Relay Apparatus On-Demand Credential Retrieval
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing relay systems face challenges in accessing service providing apparatuses when tokens are not registered or have expired, leading to user inconvenience and potential security risks due to temporary storage of credit information.
Innovation Solution
A relay apparatus with a memory for storing right information, a first retrieval unit for identifying user credentials, and an access unit that uses retrieved identification information to access service providing apparatuses instead of invalid tokens, allowing seamless service access and reducing security risks by deleting credit information upon power interruption or completion of processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the relay apparatus stores right information (tokens) to access service providing apparatuses, then access reliability is improved, but security risk increases due to potential storage of credit information
Solution Approach 1:
The patent extracts the harmful aspect (permanent storage of credit information) while retaining the useful aspect (access capability). The relay apparatus retrieves identification information only when needed for accessing service providing apparatuses, rather than storing it permanently. This is achieved by the retrieval unit that obtains identification information from the service providing apparatus on-demand, eliminating the security risk of stored credentials while maintaining access reliability.
Solution Approach 2:
The patent implements dynamic access where the relay apparatus adapts its behavior based on the validity of stored right information. When tokens are expired or invalid, the system dynamically switches to retrieving fresh identification information. This dynamic approach ensures continuous access reliability while minimizing security risks by only storing information temporarily and validating it before use.
2Reliability
If the relay apparatus requires token registration for accessing service providing apparatuses, then access security is improved, but ease of operation deteriorates due to additional registration steps
Solution Approach 1:
The patent implements self-service functionality where the relay apparatus automatically manages access credentials without requiring manual user intervention for token registration. The retrieval unit automatically obtains identification information from service providing apparatuses when needed, and the determination unit automatically validates tokens. This automated credential management maintains security while eliminating the operational burden of manual token registration on users.
Solution Approach 2:
The patent performs preliminary actions by pre-configuring the relay apparatus with retrieval capabilities that can obtain identification information on-demand. Instead of requiring users to manually register tokens beforehand, the system is pre-equipped with the ability to automatically retrieve and validate credentials when access is needed, thereby maintaining security without compromising ease of operation.
3Speed
If the relay apparatus uses stored right information for access, then access speed is improved, but adaptability worsens when tokens expire or are invalid
Solution Approach 1:
The patent implements a feedback mechanism where the determination unit validates stored right information before use and provides feedback on its validity. When validation fails (expired or invalid tokens), the system receives feedback and automatically switches to the retrieval unit to obtain fresh identification information. This feedback loop ensures both fast access (when tokens are valid) and high adaptability (when tokens need renewal), resolving the contradiction between speed and adaptability.
Solution Approach 2:
The patent creates a dynamic access system that adapts its behavior based on the validity status of stored right information. The system smoothly transitions between using stored tokens (for speed) and retrieving fresh credentials (for adaptability) based on real-time validation results. This dynamic switching mechanism maintains access speed when possible while ensuring adaptability when conditions change, such as token expiration.
Data Source
AI summary
A relay apparatus includes a memory that stores right information indicating a right to access a service providing apparatus, a first retrieval unit that retrieves, from a client apparatus, identification information of a user registered in the service providing apparatus that is a target of an access request from the client apparatus, and an access unit that accesses the service providing apparatus as the target using the identification information retrieved by the first retrieval unit instead of the right information stored on the memory if the right information to access the service providing apparatus as the target is not valid.


