Authentication via Client Health Enforcement Framework

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network authentication processes are inefficient as they require separate mechanisms for authentication and client health enforcement, leading to complexity and the need for frequent protocol changes, while also lacking flexibility to operate across different network transport layers.

Innovation Solution

Integrating authentication functions into a client health enforcement framework, allowing authentication information to be formatted as part of a statement of health, which is validated by the health policy server, thereby simplifying authentication methods and enabling them to operate independently of the enforcement mechanism and network transport protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate authentication mechanisms are used alongside client health enforcement, then authentication can be performed, but system complexity increases and requires frequent protocol changes

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines authentication functionality with the existing client health enforcement framework by integrating an authentication component into the health policy server. This allows authentication information to be exchanged through the same infrastructure used for health checks, eliminating the need for separate authentication protocols and reducing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The health policy server is enhanced to perform multiple functions: both traditional health enforcement and authentication. By making the server universal and capable of handling both authentication requests and health policy evaluations, the system eliminates the need for dedicated authentication mechanisms while maintaining both capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate authentication mechanisms are used, then authentication can be performed, but the system requires frequent protocol changes

Engineering Contradiction:
Improveauthentication capabilityVSAvoidprotocol stability
Core Design Contradiction:
ReliabilityVSDuration of action of stationary object

Solution Approach 1:

By merging authentication with the established health enforcement protocol, the system leverages the stability and maturity of existing health check protocols. This integration allows authentication to benefit from the proven reliability and stability of the health enforcement framework, reducing the need for frequent protocol changes.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If traditional authentication mechanisms are used, then authentication can be performed, but they lack flexibility to operate across different network transport layers

Engineering Contradiction:
Improveauthentication capabilityVSAvoidtransport layer flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The integrated authentication component is designed to work within the universal health enforcement framework, which already operates across multiple network transport layers. This allows the authentication mechanism to inherit the transport layer flexibility of the health enforcement system, enabling it to operate seamlessly across different network protocols and layers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If separate authentication and health enforcement mechanisms are used, then both functions can be performed, but the authorization process becomes inefficient

Engineering Contradiction:
Improveauthentication and health enforcement capabilityVSAvoidauthorization efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges authentication and health enforcement into a single integrated process within the health policy server. This consolidation allows both authentication and health evaluation to be performed in a unified authorization workflow, eliminating the need for separate processing steps and improving overall authorization efficiency.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2321928B1Authentication in a network using client health enforcement framework
Publication Date: 2019.05.15 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP2321928B1 patent drawingFigure 1
  • EP2321928B1 patent drawingFigure 2
  • EP2321928B1 patent drawingFigure 3A~3D

AI summary

A network with authentication implemented using a client health enforcement framework. The framework is adapted to receive plug-ins on clients that generate health information. Corresponding plug-ins on a server validate that health information. Based on the results of validation, the server may instruct the client to remediate or may authorize an underlying access enforcement mechanism to allow access. A client plug-in that generates authentication information formatted as a statement of health may be incorporated into such a framework. Similarly, on the server, a validator to determine, based on the authentication information, whether the client should be granted network access can be incorporated into the framework. Authentication can be simply applied or modified by changing the plug-ins, while relying on the framework to interface with an enforcement mechanism. Functions of the health enforcement framework can be leveraged to provide authentication-based functionality, such as revoking authorized access after a period of user inactivity or in response to a user command.