Distributed Security Nodes for Enterprise Authentication Efficiency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems face inefficiencies in processing authentication and authorization requests, which can lead to resource-intensive operations and are vulnerable to replay attacks and unauthorized data theft.

Innovation Solution

A distributed security system is implemented externally to the network edge, utilizing processing nodes and authority nodes to monitor and control data communications, employing data inspection engines and encryption techniques to prevent security threats and fraudulently generated data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If authentication and authorization checks are performed within the enterprise network, then security control is maintained, but processing inefficiencies occur and resource consumption increases

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidresource consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the authentication and authorization check functions from the enterprise network infrastructure and relocates them to external authority nodes. This separation allows the enterprise network to focus on core business operations while external specialized nodes handle security verification, improving overall processing efficiency and reducing resource consumption within the enterprise.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces authority nodes as intermediary components between users and enterprise resources. These intermediary nodes perform authentication and authorization checks, acting as a mediator that verifies user credentials and permissions without requiring enterprise resources to directly perform these security functions, thereby reducing enterprise resource consumption.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple analysis of user requests are performed to determine authentication and authorization, then security verification is thorough, but processing time increases

Engineering Contradiction:
Improvesecurity verificationVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by performing authentication verification in advance through authority nodes before users access enterprise resources. User credentials are verified and authorization decisions are made beforehand, storing the results for quick retrieval during actual resource access, thus maintaining thorough security verification while significantly reducing processing time during user operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the authentication and authorization process into distinct phases: credential verification by authority nodes, authorization decision-making, and resource access execution. This segmentation allows each phase to be handled by specialized components, improving overall processing efficiency while maintaining comprehensive security verification through dedicated functions at each stage.

Inventive Principle:
Principle #1Segmentation

3Speed

If authentication and authorization data are stored locally, then quick access is possible, but vulnerability to replay attacks and data theft increases

Engineering Contradiction:
Improvedata access speedVSAvoidsecurity vulnerability
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the storage of sensitive authentication and authorization data from local enterprise systems and relocates it to external authority nodes. This extraction maintains fast access speeds through efficient data retrieval mechanisms at authority nodes while eliminating the security vulnerability of storing sensitive data locally within the enterprise network.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses authority nodes as intermediary storage locations for authentication and authorization data. These intermediary nodes specialize in secure data management and provide fast access through optimized retrieval processes, while their external location and specialized security measures protect against replay attacks and data theft that would affect local storage systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If distributed security system is implemented externally, then processing efficiency improves and resource usage reduces, but system complexity increases

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidsystem architecture
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements universal authority nodes that can serve multiple enterprises and handle various types of authentication and authorization requests through standardized interfaces. This multi-functionality reduces the need for separate security systems for each enterprise, thereby improving processing efficiency across multiple clients while actually reducing overall system complexity through consolidation and standardization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12137121B2Distributed cloud-based security systems and methods
Publication Date: 2024.11.05 ZSCALER INC
  • US12137121B2 patent drawing
  • US12137121B2 patent drawing
  • US12137121B2 patent drawing

AI summary

A distributed security system includes a plurality of content processing nodes that are located external to a network edge of an enterprise and located external from one of a computer device and a mobile device associated with a user, and a content processing node is configured to monitor a content item that is sent from or requested by the external system; classify the content item via a plurality of data inspection engines that utilize policy data and threat data; and one of distribute the content item, preclude distribution of the content item, allow distribution of the content item after a cleaning process, or perform threat detection on the content item, based on classification by the plurality of data inspection engines; and an authority node communicatively coupled to the plurality of content processing nodes and configured to provide the policy data and the threat data for threat classification.