Authentication Agents for Distributed Application Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for application segmentation in networked systems face scalability issues due to the exponential growth of firewall rules, making it difficult to manage communications between a large number of applications across different network domains.

Innovation Solution

Implementing an authentication and authorization model that uses authentication agents to manage secure communications by appending and validating trust profiles associated with application processes, allowing only authorized interactions based on predefined policies, thereby reducing the complexity of firewall rules and enabling linear scalability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional firewall rules are used for application segmentation, then security between network domains is improved, but device complexity and scalability deteriorate due to exponential growth of rules

Engineering Contradiction:
ImprovesecurityVSAvoidfirewall rules complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces authentication agents as intermediary components that mediate between applications and the authorization service. These agents intercept communications, append trust profiles, and validate authorizations, thereby replacing the need for complex exponential firewall rules with a scalable linear authorization model based on identity and policy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the fundamental parameter for access control from network-based (IP addresses, ports) to identity-based (trust profiles, application identities). This parameter change enables linear scalability because authorization decisions are made based on identity attributes and policies rather than requiring explicit rules for every application pair.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If authentication agents append trust profiles to all transmissions, then authorization control is improved, but use of energy and processing overhead increase

Engineering Contradiction:
Improveauthorization controlVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements preliminary action by having authentication agents append trust profiles to transmissions before they reach the receiving application. The receiving application's authentication agent validates these trust profiles against stored policies, enabling authorization decisions to be made in advance rather than requiring real-time complex rule evaluation for each communication pair.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11689517B2Method for distributed application segmentation through authorization
Publication Date: 2023.06.27 PALO ALTO NETWORKS INC
  • US11689517B2 patent drawing
  • US11689517B2 patent drawing
  • US11689517B2 patent drawing

AI summary

Methods and supporting systems for managing secure communications and establishing authenticated communications between processes of a computer application operating across network domains are provided. Authentication agents operate on servers hosting application processes, wherein each authentication agent has access to policies related to each of the application processes. An authentication agent operating on an originating server intercepts transmissions from an originating application processes and appends a trust profile associated with the originating application process. The transmission is released to a receiving server, where it is intercepted and validated at the receiving server by a second authentication agent on the receiving server. If the validation succeeds the transmission is forwarded to the receiving application process where it is executed, processed or otherwise acted upon acted upon, and the receiving server provides an acknowledgement transmission to the originating server confirming the transmission was received and processed by the receiving application process.