Edge-Server Identity Authentication for Lower-Latency Zero-Trust Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The implementation and deployment of zero-trust models in large-scale enterprise environments face challenges such as complex IAM integration, high IAM workload, and high client latency due to the need for continuous authentication, which can lead to hardware resource shortages and unpleasant user experiences.
Innovation Solution
A centralized identity agent in the cloud connects various IAMs and IDPs, providing a uniform interface, and edge servers store identity authentication information to reduce the load on IAMs and improve user experience by handling authentication requests locally.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized cloud-based IAM is used for continuous authentication, then security and authentication reliability are improved, but system latency and user experience deteriorate
Solution Approach 1:
The patent segments the centralized cloud-based IAM system into distributed edge server nodes. Each edge server maintains local authentication databases and can perform authentication operations independently, reducing the need for continuous cloud communication. This segmentation preserves authentication reliability through distributed verification while lowering latency by enabling local authentication decisions.
Solution Approach 2:
The patent implements preliminary action by pre-synchronizing authentication data to edge servers before authentication is needed. Edge servers maintain up-to-date local copies of authentication information, allowing them to perform rapid local authentication without waiting for cloud-based verification. This preliminary data preparation reduces authentication latency while maintaining security through periodic cloud synchronization.
2Reliability
If continuous authentication is implemented in zero-trust model, then security is improved, but hardware resource consumption and system complexity increase
Solution Approach 1:
The patent divides the continuous authentication burden into segments handled by individual edge servers rather than a single centralized system. Each edge server independently manages local authentication for its辖区 users, simplifying the overall system architecture while maintaining continuous security verification through distributed operation.
Solution Approach 2:
Edge servers are designed to autonomously perform authentication operations using local databases and cached credentials. The system enables self-service authentication at the edge level, reducing the complexity of centralized coordination while maintaining security through periodic cloud synchronization and centralized policy management for exceptional cases.
3Extent of automation
If cloud server handles all authentication requests, then centralized control is maintained, but server workload and response time worsen
Solution Approach 1:
The patent segments authentication request handling between cloud servers and edge servers. Routine authentication requests are processed locally at edge servers, while the cloud server handles policy management, exceptional cases, and periodic synchronization. This segmentation maintains centralized control over security policies while dramatically improving authentication throughput through distributed processing.
Solution Approach 2:
The patent introduces edge servers as intermediaries between end users and the centralized cloud IAM system. These intermediaries handle the bulk of authentication operations locally, reducing the workload on cloud servers. The cloud server maintains centralized control by managing authentication policies, credentials, and exceptional cases, while edge servers provide rapid local authentication services.
Data Source
AI summary
The present disclosure relates to a method, a server, and a computer program product for identity authentication. The method includes searching, in response to receiving an identity authentication request from a user at an edge server, an identity authentication database of the edge server for identity authentication information associated with the user. The method further includes sending, in response to the identity authentication information associated with the user not being found in the identity authentication database, the identity authentication request to a cloud server, the cloud server including an agent for interfacing with a plurality of identity authentication providers. In addition, the method further includes receiving the identity authentication information associated with the user from the cloud server, storing the identity authentication information to the identity authentication database, and using the identity authentication information to authenticate the user.


