Client Certificate Attribute-Based Connection Type Assignment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for access control in data communication networks do not effectively utilize certificate data to determine the type of connection to establish for users, limiting the ability to provide tailored access to resources based on authentication information.
Innovation Solution
A method and appliance that request a client authentication certificate, identify specific fields within it, and apply policies to assign appropriate access types, such as accelerated, load-balanced, or traffic-managed connections, based on the certificate attributes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional access control methods are used that only evaluate authentication credentials for access granting, then access security is maintained, but the ability to determine connection types based on certificate data is lost
Solution Approach 1:
The system performs preliminary extraction and evaluation of certificate attributes (such as username, group membership, policy information) from the client certificate before the access decision is made. This allows the system to pre-determine the appropriate connection type (accelerated, load-balanced, traffic-managed, or session-managed) based on the user's identity and associated policies, rather than making this determination after access is already granted.
Solution Approach 2:
The patent introduces an intermediary component that acts as a bridge between the authentication credential evaluation and the connection type determination. This intermediary extracts relevant attributes from the certificate data and maps them to appropriate connection types, allowing the system to utilize certificate information for connection classification without requiring complete redesign of the access control architecture.
2Ease of operation
If certificate data is utilized to determine connection types, then tailored access control is improved, but processing complexity increases
Solution Approach 1:
The system extracts only the specific, relevant attributes needed for connection type determination from the certificate data, such as the username field, group membership fields, and policy information fields. By taking out only these essential elements rather than processing the entire certificate, the system achieves tailored access control based on certificate data while minimizing the processing complexity associated with handling complete certificate structures.
3Adaptability or versatility
If multiple connection types are assigned based on certificate attributes, then service quality is improved, but system complexity increases
Solution Approach 1:
The patent applies different connection types (accelerated, load-balanced, traffic-managed, session-managed) to different users or user groups based on their specific certificate attributes. Each user receives a connection type that is locally optimized for their needs and policies, rather than applying a uniform connection type to all users. This allows service quality to be improved through differentiated connection assignments while managing system complexity by handling each user's connection type determination independently based on their certificate data.
Data Source
AI summary
In a method and appliance for authenticating, by an appliance, a client to access a virtual network connection, based on an attribute of a client-side certificate, a client authentication certificate is requested from a client. A value of at least one field in the client authentication certificate received from the client is identified. One of a plurality of types of access is assigned responsive to an application of a policy to the identified value of the at least one field, each of the plurality of access types associated with at least one connection characteristic.


