Proxy Server Smart Key Network Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security methods are difficult to operate, incompatible, and unsafe, particularly due to the need for complex installations and limitations in compatibility across different browsers, leading to vulnerabilities in authentication processes.
Innovation Solution
A method and system that utilizes a proxy server in the customer terminal to parse protocol messages, determine the inclusion of critical information, and interact with a smart key device for user confirmation and signature, ensuring secure communication between the customer terminal, smart key device, and application server without requiring extensive user intervention or browser-specific plugins.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital certificate or USB Key is used for network security, then security level is improved, but operation complexity increases and compatibility decreases
Solution Approach 1:
The patent extracts the critical security verification function from the complex USB Key authentication process. The proxy server extracts and verifies essential information elements from protocol messages, performing security checks without requiring the full USB Key infrastructure. This separates the core security verification function from the cumbersome authentication hardware requirements.
Solution Approach 2:
The proxy server implements a universal security verification mechanism that works across different browsers and network applications without requiring browser-specific plugins or specialized hardware. The verification process handles multiple protocol types (HTTP, HTTPS, FTP, etc.) and various security scenarios through a single unified approach, making the system universally applicable.
2Reliability
If USB Key with plugs and software is installed for signature operation, then security is improved, but device complexity and installation difficulty increase
Solution Approach 1:
The proxy server performs security verification automatically without requiring user intervention for plugin installation or configuration. The system self-configures by intercepting protocol messages and automatically extracting verification information. Users simply need to input their credentials, while the proxy server handles all complex security verification processes in the background.
Solution Approach 2:
The proxy server acts as an intermediary between the client application and the security verification system. Instead of requiring direct interaction with complex USB Key drivers and plugins, the proxy server mediates the authentication process by intercepting and verifying protocol messages, simplifying the user interface while maintaining security.
3Reliability
If browser-specific plugins are used for security authentication, then security functionality is achieved, but adaptability across different browsers decreases
Solution Approach 1:
The patent segments the security verification process into independent protocol message interception and verification steps. Instead of relying on browser-specific integrated authentication mechanisms, the system breaks down the authentication process into discrete protocol messages that can be intercepted and verified independently. This segmentation allows the same verification logic to be applied across different browser environments.
Solution Approach 2:
The proxy server implements a universal security verification mechanism that works across different browsers and network applications without requiring browser-specific plugins or specialized hardware. The verification process handles multiple protocol types (HTTP, HTTPS, FTP, etc.) and various security scenarios through a single unified approach, making the system universally applicable.
4Reliability
If critical information is transmitted in protocol messages, then security verification is enabled, but information security risk increases
Solution Approach 1:
The proxy server performs preliminary verification of critical information elements before they are fully processed or transmitted. By intercepting protocol messages early in the transmission process and verifying essential elements (such as account numbers, transaction amounts, and recipient information) before completion, the system enables security verification while minimizing the exposure of sensitive information.
Solution Approach 2:
The proxy server extracts only the essential verification information elements from protocol messages rather than handling or storing complete sensitive data. The verification process focuses on extracting and checking specific critical fields (like account identifiers and transaction parameters) without exposing or retaining the full scope of sensitive information, thereby reducing security risks.
Data Source
AI summary
A method for improving network application security and the system thereof are disclosed in the invention, relating to the field of information security. The method includes: a proxy server in a customer terminal host receives a protocol message, generated and sent by the customer terminal software according to the information input by a user, and obtains the protocol content after parsing the protocol message, and determines whether critical information is included in the protocol content, if it is, the server sends the protocol content to the smart key device; and the smart key device obtains the critical information by parsing it and sends it to the user, and after a confirmation information is gotten from the user, the smart key device signs the protocol content and sends the signature result to the server; and then the server generates a new protocol message to an application server according to the signature result and the protocol content; after an error confirmation or no confirmation is received within a predetermined time period by the user, the smart key device performs the exception handling. The system includes a smart key device and a proxy server in the customer terminal host. The invention improves network application security on the premise of no change to the customer terminal, and it is usable and compatible.


