Relay Device Protocol Conversion for Cloud Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud service systems face challenges in data exchange and authentication due to differences in resource capabilities and specifications between client devices and cloud service providing devices, leading to inefficiencies and security risks in data relay processes.
Innovation Solution
A relay device equipped with an identification information acquisition unit, a privilege information acquisition unit, and a controller that acquires and stores user identification and privilege information, enabling it to perform communication processing by converting data languages and protocols to facilitate seamless data exchange between client devices and cloud service providing devices without holding user credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If client devices directly communicate with cloud service providing devices, then data exchange can occur, but security risks increase due to exposure of user credentials and authentication information
Solution Approach 1:
The patent introduces a relay device as an intermediary between client devices and cloud service providing devices. The relay device acquires privilege information from cloud service providers and stores it in association with user identification information. When relaying service processing requests, the relay device uses this stored privilege information instead of requiring client devices to directly present credentials to cloud services, thereby enhancing security while maintaining communication functionality.
2Reliability
If relay devices store user credentials for authentication, then secure communication is enabled, but the risk of personal information leakage increases
Solution Approach 1:
The patent extracts and separates the privilege information acquisition function from the client device, placing it in the relay device. The relay device acquires privilege information from cloud service providing devices and stores it in association with user identification information. This extraction allows the system to maintain authentication capability while reducing the exposure of sensitive credentials, as the relay device handles privilege information management centrally rather than requiring each client device to store and manage credentials.
3Adaptability or versatility
If client devices with different resource capabilities communicate with cloud services, then service accessibility is improved, but communication efficiency decreases due to protocol and specification differences
Solution Approach 1:
The patent implements a universal relay device that can handle communications with multiple different cloud service providing devices. The relay device acquires and stores privilege information from various cloud services in association with user identification information, creating a universal authentication mechanism. This allows client devices with diverse resource capabilities to access different cloud services through a single relay interface, improving service accessibility while maintaining communication efficiency through standardized privilege information management.
Data Source
AI summary
A relay device includes an identification information acquisition unit, a privilege information acquisition unit, a memory, and a controller. The identification information acquisition unit acquires user identification information for allowing the relay device to identify a user. The privilege information acquisition unit acquires privilege information indicating that access to the service providing device is authorized from a service providing device which provides a service to a client device used by the user. The memory stores the user identification information and the privilege information in association with each other. Upon receiving a service processing request made to the service providing device and transmitted together with the user identification information from the client device, the controller controls the service providing device to perform communication processing corresponding to the service processing request using the privilege information stored in association with the user identification information.


