Authentication Agent Decouples Manager Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing authentication data for hundreds or thousands of servers and applications in large-scale systems is challenging due to the need for unique and regularly updated authentication credentials for each application and server, leading to increased complexity and burden on system managers.

Innovation Solution

An authentication agent decouples manager authentication from user authentication, allowing for a scalable authentication system where multiple servers within a group can use the same or related credentials, reducing the complexity of managing authentication data by using a single certificate or shared credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If unique authentication credentials are assigned to each server and application, then security is improved, but device complexity and administrative burden increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication data management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments authentication management into two distinct layers: (1) server-level authentication credentials that remain unique and secure for each server, and (2) application-level access credentials that can be shared across multiple applications. This segmentation allows system managers to maintain strong security at the server level while simplifying application-level access management through shared credentials, thereby resolving the contradiction between security and management complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication mechanism that sits between the server and application layers. This intermediary layer enables shared credentials to be used across multiple applications without exposing the underlying unique server credentials, thus maintaining security while reducing the administrative burden of managing unique credentials for each application.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If unique authentication credentials are required for each application, then security is maintained, but ease of operation deteriorates due to increased administrative burden

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication data management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the authentication credential management at the application level by allowing multiple applications to share common credentials. This merging reduces the administrative burden of managing unique credentials for each application while maintaining security through the underlying server-level unique credentials and intermediary authentication layer.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements universality by creating authentication credentials that can serve multiple applications simultaneously. Instead of requiring separate unique credentials for each application, the system allows a set of credentials to function universally across multiple applications, thereby improving ease of operation while maintaining security through the layered authentication architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If authentication credentials are regularly updated, then security is strengthened, but loss of time increases due to frequent management updates

Engineering Contradiction:
ImprovesecurityVSAvoidtime for credential management updates
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments credential update operations into two independent layers: server-level credentials and application-level credentials. This segmentation allows application-level credentials to be updated independently without affecting server-level credentials, thereby reducing the time and effort required for credential management updates while maintaining security through regular updates at both layers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

By merging application-level credential management into a shared credential system, the patent reduces the number of credential updates required. Instead of updating unique credentials for each application, administrators can update shared credentials that serve multiple applications simultaneously, thereby reducing the time loss associated with frequent credential management while maintaining security through the underlying server-level credential updates.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8844015B2Application-access authentication agent
Publication Date: 2014.09.23 MICRO FOCUS LLC
  • US8844015B2 patent drawing
  • US8844015B2 patent drawing
  • US8844015B2 patent drawing

AI summary

In response to requests from a manager to the agents for connections to the applications executing, the agents authenticate the manager. In response to the authenticating, the agents establish connections to the applications. In response to the establishing of connections, the agents provide the connections to the manager.