Edge Node Delegated Authentication for Distributed Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Complexity in managing large, distributed IT ecosystems due to increased geographic footprints and user mobility leads to challenges in reliably and securely authenticating users and devices across managed networks, with persistent threats from malicious authentication attempts.

Innovation Solution

Implementing systems and methods for locally conducting delegated authentication at edge nodes, where edge nodes receive and store authentication information, process authentication requests, and perform authenticating operations to establish sessions, reducing reliance on centralized systems and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized authentication systems are used to manage large, distributed IT ecosystems, then authentication coverage across the network is comprehensive, but system complexity and vulnerability to malicious attempts increase

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the centralized authentication system into distributed authentication edge nodes that operate autonomously. Each edge node stores local authentication information and can independently perform authentication operations, segmenting the monolithic centralized system into multiple smaller, manageable units that reduce overall system complexity while maintaining comprehensive authentication coverage

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local authentication processing at edge nodes rather than requiring all authentication operations to be handled centrally. Each edge node has the capability to locally verify authentication information and perform authentication operations, providing localized authentication services that reduce the burden on centralized systems and lower overall system complexity

Inventive Principle:
Principle #3Local quality

2Productivity

If centralized authentication systems process all authentication requests, then authentication decisions are centralized and controlled, but the burden on centralized systems increases and response time may be affected

Engineering Contradiction:
Improveauthentication processing capacityVSAvoidauthentication response time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent pre-loads authentication information onto edge nodes before authentication requests arrive. Edge nodes receive and store authentication information in advance, enabling them to immediately process authentication requests without needing to query centralized systems in real-time, thereby increasing processing capacity and reducing response time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent distributes authentication processing capacity across multiple edge nodes rather than concentrating it all in one centralized system. This segmentation allows parallel processing of authentication requests at different edge nodes simultaneously, increasing overall authentication processing capacity while reducing the burden on any single system and minimizing response time

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11695768B1Systems and methods for locally conducting delegated authentication at edge nodes
Publication Date: 2023.07.04 WELLS FARGO BANK NA
  • US11695768B1 patent drawing
  • US11695768B1 patent drawing
  • US11695768B1 patent drawing

AI summary

Disclosed herein are embodiments of systems and methods for locally conducting delegated authentication at edge nodes. In an embodiment, an edge node of a managed network receives, from an authentication system, authentication information for a user. The edge node stores the authentication information. The edge node receives, from a user device associated with the user, an authentication request that includes presented authentication information. The edge node determines whether one or more authentication criteria are met for the authentication request, and if so performs a set of authenticating operations. The one or more authentication criteria includes the presented authentication information matching the stored authentication information. The set of authenticating operations includes authenticating the user with respect to the managed network, as well as establishing an authenticated session for the user at the edge node.