domain names are used to authenticate application servers, then authentication can be performed using existing identification methods, but authentication fails when IP addresses and domain names are dynamically changed by software-defined networking
Solution Approach 1:
The patent applies preliminary action by pre-registering application servers with the authentication server before they are actually deployed or before their IP addresses change. The registration process stores server identification information and authentication credentials in advance, creating a baseline authentication record that remains valid even when network parameters change dynamically.
Solution Approach 2:
The patent implements dynamics by enabling the authentication system to adapt to changing IP addresses and domain names. The authentication server maintains registered server identities independently of their current network parameters, allowing servers to be re-authenticated with new IP addresses without requiring re-registration, thus making the system flexible to dynamic cloud environments.
2Stability of the object's composition
If application servers are authenticated using fixed IP addresses, then authentication stability is maintained, but dynamic scale-out cannot be achieved until IP addresses are registered
Solution Approach 1:
The patent enables preliminary registration of application servers with the authentication server before they are fully deployed or before their IP addresses are assigned. This pre-registration process stores server identification information in advance, allowing servers to be quickly added to the system without waiting for IP address allocation and registration, thus accelerating scale-out operations while maintaining authentication stability.
Solution Approach 2:
The authentication server automatically manages the registration and authentication processes without requiring manual intervention for each server addition. The system self-updates authentication records when servers register themselves or when IP addresses change, enabling rapid scale-out while maintaining stable authentication through automated processes.
3Adaptability or versatility
If IP addresses are dynamically assigned by software-defined networking, then cloud flexibility and scalability are improved, but traditional authentication methods become ineffective
Solution Approach 1:
The patent makes the authentication system dynamic by decoupling authentication from fixed network parameters. The authentication server stores server identities and credentials independently of IP addresses, allowing servers to change their network parameters dynamically while maintaining valid authentication. This enables cloud scalability with dynamic IP assignment while preserving authentication reliability through adaptive verification processes.
Solution Approach 2:
The patent introduces an intermediary authentication server that mediates between application servers and the authentication verification process. This intermediary maintains a registry of authorized servers and their identification information, serving as a stable reference point that validates servers regardless of their dynamically changing IP addresses, thus enabling both cloud flexibility and secure authentication.
Data Source
AI summary
Provided are a client system authentication method, a client device, and an authentication server. The client system authentication method includes acquiring a shared key to be shared between a client system and an authentication server in cooperation with the authentication server, generating a virtual address of the client system using identification information of the client system and the shared key, transmitting registration request information including the virtual address to the authentication server, and receiving an authentication key for the client system from the authentication server.


