Enterprise Access Gateway for Cloud Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional solutions for controlling access to resources in cloud computing are costly and may compromise security due to the need to duplicate identity management and access policy infrastructure, which can become out of sync with the internal network, leading to unauthorized access.
Innovation Solution
Implementing an access gateway within the enterprise's internal network that delegates user authentication and authorization tasks, using a security token service to verify user access without duplicating the enterprise's identity management and access policy infrastructure in the cloud, and employing multi-factor authentication and health checks for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the enterprise duplicates its identity management and access policy infrastructure in the cloud, then access control decisions can be made independently, but the infrastructure becomes costly and may become out of sync with the internal network, compromising security
Solution Approach 1:
The patent extracts the identity management and access policy infrastructure from the cloud environment and places it exclusively within the enterprise's internal network. The cloud authentication server is removed, and only an authentication redirector remains in the cloud, which redirects authentication requests to the enterprise's internal authentication server. This eliminates the need to duplicate infrastructure while maintaining access control capabilities.
Solution Approach 2:
The patent introduces an authentication redirector as an intermediary component in the cloud environment. This redirector receives authentication requests from cloud applications, redirects them to the enterprise's internal authentication server, and relays the authentication results back. This mediator enables the cloud to leverage the enterprise's internal infrastructure without direct duplication.
2Ease of operation
If the enterprise uses cloud-based authentication server, then access to cloud resources is enabled, but the enterprise loses control over access policy synchronization and security
Solution Approach 1:
The patent inverts the traditional authentication architecture by placing the authentication server within the enterprise's internal network rather than in the cloud. The cloud application does not directly authenticate users; instead, it redirects authentication requests to the enterprise's internal server. This inversion ensures the enterprise maintains full control over access policies while enabling cloud resource access.
Solution Approach 2:
The authentication redirector serves as an intermediary that enables cloud resource access while preserving enterprise control. It receives requests from cloud applications, forwards them to the internal authentication server, and relays results back, allowing the enterprise to maintain policy control without preventing cloud access.
3Reliability
If the enterprise implements strict authentication and compliance checks, then security is enhanced, but user access process becomes more complex and time-consuming
Solution Approach 1:
The patent implements preliminary authentication and compliance checks within the enterprise's internal network before users access cloud resources. The authentication server and compliance evaluation component perform security validations in advance, so that once authenticated, users can access cloud resources without repeated checks. This preliminary action enhances security while reducing operational complexity during actual access.
Solution Approach 2:
The patent segments the authentication and access control process into distinct components: authentication verification, compliance evaluation, and resource access. The authentication server handles identity verification, the compliance evaluation component checks policy requirements, and the authentication redirector coordinates these steps. This segmentation allows each component to specialize, improving both security and operational efficiency.
Data Source
AI summary
Systems, methods and apparatus for accessing at least one resource hosted by at least one server of a cloud service provider. In some embodiments, a client computer sends authentication information associated with a user of the client computer and a statement of health regarding the client computer to an access control gateway deployed in an enterprise's managed network. The access control gateway authenticates the user and determines whether the user is authorized to access the at least one resource hosted in the cloud. If the user authentication and authorization succeeds, the access control gateway requests a security token from a security token service trusted by an access control component in the cloud and forwards the security token to the client computer. The client computer sends the security token to the access component in the cloud to access the at least one resource from the at least one server.


