Federated Messaging Cross-Network Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication platforms restrict cross-network communication due to security concerns, preventing users from different corporate networks from securely exchanging messages, files, and video conferencing, as they lack authentication and encryption key distribution mechanisms that are vulnerable to interception and unauthorized access.
Innovation Solution
A federated messaging system with a unified user database that authenticates senders and distributes encryption keys securely across different secure communication networks, allowing users to exchange encrypted communications while ensuring only authorized users access the unified database, thus maintaining high assurance of sender identity and network security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If cross-network communication is allowed without authentication, then communication versatility is improved, but network security deteriorates due to malware introduction and unauthorized access
Solution Approach 1:
The patent introduces a federated identity provider as an intermediary that issues security tokens to authenticate users across different corporate networks. This mediator enables cross-network communication by verifying user identities and granting appropriate access permissions without requiring direct trust between networks, thus improving versatility while maintaining security through centralized authentication.
2Reliability
If encryption keys are distributed across networks, then communication security is improved, but key distribution vulnerability increases due to interception risks
Solution Approach 1:
The patent extracts the key distribution function from the communication protocol itself and separates it into a distinct token-based authentication system. Encryption keys are not distributed directly between communicating parties but are obtained through secure token issuance from a federated identity provider, removing the vulnerable key distribution step from the communication path and eliminating interception risks.
3Reliability
If external network communications are blocked, then network security is improved, but communication functionality deteriorates by preventing legitimate cross-network exchanges
Solution Approach 1:
The patent implements dynamic access control where network blocking rules are not static but adapt based on authentication status. Users who obtain valid security tokens from the federated identity provider are dynamically granted access permissions, allowing the system to maintain security blocks for unauthorized users while enabling legitimate cross-network communications for authenticated users.
Data Source
AI summary
The present disclosure describes a method, system, and non-transitory computer readable medium that includes instructions that permit users of different secure communication networks to exchange secure communications. A secure communication platform includes a user database that allows users from different secure communication networks to access keys for recipients outside of their network. Additionally, the secure communication platform provides a high degree of trust regarding the sender's identity, allowing the receiving network to trust the sender.


