Relay Device Segmented Authentication for Financial Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access management systems for privileged IDs in business information systems face challenges in accurately managing and authenticating access, particularly in scenarios where incorrect passwords can lead to unauthorized access and lack of duty division and operation log acquisition.
Innovation Solution
A relay device that receives user IDs and passwords from client terminals, establishes sessions with servers without initial authentication, and uses separate confirmation processes to validate the user ID and password combinations through different protocols or interfaces, ensuring correct authentication before establishing a session.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the gateway server performs user authentication based on user ID and password before relaying connection to the destination server, then access management is improved, but the system cannot prevent unauthorized access when incorrect passwords are entered and displayed on login screens
Solution Approach 1:
The patent segments the authentication process into two distinct phases: (1) initial authentication phase where the gateway server verifies user ID and password before establishing relay connection, and (2) destination server authentication phase where the destination server independently verifies credentials. This segmentation ensures that even if the first phase is bypassed or fails, the second phase still provides security protection, thereby resolving the contradiction between maintaining access management reliability and preventing unauthorized access.
Solution Approach 2:
The patent implements preliminary authentication action by the gateway server before relaying connections, where user credentials are verified in advance. Additionally, the destination server performs preliminary verification by checking if the user ID and password combination is valid before allowing access. This preliminary action ensures that unauthorized access attempts are blocked before they can compromise the system, addressing the security vulnerability where incorrect passwords displayed on login screens could lead to unauthorized access.
2Ease of operation
If the gateway server manages privileged ID authentication, then access control is improved, but operation logs cannot be acquired and duties are not divided
Solution Approach 1:
The patent introduces the gateway server as an intermediary component between client terminals and destination servers. The gateway server relays authentication requests and connection requests, maintaining detailed logs of all authentication attempts and connection activities. This intermediary role enables comprehensive operation log acquisition while preserving duty division, as the gateway server handles authentication logging separately from the destination server's operational functions, thereby resolving the contradiction between ease of access control management and operation log acquisition.
3Device complexity
If the gateway server relays connection without initial authentication, then system simplicity is improved, but security is worsened allowing unauthorized access
Solution Approach 1:
The patent implements a dynamic authentication approach where the gateway server initially relays connections with minimal authentication overhead, maintaining system simplicity. However, the destination server dynamically performs additional verification by checking credential validity before granting access. This dynamic multi-layered authentication system maintains simplicity at the gateway level while ensuring security at the destination level, resolving the contradiction between device complexity and security reliability.
Data Source
AI summary
Provided are a relay device capable of appropriate access management, a relay method, and a program. The relay device (10): receives a user ID and password for logging on to a server (a desired server) in a financial information system (41), a client information system (42), or an inventory management system (43), on the basis of a connection request from a work terminal (20) (client terminal); and relays a connection without performing user verification using the received user ID and password, when establishing a session with the desired server. The relay device connects to the server using processing that differs from the processing for relaying this connection, confirms the appropriateness of the received user ID and password combination, and establishes a session with the desired server if the user ID and password combination is confirmed to be correct.


