Authentication Agents for Distributed Application Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for application segmentation in networked systems face scalability issues due to the exponential growth of firewall rules, making it difficult to manage communications between a large number of applications across different network domains.
Innovation Solution
Implementing an authentication and authorization model that uses authentication agents to manage secure communications by appending and validating trust profiles associated with application processes, allowing only authorized interactions based on predefined policies, thereby reducing the complexity of firewall rules and enabling linear scalability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional firewall rules are used for application segmentation, then security between network domains is improved, but device complexity and scalability deteriorate due to exponential growth of rules
Solution Approach 1:
The patent introduces authentication agents as intermediary components that mediate between applications and the authorization service. These agents intercept communications, append trust profiles, and validate authorizations, thereby replacing the need for complex exponential firewall rules with a scalable linear authorization model based on identity and policy.
Solution Approach 2:
The patent changes the fundamental parameter for access control from network-based (IP addresses, ports) to identity-based (trust profiles, application identities). This parameter change enables linear scalability because authorization decisions are made based on identity attributes and policies rather than requiring explicit rules for every application pair.
2Reliability
If authentication agents append trust profiles to all transmissions, then authorization control is improved, but use of energy and processing overhead increase
Solution Approach 1:
The patent implements preliminary action by having authentication agents append trust profiles to transmissions before they reach the receiving application. The receiving application's authentication agent validates these trust profiles against stored policies, enabling authorization decisions to be made in advance rather than requiring real-time complex rule evaluation for each communication pair.
Data Source
AI summary
Methods and supporting systems for managing secure communications and establishing authenticated communications between processes of a computer application operating across network domains are provided. Authentication agents operate on servers hosting application processes, wherein each authentication agent has access to policies related to each of the application processes. An authentication agent operating on an originating server intercepts transmissions from an originating application processes and appends a trust profile associated with the originating application process. The transmission is released to a receiving server, where it is intercepted and validated at the receiving server by a second authentication agent on the receiving server. If the validation succeeds the transmission is forwarded to the receiving application process where it is executed, processed or otherwise acted upon acted upon, and the receiving server provides an acknowledgement transmission to the originating server confirming the transmission was received and processed by the receiving application process.


