Bulk Authentication Service Cluster for Networked Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service providers face inefficiencies in authenticating user appliances across multiple cloud-based services, leading to increased burden and network latency due to the need for individual authentication and load balancing across geographically distributed service clusters.

Innovation Solution

A system that enables bulk authentication of appliances to multiple cloud-based services through an authentication service cluster, which handles authentication and entitlement management centrally, allowing appliances to connect directly to optimized service clusters for reduced latency and streamlined access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual authentication is performed for each service provider, then service access control is ensured, but authentication time and appliance burden increase

Engineering Contradiction:
Improveservice access controlVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines multiple individual authentication processes into a single bulk authentication transaction. The appliance authenticates to multiple service providers simultaneously by sending one authentication request that includes credentials for all service providers, receiving back authentication results for all services in one response, thereby reducing authentication time while maintaining security control.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal authentication mechanism that works across multiple different service providers. By using a standardized bulk authentication protocol, the same authentication process can authenticate the appliance to any number of service providers, making the system multi-functional and eliminating the need for separate authentication procedures for each provider.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If per-service authentication is implemented, then service entitlement accuracy is maintained, but network latency and processing overhead increase

Engineering Contradiction:
Improveservice entitlement accuracyVSAvoidservice access efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent merges multiple entitlement verification operations into a single bulk authentication transaction. Instead of verifying entitlements for each service individually, the system verifies all entitlements in one transaction, maintaining precise entitlement tracking while dramatically improving access efficiency by eliminating repeated verification overhead.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If geographically distributed service clusters are used, then service accessibility is improved, but load balancing complexity increases

Engineering Contradiction:
Improveservice accessibilityVSAvoidload balancing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements self-service load balancing where each appliance autonomously determines the optimal service cluster to connect to based on its geographical location. The appliance receives location information from the authentication server and independently selects the nearest service cluster, eliminating the need for complex centralized load balancing infrastructure while maintaining high accessibility.

Inventive Principle:
Principle #25Self-service

4Reliability

If multiple authentication transactions are required for different services, then service-specific security is ensured, but authentication overhead increases

Engineering Contradiction:
Improveservice-specific securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple separate authentication transactions into a single unified bulk authentication request. The appliance sends one authentication request containing credentials for multiple service providers and receives back a comprehensive authentication response, thereby reducing process complexity while maintaining service-specific security through individual authentication results for each service provider.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9942050B2Method and apparatus for bulk authentication and load balancing of networked devices
Publication Date: 2018.04.10 BARRACUDA NETWORKS INC
  • US9942050B2 patent drawing
  • US9942050B2 patent drawing
  • US9942050B2 patent drawing

AI summary

A new approach is proposed that contemplates systems and methods to support bulk authentication of a device associated with a user to all cloud-based services the device intends to access in one transaction instead of authenticating the device against each of the services individually. First, the device generates and transmits to one or more authentication service clusters an authentication request that includes its identification and authentication credentials in order to access to a plurality of services. Upon receiving the authentication request, the authentication service cluster(s) authenticate the device for all of the services to be accessed based on the information in the authentication request. Once the device is authenticated, the authentication service cluster(s) then retrieve entitlement information of the services to be accessed by the device, and identify the service clusters/nodes that the device will connect to for the services with the fastest response time.