Authentication Proxy Server Read-Only Cache
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems face challenges in securely managing authentication requests across non-secure networks, particularly in preventing eavesdropping and replay attacks, and in efficiently filtering and processing authentication requests to ensure only authorized access.
Innovation Solution
An authentication proxy server is deployed between a wide area network and a local area network to process and filter authentication requests, using Kerberos or other protocols, and implementing both hardware and user authentication mechanisms to provide secure evidence of authentication, while minimizing sensitive data storage to limit potential attacker advantages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an authentication server is deployed between wide area network and local area network to process authentication requests, then network security is improved, but the server may become a target for attacks and potential compromise
Solution Approach 1:
The patent introduces a read-only domain services object cache as an intermediary component between the authentication server and the credential server. This cache stores authentication data in read-only format, allowing the server to respond to authentication requests without exposing writable sensitive data, thus reducing the impact of potential compromise while maintaining security functionality.
Solution Approach 2:
The patent extracts sensitive writable data from the authentication server by implementing a read-only domain services object cache. The cache contains only the necessary authentication information in read-only format, separating the authentication functionality from the sensitive data storage, thereby reducing the server's attack surface while maintaining authentication capabilities.
2Ease of operation
If the server stores domain services objects for authentication processing, then authentication functionality is improved, but sensitive data storage increases potential attacker advantage
Solution Approach 1:
The patent implements read-only domain services objects that can be easily regenerated from the credential server. These objects are treated as disposable - when compromised or expired, they can be refreshed without requiring changes to the underlying credential server or sensitive data storage, thus maintaining authentication functionality while minimizing the impact of compromise.
Solution Approach 2:
The read-only domain services object cache acts as an intermediary layer between the authentication server and the credential server. It provides the necessary authentication data in read-only format, allowing the server to process authentication requests without storing or exposing sensitive writable data, thus reducing attacker advantage while maintaining operational capability.
3Reliability
If the server filters and processes all authentication requests, then authorization control is improved, but processing time and complexity increase
Solution Approach 1:
The patent pre-loads domain services objects into a read-only cache before authentication requests arrive. This preliminary action allows the server to quickly serve authentication requests from cached data without requiring real-time processing or communication with the credential server, thus reducing processing time while maintaining authorization control through the pre-filtered read-only objects.
Data Source
AI summary
A server may bridge between a wide area network, such as the Internet, and a local area network and may process authentication requests from clients on the wide area network. The server may filter the requests to enable specific types of requests to pass, and may forward the requests to a credential server within the local area network and pass any responses back to the client. The server may be configured with some or all of a set of domain services objects, but such objects may be stored in a read only format. The server may further contain a minimum of or no sensitive data such that, if compromised, an attacker may gain little advantage. The client may request evidence of authentication available to devices within the local area network and may use the evidence of authentication to access services made available to the wide area network.


