Universal Proxy Third-Party Authentication Cloud Edge Fog

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face inconvenience in accessing cloud, fog, and edge communication services due to the need for separate accounts and different communication protocols, making it difficult to switch between these services seamlessly.

Innovation Solution

A communication system with a universal proxy that performs third-party authentication between home and foreign service ends, using a control module and operation modules to communicate through cloud, edge, and fog relays, supporting various protocols like OIDC and 802.1x, allowing a single account to access multiple services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users use separate accounts for cloud, fog, and edge services, then each service can be accessed securely, but user convenience and ease of operation deteriorate due to the need to switch accounts

Engineering Contradiction:
Improveservice access securityVSAvoidaccount switching convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a universal proxy that serves multiple authentication functions simultaneously - it can authenticate users against cloud, fog, and edge services using a single account. The proxy acts as a universal gateway that handles different authentication protocols (OIDC, 802.1x) and service types through one unified interface, eliminating the need for separate accounts while maintaining security through centralized credential management

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The universal proxy serves as an intermediary between the user and multiple service providers. It mediates the authentication process by receiving authentication requests, translating between different protocols, and coordinating with various service endpoints. This intermediary approach allows users to interact with a single system while the proxy handles the complexity of multiple service authentications in the background

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If cloud, fog, and edge services use different communication protocols, then each service can optimize for its specific requirements, but system complexity and difficulty of integration increase

Engineering Contradiction:
Improveprotocol optimization capabilityVSAvoidcommunication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The universal proxy dynamically changes communication parameters including protocol type, authentication method, and transmission format based on the target service. It can switch between OIDC for cloud services, 802.1x for edge services, and other protocols as needed. This parameter adaptation allows the system to optimize for each service's requirements while presenting a unified interface to users, managing complexity through automated protocol selection and translation

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11502987B2Communication system and method for performing third-party authentication between home service end and foreign service end
Publication Date: 2022.11.15 NAT YANG MING CHIAO TUNG UNIV
  • US11502987B2 patent drawing
  • US11502987B2 patent drawing
  • US11502987B2 patent drawing

AI summary

A communication system performs a third-party authentication between a home service end and a foreign service end, wherein the home service end and the foreign service end each have a type of a cloud, an edge or a fog. The communication system includes a control module and a plurality of operation modules that are configured in a universal proxy, wherein the universal proxy performs communication with a cloud through a cloud relay, performs communication with an edge through an edge relay, and performs communication with a fog through a fog relay. The control module selects two of the operation modules to perform the third-party authentication according to the types of the home service end and the foreign service end.