Edge Node Delegated Authentication for Distributed Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Complexity in managing large, distributed IT ecosystems due to increased geographic footprints and user mobility leads to challenges in reliably and securely authenticating users and devices across managed networks, with persistent threats from malicious authentication attempts.
Innovation Solution
Implementing systems and methods for locally conducting delegated authentication at edge nodes, where edge nodes receive and store authentication information, process authentication requests, and perform authenticating operations to establish sessions, reducing reliance on centralized systems and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized authentication systems are used to manage large, distributed IT ecosystems, then authentication coverage across the network is comprehensive, but system complexity and vulnerability to malicious attempts increase
Solution Approach 1:
The patent divides the centralized authentication system into distributed authentication edge nodes that operate autonomously. Each edge node stores local authentication information and can independently perform authentication operations, segmenting the monolithic centralized system into multiple smaller, manageable units that reduce overall system complexity while maintaining comprehensive authentication coverage
Solution Approach 2:
The patent implements local authentication processing at edge nodes rather than requiring all authentication operations to be handled centrally. Each edge node has the capability to locally verify authentication information and perform authentication operations, providing localized authentication services that reduce the burden on centralized systems and lower overall system complexity
2Productivity
If centralized authentication systems process all authentication requests, then authentication decisions are centralized and controlled, but the burden on centralized systems increases and response time may be affected
Solution Approach 1:
The patent pre-loads authentication information onto edge nodes before authentication requests arrive. Edge nodes receive and store authentication information in advance, enabling them to immediately process authentication requests without needing to query centralized systems in real-time, thereby increasing processing capacity and reducing response time
Solution Approach 2:
The patent distributes authentication processing capacity across multiple edge nodes rather than concentrating it all in one centralized system. This segmentation allows parallel processing of authentication requests at different edge nodes simultaneously, increasing overall authentication processing capacity while reducing the burden on any single system and minimizing response time
Data Source
AI summary
Disclosed herein are embodiments of systems and methods for locally conducting delegated authentication at edge nodes. In an embodiment, an edge node of a managed network receives, from an authentication system, authentication information for a user. The edge node stores the authentication information. The edge node receives, from a user device associated with the user, an authentication request that includes presented authentication information. The edge node determines whether one or more authentication criteria are met for the authentication request, and if so performs a set of authenticating operations. The one or more authentication criteria includes the presented authentication information matching the stored authentication information. The set of authenticating operations includes authenticating the user with respect to the managed network, as well as establishing an authenticated session for the user at the edge node.


