Centralized Policy Server for Enterprise Network Federation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity of enterprise ecosystems due to numerous IT partners and cloud connectivity necessitates more efficient identity and federation management solutions, particularly in enabling secure access across multiple enterprise network domains.

Innovation Solution

A cloud-based policy server establishes centralized trust relationships between enterprise network domains, enabling a flexible and scalable federation management system by separating authentication from partnership processes and enforcing policies across multiple partners through a central hub, allowing for granular control of access and easy establishment of sub-federations and recursive relationships.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If enterprises establish federation relationships with multiple IT partners to enable access across enterprise network domains, then access capability and ecosystem connectivity are improved, but infrastructure complexity and policy management burden increase

Engineering Contradiction:
Improveaccess capabilityVSAvoidinfrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized policy server as an intermediary component that mediates authentication and policy enforcement between multiple enterprise network domains. This policy server acts as a hub that receives authentication requests from partner enterprises, applies centralized policies, and manages federation relationships, thereby enabling access capability while avoiding the complexity of direct peer-to-peer federation configurations between all partners.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If enterprises configure direct federation relationships between all partner enterprises to enable mutual access, then access flexibility is improved, but policy management complexity and operational overhead increase

Engineering Contradiction:
Improveaccess flexibilityVSAvoidpolicy management complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent merges the policy management functions of multiple federation relationships into a single centralized policy server. Instead of managing separate policies for each partner enterprise relationship, the system consolidates all authentication and authorization policies into one centralized location, significantly reducing policy management complexity while maintaining access flexibility through the policy server's ability to enforce differentiated policies for different partners.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If enterprises use traditional distributed authentication approaches without centralized trust, then autonomy of individual enterprises is maintained, but security consistency and trust management across the ecosystem deteriorate

Engineering Contradiction:
Improvesecurity consistencyVSAvoidtrust management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal trust model where the centralized policy server serves multiple functions: it acts as an authentication authority, a policy enforcement point, a trust anchor, and a federation manager for all partner enterprises. This multi-functional approach ensures security consistency across the entire ecosystem while simplifying trust management, as all enterprises trust the same centralized policy server rather than requiring complex mutual trust relationships.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9917861B2Enabling access to an enterprise network domain based on a centralized trust
Publication Date: 2018.03.13 CISCO TECHNOLOGY INC
  • US9917861B2 patent drawing
  • US9917861B2 patent drawing
  • US9917861B2 patent drawing

AI summary

A method of establishing centralized trust includes, at a policy server having connectivity to a network, establishing a trust relationship with a first enterprise network domain and a second enterprise network domain. One or more criterion from a server in the first enterprise network domain are received by the policy server and a federation relationship is established between at least a portion of the first enterprise network domain and one or more entities in the second enterprise network domain based on the one or more criterion. Based on the federation relationship, the policy server enables the one or more entities in the second enterprise network domain to access the at least a portion of the first enterprise network domain.