Enterprise Access Gateway for Cloud Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional solutions for controlling access to resources in cloud computing are costly and may compromise security due to the need to duplicate identity management and access policy infrastructure, which can become out of sync with the internal network, leading to unauthorized access.

Innovation Solution

Implementing an access gateway within the enterprise's internal network that delegates user authentication and authorization tasks, using a security token service to verify user access without duplicating the enterprise's identity management and access policy infrastructure in the cloud, and employing multi-factor authentication and health checks for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the enterprise duplicates its identity management and access policy infrastructure in the cloud, then access control decisions can be made independently, but the infrastructure becomes costly and may become out of sync with the internal network, compromising security

Engineering Contradiction:
Improveaccess control synchronizationVSAvoidinfrastructure duplication
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the identity management and access policy infrastructure from the cloud environment and places it exclusively within the enterprise's internal network. The cloud authentication server is removed, and only an authentication redirector remains in the cloud, which redirects authentication requests to the enterprise's internal authentication server. This eliminates the need to duplicate infrastructure while maintaining access control capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an authentication redirector as an intermediary component in the cloud environment. This redirector receives authentication requests from cloud applications, redirects them to the enterprise's internal authentication server, and relays the authentication results back. This mediator enables the cloud to leverage the enterprise's internal infrastructure without direct duplication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the enterprise uses cloud-based authentication server, then access to cloud resources is enabled, but the enterprise loses control over access policy synchronization and security

Engineering Contradiction:
Improvecloud resource accessVSAvoidaccess policy control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent inverts the traditional authentication architecture by placing the authentication server within the enterprise's internal network rather than in the cloud. The cloud application does not directly authenticate users; instead, it redirects authentication requests to the enterprise's internal server. This inversion ensures the enterprise maintains full control over access policies while enabling cloud resource access.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The authentication redirector serves as an intermediary that enables cloud resource access while preserving enterprise control. It receives requests from cloud applications, forwards them to the internal authentication server, and relays results back, allowing the enterprise to maintain policy control without preventing cloud access.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the enterprise implements strict authentication and compliance checks, then security is enhanced, but user access process becomes more complex and time-consuming

Engineering Contradiction:
ImprovesecurityVSAvoidaccess process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary authentication and compliance checks within the enterprise's internal network before users access cloud resources. The authentication server and compliance evaluation component perform security validations in advance, so that once authenticated, users can access cloud resources without repeated checks. This preliminary action enhances security while reducing operational complexity during actual access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the authentication and access control process into distinct components: authentication verification, compliance evaluation, and resource access. The authentication server handles identity verification, the compliance evaluation component checks policy requirements, and the authentication redirector coordinates these steps. This segmentation allows each component to specialize, improving both security and operational efficiency.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8997196B2Flexible end-point compliance and strong authentication for distributed hybrid enterprises
Publication Date: 2015.03.31 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8997196B2 patent drawing
  • US8997196B2 patent drawing
  • US8997196B2 patent drawing

AI summary

Systems, methods and apparatus for accessing at least one resource hosted by at least one server of a cloud service provider. In some embodiments, a client computer sends authentication information associated with a user of the client computer and a statement of health regarding the client computer to an access control gateway deployed in an enterprise's managed network. The access control gateway authenticates the user and determines whether the user is authorized to access the at least one resource hosted in the cloud. If the user authentication and authorization succeeds, the access control gateway requests a security token from a security token service trusted by an access control component in the cloud and forwards the security token to the client computer. The client computer sends the security token to the access component in the cloud to access the at least one resource from the at least one server.