Client Certificate Attribute-Based Connection Type Assignment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for access control in data communication networks do not effectively utilize certificate data to determine the type of connection to establish for users, limiting the ability to provide tailored access to resources based on authentication information.

Innovation Solution

A method and appliance that request a client authentication certificate, identify specific fields within it, and apply policies to assign appropriate access types, such as accelerated, load-balanced, or traffic-managed connections, based on the certificate attributes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional access control methods are used that only evaluate authentication credentials for access granting, then access security is maintained, but the ability to determine connection types based on certificate data is lost

Engineering Contradiction:
Improveconnection type determinationVSAvoidaccess control system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system performs preliminary extraction and evaluation of certificate attributes (such as username, group membership, policy information) from the client certificate before the access decision is made. This allows the system to pre-determine the appropriate connection type (accelerated, load-balanced, traffic-managed, or session-managed) based on the user's identity and associated policies, rather than making this determination after access is already granted.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary component that acts as a bridge between the authentication credential evaluation and the connection type determination. This intermediary extracts relevant attributes from the certificate data and maps them to appropriate connection types, allowing the system to utilize certificate information for connection classification without requiring complete redesign of the access control architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If certificate data is utilized to determine connection types, then tailored access control is improved, but processing complexity increases

Engineering Contradiction:
Improvetailored access controlVSAvoidcertificate processing
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system extracts only the specific, relevant attributes needed for connection type determination from the certificate data, such as the username field, group membership fields, and policy information fields. By taking out only these essential elements rather than processing the entire certificate, the system achieves tailored access control based on certificate data while minimizing the processing complexity associated with handling complete certificate structures.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If multiple connection types are assigned based on certificate attributes, then service quality is improved, but system complexity increases

Engineering Contradiction:
Improveconnection type assignmentVSAvoidaccess infrastructure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies different connection types (accelerated, load-balanced, traffic-managed, session-managed) to different users or user groups based on their specific certificate attributes. Each user receives a connection type that is locally optimized for their needs and policies, rather than applying a uniform connection type to all users. This allows service quality to be improved through differentiated connection assignments while managing system complexity by handling each user's connection type determination independently based on their certificate data.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8819809B2Method and appliance for authenticating, by an appliance, a client to access a virtual private network connection, based on an attribute of a client-side certificate
Publication Date: 2014.08.26 CITRIX SYSTEMS INC
  • US8819809B2 patent drawing
  • US8819809B2 patent drawing
  • US8819809B2 patent drawing

AI summary

In a method and appliance for authenticating, by an appliance, a client to access a virtual network connection, based on an attribute of a client-side certificate, a client authentication certificate is requested from a client. A value of at least one field in the client authentication certificate received from the client is identified. One of a plurality of types of access is assigned responsive to an application of a policy to the identified value of the at least one field, each of the plurality of access types associated with at least one connection characteristic.