Proxy Server Smart Key Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security methods are difficult to operate, incompatible, and unsafe, particularly due to the need for complex installations and limitations in compatibility across different browsers, leading to vulnerabilities in authentication processes.

Innovation Solution

A method and system that utilizes a proxy server in the customer terminal to parse protocol messages, determine the inclusion of critical information, and interact with a smart key device for user confirmation and signature, ensuring secure communication between the customer terminal, smart key device, and application server without requiring extensive user intervention or browser-specific plugins.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital certificate or USB Key is used for network security, then security level is improved, but operation complexity increases and compatibility decreases

Engineering Contradiction:
Improvenetwork securityVSAvoidoperation complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the critical security verification function from the complex USB Key authentication process. The proxy server extracts and verifies essential information elements from protocol messages, performing security checks without requiring the full USB Key infrastructure. This separates the core security verification function from the cumbersome authentication hardware requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The proxy server implements a universal security verification mechanism that works across different browsers and network applications without requiring browser-specific plugins or specialized hardware. The verification process handles multiple protocol types (HTTP, HTTPS, FTP, etc.) and various security scenarios through a single unified approach, making the system universally applicable.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If USB Key with plugs and software is installed for signature operation, then security is improved, but device complexity and installation difficulty increase

Engineering Contradiction:
Improveauthentication securityVSAvoidinstallation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The proxy server performs security verification automatically without requiring user intervention for plugin installation or configuration. The system self-configures by intercepting protocol messages and automatically extracting verification information. Users simply need to input their credentials, while the proxy server handles all complex security verification processes in the background.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The proxy server acts as an intermediary between the client application and the security verification system. Instead of requiring direct interaction with complex USB Key drivers and plugins, the proxy server mediates the authentication process by intercepting and verifying protocol messages, simplifying the user interface while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If browser-specific plugins are used for security authentication, then security functionality is achieved, but adaptability across different browsers decreases

Engineering Contradiction:
Improveauthentication functionalityVSAvoidbrowser compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the security verification process into independent protocol message interception and verification steps. Instead of relying on browser-specific integrated authentication mechanisms, the system breaks down the authentication process into discrete protocol messages that can be intercepted and verified independently. This segmentation allows the same verification logic to be applied across different browser environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The proxy server implements a universal security verification mechanism that works across different browsers and network applications without requiring browser-specific plugins or specialized hardware. The verification process handles multiple protocol types (HTTP, HTTPS, FTP, etc.) and various security scenarios through a single unified approach, making the system universally applicable.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If critical information is transmitted in protocol messages, then security verification is enabled, but information security risk increases

Engineering Contradiction:
Improvesecurity verification capabilityVSAvoidinformation security risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The proxy server performs preliminary verification of critical information elements before they are fully processed or transmitted. By intercepting protocol messages early in the transmission process and verifying essential elements (such as account numbers, transaction amounts, and recipient information) before completion, the system enables security verification while minimizing the exposure of sensitive information.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The proxy server extracts only the essential verification information elements from protocol messages rather than handling or storing complete sensitive data. The verification process focuses on extracting and checking specific critical fields (like account identifiers and transaction parameters) without exposing or retaining the full scope of sensitive information, thereby reducing security risks.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8719915B2Method for improving network application security and the system thereof
Publication Date: 2014.05.06 FEITIAN TECHNOLOGIES CO LTD
  • US8719915B2 patent drawing
  • US8719915B2 patent drawing
  • US8719915B2 patent drawing

AI summary

A method for improving network application security and the system thereof are disclosed in the invention, relating to the field of information security. The method includes: a proxy server in a customer terminal host receives a protocol message, generated and sent by the customer terminal software according to the information input by a user, and obtains the protocol content after parsing the protocol message, and determines whether critical information is included in the protocol content, if it is, the server sends the protocol content to the smart key device; and the smart key device obtains the critical information by parsing it and sends it to the user, and after a confirmation information is gotten from the user, the smart key device signs the protocol content and sends the signature result to the server; and then the server generates a new protocol message to an application server according to the signature result and the protocol content; after an error confirmation or no confirmation is received within a predetermined time period by the user, the smart key device performs the exception handling. The system includes a smart key device and a proxy server in the customer terminal host. The invention improves network application security on the premise of no change to the customer terminal, and it is usable and compatible.