Relay Device Segmented Authentication for Financial Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access management systems for privileged IDs in business information systems face challenges in accurately managing and authenticating access, particularly in scenarios where incorrect passwords can lead to unauthorized access and lack of duty division and operation log acquisition.

Innovation Solution

A relay device that receives user IDs and passwords from client terminals, establishes sessions with servers without initial authentication, and uses separate confirmation processes to validate the user ID and password combinations through different protocols or interfaces, ensuring correct authentication before establishing a session.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the gateway server performs user authentication based on user ID and password before relaying connection to the destination server, then access management is improved, but the system cannot prevent unauthorized access when incorrect passwords are entered and displayed on login screens

Engineering Contradiction:
Improveaccess management reliabilityVSAvoidunauthorized access risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the authentication process into two distinct phases: (1) initial authentication phase where the gateway server verifies user ID and password before establishing relay connection, and (2) destination server authentication phase where the destination server independently verifies credentials. This segmentation ensures that even if the first phase is bypassed or fails, the second phase still provides security protection, thereby resolving the contradiction between maintaining access management reliability and preventing unauthorized access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary authentication action by the gateway server before relaying connections, where user credentials are verified in advance. Additionally, the destination server performs preliminary verification by checking if the user ID and password combination is valid before allowing access. This preliminary action ensures that unauthorized access attempts are blocked before they can compromise the system, addressing the security vulnerability where incorrect passwords displayed on login screens could lead to unauthorized access.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If the gateway server manages privileged ID authentication, then access control is improved, but operation logs cannot be acquired and duties are not divided

Engineering Contradiction:
Improveaccess control managementVSAvoidoperation log acquisition
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent introduces the gateway server as an intermediary component between client terminals and destination servers. The gateway server relays authentication requests and connection requests, maintaining detailed logs of all authentication attempts and connection activities. This intermediary role enables comprehensive operation log acquisition while preserving duty division, as the gateway server handles authentication logging separately from the destination server's operational functions, thereby resolving the contradiction between ease of access control management and operation log acquisition.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If the gateway server relays connection without initial authentication, then system simplicity is improved, but security is worsened allowing unauthorized access

Engineering Contradiction:
Improveauthentication process complexityVSAvoidsecurity reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements a dynamic authentication approach where the gateway server initially relays connections with minimal authentication overhead, maintaining system simplicity. However, the destination server dynamically performs additional verification by checking credential validity before granting access. This dynamic multi-layered authentication system maintains simplicity at the gateway level while ensuring security at the destination level, resolving the contradiction between device complexity and security reliability.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9887986B2Relay device, relay method, and program
Publication Date: 2018.02.06 NOMURA RESEARCH INSTITUTE
  • US9887986B2 patent drawing
  • US9887986B2 patent drawing
  • US9887986B2 patent drawing

AI summary

Provided are a relay device capable of appropriate access management, a relay method, and a program. The relay device (10): receives a user ID and password for logging on to a server (a desired server) in a financial information system (41), a client information system (42), or an inventory management system (43), on the basis of a connection request from a work terminal (20) (client terminal); and relays a connection without performing user verification using the received user ID and password, when establishing a session with the desired server. The relay device connects to the server using processing that differs from the processing for relaying this connection, confirms the appropriateness of the received user ID and password combination, and establishes a session with the desired server if the user ID and password combination is confirmed to be correct.