Portable Secure Object Offloading Server Load

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current server systems face high loads and security challenges due to limited bandwidth and computational power, especially under high-demand scenarios like online tax declarations and massively multiplayer games, where delegating computations to untrustworthy clients is risky.

Innovation Solution

Implementing a Secure Portable Object (SPO) on the client side with data processing and storage means, which reduces server load by handling part of the server processing and storage, and ensures security through authentication, personalization, and timestamping, establishing a trusted encrypted link with the server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Power

If distributed computing is used to reduce server load, then server computational power and bandwidth requirements are reduced, but security and trustworthiness of the service deteriorate

Engineering Contradiction:
Improveserver computational powerVSAvoidservice security
Core Design Contradiction:
PowerVSReliability

Solution Approach 1:

A portable secure object (SPO) is introduced as an intermediary between the client and server. The SPO contains a trusted execution environment that securely hosts server extension code, acting as a mediator that allows distributed computing while maintaining security. The SPO verifies the integrity of the portable object and ensures that server extensions execute in a controlled, secure manner, thus resolving the contradiction between distributing computation and maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The server functionality is segmented into core server components and extension components. The extension components are deployed to portable objects on client sides, while the core server maintains centralized control and security-critical functions. This segmentation allows computation to be distributed to reduce server load while keeping security-critical operations centralized, thus resolving the contradiction between distributed computing and service security.

Inventive Principle:
Principle #1Segmentation

2Productivity

If more client requests are handled simultaneously, then service coverage and productivity increase, but server load and connection requirements increase

Engineering Contradiction:
Improveservice throughputVSAvoidserver connection load
Core Design Contradiction:
ProductivityVSPower

Solution Approach 1:

Client-side portable objects with server extensions perform local processing of requests, reducing the need for continuous server involvement. The portable objects can handle routine operations locally, only contacting the server when necessary for authentication or complex operations. This self-service capability increases service throughput while reducing server connection load, as the server doesn't need to handle every client request directly.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If server storage is used to store user data, then data accessibility and service functionality are improved, but server bandwidth and storage requirements increase

Engineering Contradiction:
Improvedata accessibilityVSAvoidserver storage capacity
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

User data is stored locally in the portable objects on client sides rather than centrally on the server. Each portable object maintains its own data storage, allowing users to access their data locally without requiring server bandwidth. The server only needs to provide initial data distribution and periodic updates, significantly reducing server storage requirements while maintaining data accessibility through local storage.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP1894385B1Method and system using a portable object for providing an extension to a server
Publication Date: 2018.08.01 THALES DIS FRANCE SA
  • EP1894385B1 patent drawingFigure 1~2
  • EP1894385B1 patent drawingFigure 3~4
  • EP1894385B1 patent drawingFigure 5~6

AI summary

The present invention concerns a method and a system for extending a server connected with at least one client(s), characterized in that it consists in providing said extension on the client side by means of a portable object which is connected to said client and which performs at least one of the server's operation(s) in part or entirely.