Delegated Enterprise Network Access via Trust Chain Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in managing access to their networks for outside entities, such as partner employees and devices, due to manual and time-consuming processes, leading to security risks and lack of control over access permissions, especially when credentials are shared or devices are not directly owned by the enterprise.

Innovation Solution

A cloud-based identity management system that creates and manages 'trust chains' between enterprises and partner organizations, allowing trusted entities to delegate access and perform periodic validation of outside entities, automatically revoking access when necessary, and enabling re-parenting of broken trust chains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual processes are used to manage access for outside entities, then flexibility in granting access is improved, but the time consumption and security risks increase

Engineering Contradiction:
Improveaccess management flexibilityVSAvoidtime consumption for access management
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

An identity management system acts as an intermediary between the enterprise network and outside entities. The system automatically validates credentials, establishes trust relationships, and manages access permissions without requiring manual intervention for each access request. This intermediary approach maintains operational flexibility while eliminating time-consuming manual processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary validation of outside entities by verifying credentials, establishing trust chains, and pre-configuring access permissions before actual network access is requested. This preliminary action ensures that when access is needed, the process is automated and immediate, reducing time consumption while maintaining security controls.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual access control processes are used, then control over access permissions can be maintained, but security risks increase due to credential sharing and lack of validation

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidsecurity risks from credential sharing
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The identity management system continuously validates credentials and monitors access permissions for outside entities. It provides feedback by verifying trust chains, checking credential validity, and automatically revoking access when credentials expire or become compromised. This continuous feedback mechanism maintains reliable access control while preventing security risks from credential sharing.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system enables self-service validation where outside entities automatically present credentials and the system verifies them against trusted identity providers. This self-service approach eliminates manual credential management and sharing, as each entity's credentials are independently validated, maintaining security while improving reliability of access control.

Inventive Principle:
Principle #25Self-service

3Reliability

If automated validation is implemented, then security is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoididentity management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The identity management system is segmented into modular components: credential validation modules, trust chain verification modules, permission management modules, and access control modules. Each component performs a specific function, making the overall complex system manageable through clear separation of concerns. This segmentation maintains high security through automated validation while organizing complexity into manageable segments.

Inventive Principle:
Principle #1Segmentation

4Extent of automation

If trust chains are used to manage outside entity access, then automated access control is improved, but difficulty in managing broken trust chains increases

Engineering Contradiction:
Improveautomated access controlVSAvoidtrust chain validation difficulty
Core Design Contradiction:
Extent of automationVSDifficulty of detecting and measuring

Solution Approach 1:

The system implements continuous feedback mechanisms that monitor the validity of trust chains. When a trust chain becomes broken or invalid, the system automatically detects it through validation failures and provides feedback by revoking access permissions. This feedback approach maintains automated access control while simplifying the detection and management of broken trust chains through automatic monitoring and response.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10757073B2Delegated access control of an enterprise network
Publication Date: 2020.08.25 CISCO TECHNOLOGY INC
  • US10757073B2 patent drawing
  • US10757073B2 patent drawing
  • US10757073B2 patent drawing

AI summary

Presented herein are techniques for enabling delegated access control of an enterprise network. In particular, data representing a trust chain formed between a local domain and a remote domain is stored in an identity management system. The local domain has an associated secure enterprise computing network and wherein the trust chain identifies one or more outside entities associated with the remote domain that are authorized to access the secure enterprise computing network. The identity management system receives a request for access to the secure enterprise computing network by a first outside entity of the one or more outside entities associated with the remote domain. Access by the outside entity to the secure enterprise computing network is controlled/determined based on an analysis of the trust chain.