Delegated Enterprise Network Access via Trust Chain Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face challenges in managing access to their networks for outside entities, such as partner employees and devices, due to manual and time-consuming processes, leading to security risks and lack of control over access permissions, especially when credentials are shared or devices are not directly owned by the enterprise.
Innovation Solution
A cloud-based identity management system that creates and manages 'trust chains' between enterprises and partner organizations, allowing trusted entities to delegate access and perform periodic validation of outside entities, automatically revoking access when necessary, and enabling re-parenting of broken trust chains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual processes are used to manage access for outside entities, then flexibility in granting access is improved, but the time consumption and security risks increase
Solution Approach 1:
An identity management system acts as an intermediary between the enterprise network and outside entities. The system automatically validates credentials, establishes trust relationships, and manages access permissions without requiring manual intervention for each access request. This intermediary approach maintains operational flexibility while eliminating time-consuming manual processes.
Solution Approach 2:
The system performs preliminary validation of outside entities by verifying credentials, establishing trust chains, and pre-configuring access permissions before actual network access is requested. This preliminary action ensures that when access is needed, the process is automated and immediate, reducing time consumption while maintaining security controls.
2Reliability
If manual access control processes are used, then control over access permissions can be maintained, but security risks increase due to credential sharing and lack of validation
Solution Approach 1:
The identity management system continuously validates credentials and monitors access permissions for outside entities. It provides feedback by verifying trust chains, checking credential validity, and automatically revoking access when credentials expire or become compromised. This continuous feedback mechanism maintains reliable access control while preventing security risks from credential sharing.
Solution Approach 2:
The system enables self-service validation where outside entities automatically present credentials and the system verifies them against trusted identity providers. This self-service approach eliminates manual credential management and sharing, as each entity's credentials are independently validated, maintaining security while improving reliability of access control.
3Reliability
If automated validation is implemented, then security is improved, but system complexity increases
Solution Approach 1:
The identity management system is segmented into modular components: credential validation modules, trust chain verification modules, permission management modules, and access control modules. Each component performs a specific function, making the overall complex system manageable through clear separation of concerns. This segmentation maintains high security through automated validation while organizing complexity into manageable segments.
4Extent of automation
If trust chains are used to manage outside entity access, then automated access control is improved, but difficulty in managing broken trust chains increases
Solution Approach 1:
The system implements continuous feedback mechanisms that monitor the validity of trust chains. When a trust chain becomes broken or invalid, the system automatically detects it through validation failures and provides feedback by revoking access permissions. This feedback approach maintains automated access control while simplifying the detection and management of broken trust chains through automatic monitoring and response.
Data Source
AI summary
Presented herein are techniques for enabling delegated access control of an enterprise network. In particular, data representing a trust chain formed between a local domain and a remote domain is stored in an identity management system. The local domain has an associated secure enterprise computing network and wherein the trust chain identifies one or more outside entities associated with the remote domain that are authorized to access the secure enterprise computing network. The identity management system receives a request for access to the secure enterprise computing network by a first outside entity of the one or more outside entities associated with the remote domain. Access by the outside entity to the secure enterprise computing network is controlled/determined based on an analysis of the trust chain.


