Active Directory Bridge for External Network Resource Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for connecting external network resources to an internal enterprise network, such as VPNs, are complex and impractical, especially for devices like IoT devices and cloud-hosted resources, leading to security issues and management challenges due to limitations in authentication and firewall configurations.

Innovation Solution

The Active Directory Bridge (AD Bridge) system, comprising an AD Bridge Gateway, Gatekeeper, and Agent, enables registration, representation, and management of external resources within the internal network through bi-directional communication and Group Policy Objects (GPOs), allowing secure access and centralized management without the need for VPNs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VPN is used to connect external resources to internal network, then secure communication is achieved, but device complexity and configuration maintenance increase significantly

Engineering Contradiction:
Improvesecure communicationVSAvoidconfiguration and maintenance complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an Active Directory Bridge as an intermediary component that sits between external resources and the internal Active Directory domain. This bridge handles authentication and communication protocols, allowing external resources to access internal resources without requiring full VPN client installation or complex VPN configuration on each device. The bridge mediates the connection by translating authentication requests and managing the tunneling protocol centrally.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The Active Directory Bridge serves multiple functions: it acts as an authentication server, a protocol translator, a tunneling endpoint, and a policy enforcement point. By consolidating these functions into a single universal component, the system eliminates the need for separate VPN client software and configuration on each external device, thereby reducing device complexity while maintaining secure communication.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If VPN is deployed for each external resource, then secure access is provided, but the number of VPN setups increases leading to impractical installation and use

Engineering Contradiction:
Improvesecure accessVSAvoidinstallation and use practicality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The Active Directory Bridge acts as a centralized intermediary that handles all authentication and connection management for external resources. Instead of requiring individual VPN setups on each external device, the bridge consolidates these functions, allowing external resources to connect through a standardized interface without complex installation procedures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables external resources to self-register and self-authenticate with the Active Directory Bridge without requiring manual VPN configuration. The bridge automatically manages authentication credentials, establishes connections, and enforces security policies, eliminating the need for users or administrators to manually configure VPN settings on each device.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If traditional network connection methods are used, then external resources can access internal network, but authentication and firewall configurations create security issues and management challenges

Engineering Contradiction:
Improvenetwork access capabilityVSAvoidsecurity and management
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The Active Directory Bridge serves as a security intermediary that sits between external resources and the internal network. It centrally manages authentication by validating credentials against Active Directory, enforces firewall policies, and controls access permissions. This centralized approach eliminates the need for complex firewall rules on each external device and ensures consistent security enforcement across all connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the Active Directory Bridge continuously monitors authentication attempts, connection status, and policy compliance. It dynamically adjusts access permissions and security policies based on real-time conditions, such as user credentials, device state, and network context, thereby maintaining security while enabling versatile access.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10498583B1Active directory bridging of external network resources
Publication Date: 2019.12.03 FULL ARMOR CORP
  • US10498583B1 patent drawing
  • US10498583B1 patent drawing
  • US10498583B1 patent drawing

AI summary

An Active Directory Bridge (AD Bridge) provides the ability to register, represent, and manage external network resources on an internal network. The external network resources may include cloud resources, such as Internet of Things (IoT) devices, Software-as-a-Service applications (SaaS apps), cloud-hosted virtual machines (VMs), cloud-hosted computers, and other networked cloud resources. The external network resources may be unable to communicate directly with or join the internal network due to various network connection obstacles. The AD Bridge includes an AD Bridge Gateway, an AD Bridge Gatekeeper, and an AD Bridge Agent. The AD Bridge Agent resides on each external network resource, and provides the connection of the host external network resource through the AD Bridge Gatekeeper and through the AD Bridge Gateway to the internal network. The AD Bridge provides the ability to register, represent, and manage these external network resources on an internal network.