Authority Service Ticket Framework for Secure Network Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network connection establishment and maintenance methods are inadequate in ensuring security and reliability, particularly in multi-network interface scenarios, as they fail to coordinate effectively between components, leading to vulnerabilities that allow malicious entities to exploit gaps in security and policy enforcement.

Innovation Solution

A framework where an application communicates its intent to an authority service, which enforces security requirements by creating and managing tickets that include resource information, ensuring secure and reliable connections by monitoring changes in IP addresses and network interfaces, thus maintaining a valid network connection in compliance with policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If name-based policy is applied in the network stack, then security policy enforcement is simplified, but the operating system becomes blind to actual resource connections and cannot effectively determine whether access should be allowed or denied

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidaccess control accuracy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a name resolution service as an intermediary component that bridges the network stack and application layer. This service resolves hostnames to IP addresses and provides the operating system with comprehensive information about actual resource connections, enabling accurate security policy enforcement without requiring changes to the network stack's name-based approach

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds a new dimension to network connectivity by introducing application-layer awareness through the name resolution service. This service operates at a higher layer than the traditional network stack, providing additional information about resource connections without interfering with existing network protocols

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Speed

If applications cache destination IP addresses and connect directly without using hostnames, then connection speed is improved, but security and policy enforcement become difficult because the operating system cannot track which resources applications connect to

Engineering Contradiction:
Improveconnection speedVSAvoidsecurity vulnerability
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The name resolution service provides feedback to the operating system about the actual resources applications connect to, even when applications use cached IP addresses. This feedback mechanism enables the operating system to maintain awareness of resource connections and enforce security policies without slowing down application connections

Inventive Principle:
Principle #23Feedback

3Productivity

If network components use IP addresses independently without coordination, then network connectivity is established efficiently, but the operating system lacks a unified view of network connections and cannot reliably enforce policies

Engineering Contradiction:
Improvenetwork connection establishmentVSAvoidcoordination information
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The name resolution service acts as an intermediary that collects and coordinates network connection information from multiple sources. It maintains a unified view of network connections by resolving hostnames to IP addresses and tracking the relationships between applications, resources, and network paths

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10659466B2Secure resource-based policy
Publication Date: 2020.05.19 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10659466B2 patent drawing
  • US10659466B2 patent drawing
  • US10659466B2 patent drawing

AI summary

The techniques and systems described herein improve security and improve connection reliability by providing a framework for an application to communicate its intent to an authority service so that the authority service can enforce networking security requirements. In various examples, an intent to access a resource over a network is received and queries are sent to resolve a network connection that enables access to the resource. Information for the resource is then collected and stored together in a trusted and secure environment. For instance, the information can include proxy data or can include hostname data. A ticket can be created based on the information. The ticket can be used to establish and maintain a secure network connection to the resource.