Reverse Proxy Masking Address for Secure Temporary Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for secure access to data on remote servers via electronic addresses do not effectively limit access time or prevent unauthorized access to personal information and multimedia content, especially in Voice over IP communications.

Innovation Solution

A method and system that utilize a reverse proxy server to create a masking electronic address with a limited validity period, controlling access to data on a remote content server, and an OIP application server to manage this association, ensuring secure and temporary access by masking the real electronic address and verifying user authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a reverse proxy server is used to mask the content server address, then security against direct attacks is improved, but permanent access to data remains possible allowing copying and unauthorized use

Engineering Contradiction:
ImprovesecurityVSAvoidaccess duration
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The reverse proxy server dynamically creates and destroys the masking electronic address based on session events. The association between the masking address and real content server address is temporary, created when a communication session is initiated and destroyed when the session ends, transforming the static permanent access into dynamic temporary access.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system preliminarily creates the masking electronic address and its association with the real content server address before the actual data access occurs. This preparation is done in advance when the communication session is initiated, ensuring security is in place before any data transmission happens.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If the electronic address is made permanently accessible, then ease of access to multimedia resources is improved, but unauthorized access and data copying become possible

Engineering Contradiction:
Improveaccess easeVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The masking electronic address acts as an intermediary between the terminal and the real content server address. It provides ease of access by giving a simple address to use, while simultaneously protecting against unauthorized access by hiding the real server address and enabling temporary controlled access only.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the masking electronic address is deactivated after a predetermined time period, then security is improved by limiting access window, but access availability is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidaccess availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system changes the temporal parameter of the masking electronic address from permanent to temporary. By setting a predetermined time period for the address validity, it balances security (limiting the access window) with availability (providing sufficient time for legitimate communication during that window).

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8949966B2Method and system for protecting a service access link
Publication Date: 2015.02.03 ORANGE SA
  • US8949966B2 patent drawing
  • US8949966B2 patent drawing
  • US8949966B2 patent drawing

AI summary

A method and a system for securing access to data stored in a remote content server (41), and corresponding to personal multimedia data of a user (A) for example, which data is accessible by another user (B) from a terminal (2) by means of an electronic address. In order to avoid direct and extended access by the user (B) to the data of a user (A), the system also includes an application server (5) for creating an electronic masking address having a determined validity period and for sending to an inverse proxy server (6) said electronic masking address assigned to the electronic address of the remote content server (41). In this way, the terminal (2) of the user (B) temporarily accesses data stored in the remote content server (41) via the inverse proxy server (6) by means of the electronic masking address.