Proxy Server Digital Identity Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network and device security solutions are inadequate in addressing security risks, particularly man-in-the-middle attacks and compromised proxy servers, and are complex to manage, especially for connected devices in critical infrastructure and IoT systems.

Innovation Solution

A proxy and communication system that uses a unique user digital identity and digital certificate authentication to provide secure access control, managing access rights and encrypting communications, with a centralized management system to control access and monitor user devices and resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital certificate authentication and unique user digital identity are implemented, then security against man-in-the-middle attacks and proxy server compromises is improved, but system complexity and management difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a certificate authority (CA) as an intermediary that issues digital certificates to both proxy servers and resources. This CA-mediated authentication system resolves the contradiction by providing a trusted third party that enables secure communication without requiring direct trust between proxy and resource, thereby improving security while maintaining manageable system complexity through centralized certificate management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication process into distinct components: digital certificates issued by a CA, client-side authentication of proxy servers, and server-side authentication of resources. This segmentation allows each component to be managed independently, improving overall security through layered authentication while reducing management complexity by distributing security functions across multiple manageable segments.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If centralized management system is used to control access and monitor devices, then manageability and control are improved, but system complexity and overhead increase

Engineering Contradiction:
ImprovemanageabilityVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges authentication, authorization, and accounting functions into a single centralized management system that handles digital certificate verification, access control decisions, and usage monitoring. This consolidation improves manageability by providing unified control over all proxy-server-resource interactions while reducing overall system complexity compared to distributed implementations of each function separately.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If per-user and per-resource access control is implemented, then security and controllability are improved, but system complexity and management overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidmanagement overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements local quality by assigning specific digital certificates to individual users and resources, enabling fine-grained access control where each user's proxy server is authenticated based on their unique certificate, and each resource is authenticated based on its own certificate. This approach improves security through personalized authentication while managing complexity by handling credentials locally at each endpoint rather than maintaining complex centralized access lists.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4044550A1A proxy and a communication system comprising said proxy
Publication Date: 2022.08.17 XERTIFIED AB
  • EP4044550A1 patent drawingFigure 1
  • EP4044550A1 patent drawingFigure 2
  • EP4044550A1 patent drawingFigure 3

AI summary

A proxy (150) is provided. The proxy is configured to access an authorization module (250). The authorization module is arranged to provide a unique user digital identity. The unique user digital identity is linked to a user (300). The proxy is configured for digital certificate authentication. The proxy is further configured to provide access for the user to at least one of a data network (110) and at least one resource (130) based on at least one of the unique user digital identity and digital certificate authentication. The proxy is further configured to access a management system (510). The management system is configured to control access for the user to at least one of the data network and the at least one resource based on the unique user digital identity.