Centralizing Access Control via Network Traffic Management Device

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer network systems face challenges with interoperability, scalability, and security due to the disparate nature of access management and traffic management systems, which require each application server to have an EAM agent for effective communication with the EAM server, leading to administrative burdens and increased costs.

Innovation Solution

A network traffic management device is configured with a local EAM agent that directly communicates with an EAM server to receive policy information and enforce AAA functionality, shifting the policy enforcement point from individual servers to the network traffic management device, thereby centralizing access management and improving scalability and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If each application server has an EAM agent to communicate with the EAM server, then access control functionality is maintained, but device complexity and administrative burden increase

Engineering Contradiction:
Improveaccess control functionalityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network traffic management device as an intermediary between clients and application servers. This device incorporates the EAM agent functionality, acting as a mediator that handles authentication and authorization requests centrally. Instead of each application server having its own EAM agent, the network traffic management device serves as a single intermediary that communicates with the EAM server on behalf of all servers, thereby maintaining access control functionality while reducing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If each application server has an EAM agent, then access policy enforcement is distributed, but ease of operation and scalability deteriorate

Engineering Contradiction:
Improveaccess policy enforcementVSAvoidadministrative ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the EAM agent functionality from multiple application servers into a single network traffic management device. This consolidation combines the distributed access policy enforcement capability into one centralized location, making the system easier to operate and administer. The network traffic management device handles all authentication and authorization communications with the EAM server, simplifying administrative tasks while maintaining effective access policy enforcement across all servers.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If multiple EAM agents are deployed across application servers, then access control is maintained, but cost and device complexity increase

Engineering Contradiction:
Improveaccess control securityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network traffic management device is designed with multi-functionality, serving as both a traffic management component and an access control enforcement point. By incorporating the EAM agent functionality into this universal device, the system maintains robust access control security while avoiding the need for multiple separate EAM agents across different servers. This multi-functional approach reduces system architecture complexity and associated costs while preserving security requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10135831B2System and method for combining an access control system with a traffic management system
Publication Date: 2018.11.20 F5 NETWORKS INC
  • US10135831B2 patent drawing
  • US10135831B2 patent drawing
  • US10135831B2 patent drawing

AI summary

A system and method for handling a request from a client device to access a service from a server. The method comprises receiving a request from a user using a client device to access a service from a server. The request is received by a network traffic management device having a local external access management (EAM) agent. The EAM agent directly communicates with an EAM server that provides authentication policy information of a plurality of users able to at least partially access the server. User credential information is sent from the EAM agent to the EAM server, whereby the EAM agent receives access policy information of the user from the EAM server. The system and method selectively controls access of the user's request to the server in accordance with the received access policy information at the network traffic management device.