Security Server Intermediary for Web Data Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional SSL systems require certificates to be installed on service providing servers, leading to increased server capacity and management complexity for web-hosting and application server providers.
Innovation Solution
A security server intermediates security data transmission/reception between user terminals and service providing servers, generating session keys, encoding security data, and decoding it upon request, thereby reducing the need for certificate installation on the service providing server and optimizing data bandwidth.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificates are installed on the service providing server to enable secure data transmission, then security is improved, but server capacity and management complexity increase
Solution Approach 1:
The patent introduces a security server as an intermediary component between the user terminal and the service providing server. The security server handles certificate installation and security management, allowing the service providing server to maintain security functionality without bearing the burden of certificate management. This mediator approach resolves the contradiction by separating security functions from the main service server, thus improving security while avoiding increased server capacity requirements.
2Reliability
If certificates are installed on the service providing server to enable secure data transmission, then security is improved, but management complexity increases
Solution Approach 1:
The security server acts as a dedicated intermediary for certificate management and security operations. By centralizing these functions in a specialized security server, the patent simplifies the management burden on service providing servers. The security server handles all certificate-related operations, making security management more straightforward and reducing operational complexity for web-hosting and application server providers.
Solution Approach 2:
The security server provides self-service capabilities for security data transmission and reception. It automatically manages certificates, generates session keys, and handles encoding/decoding operations without requiring manual intervention on the service providing server. This self-service mechanism reduces management complexity while maintaining security standards.
3Reliability
If all data in web pages are encoded to ensure security, then security is improved, but data bandwidth increases
Solution Approach 1:
The patent applies encoding selectively only to security data fields within web pages rather than encoding all data. The security server identifies and encodes only the necessary security-related portions of data transmissions, leaving non-security data in plaintext format. This local quality approach maintains security for sensitive information while significantly reducing the overall bandwidth consumption compared to full-page encoding.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
There are provided a security server for intermediating transmission/reception of security data between a service providing server and a user terminal, a security data transmission/reception system and a method. In order to intermediate the transmission/reception of security data between the service providing server and the user terminal, the security server may generate a session key corresponding to a secret key provided from a user terminal, receive security data together with the session key from a security data transmitter, encode the security data with the secret key corresponding to the session key, store the encoded security data, provide a data encryption key to the security data transmitter, decode the encoded security data with the secret key corresponding to the session key when the session key is received together with a security data request key from a security data receiver, and provide the decoded security data to the security data receiver.