Distributed Security Component Authentication for Remote Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Employees working outside the corporate network face challenges in maintaining the same level of security and policy enforcement as when connected to the enterprise network, especially when accessing remote resources, due to the limitations of traditional security solutions.

Innovation Solution

A distributed secure content management system that routes requests to a security component for authentication, using various protocols to authenticate entities and allowing access through a forward proxy, even when the user is not close to the enterprise network, by communicating with an identity system for credentials and logging purposes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If employees access resources outside the enterprise network, then mobility and work flexibility are improved, but security control and policy enforcement deteriorate

Engineering Contradiction:
Improvework flexibilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The security system is segmented into multiple distributed security components deployed across different network locations. Each security component can independently authenticate and authorize users, allowing security control to be maintained at the edge rather than requiring centralized network access. This enables employees to access resources securely from any location while maintaining enterprise security policies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A forward proxy server acts as an intermediary between employees and external resources. The proxy server mediates all traffic, enforcing security policies and authentication requirements before allowing access to external resources. This intermediary approach maintains security control while enabling flexible remote access to resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If employees are required to log on to the enterprise network to access external resources, then security control is improved, but network dependency and access efficiency deteriorate

Engineering Contradiction:
Improvesecurity controlVSAvoidaccess efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Security functionality is segmented and distributed to multiple locations including forward proxy servers deployed at branch offices and remote sites. This allows employees to authenticate and access external resources locally without requiring connection to the central enterprise network, maintaining security control while improving access efficiency for roaming users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system adds a new dimension to security architecture by deploying security components in multiple spatial dimensions (central enterprise network, branch offices, remote locations) rather than relying solely on centralized network access. This enables employees to maintain secure access from any location, improving productivity while preserving security control.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If a centralized security system is used, then policy enforcement is improved, but system complexity and deployment difficulty increase for distributed environments

Engineering Contradiction:
Improvepolicy enforcementVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The centralized security policy framework is segmented into distributed security components that can be deployed independently at various locations. Each component enforces the same enterprise security policies locally, eliminating the need for complex centralized infrastructure at remote sites while maintaining consistent policy enforcement across the enterprise.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security components are designed with universal functionality that can operate autonomously at any location while maintaining compatibility with enterprise security policies. This multi-functionality allows the same security framework to serve both centralized and distributed environments, reducing deployment complexity while ensuring consistent policy enforcement.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8910255B2Authentication for distributed secure content management system
Publication Date: 2014.12.09 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8910255B2 patent drawing
  • US8910255B2 patent drawing
  • US8910255B2 patent drawing

AI summary

Aspects of the subject matter described herein relate to authentication for a distributed secure content management system. In aspects, a request to access a resource available through the Internet is routed to a security component. The security component is one of a plurality of security components distributed throughout the Internet and responsible for authenticating entities associated with an enterprise. The security component determines an authentication protocol to use with the entity and then authenticates the entity. If the entity is authenticated, the entity is allowed to use a forward proxy.