Enterprise Gateway Authentication Proxy for Network Resource Optimization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication and authorization processes for client devices in enterprise systems involve frequent communications, leading to network resource wastage and wear on client devices, as they need to repeatedly authenticate and authorize access to enterprise resources.

Innovation Solution

Implementing a gateway device to manage authentication and authorization processes, acting as a proxy for client devices, which reduces the number of communication calls by negotiating with enterprise resources and storing authentication information, thereby minimizing the processing and storage requirements on client devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If client devices communicate frequently with enterprise resources for authentication and authorization, then access control security is improved, but network resource usage increases and client device wear increases

Engineering Contradiction:
Improveaccess control securityVSAvoidnetwork resource usage
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent introduces an enterprise gateway as an intermediary component that sits between client devices and enterprise resources. The gateway performs authentication and authorization functions centrally, allowing client devices to authenticate once with the gateway and then access multiple resources without repeated authentication cycles. This mediator role reduces the frequency of authentication communications while maintaining security, directly resolving the contradiction between security reliability and network resource consumption

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If client devices communicate frequently with enterprise resources for authentication and authorization, then access control security is improved, but client device wear increases

Engineering Contradiction:
Improveaccess control securityVSAvoidclient device lifespan
Core Design Contradiction:
ReliabilityVSDuration of action of stationary object

Solution Approach 1:

The enterprise gateway serves as a mediator that centralizes authentication and authorization processing. Instead of client devices repeatedly communicating with multiple enterprise resources for authentication, they authenticate once with the gateway which then manages access to resources. This significantly reduces the communication frequency and processing load on client devices, extending their operational lifespan while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If authentication information is stored on client devices, then authentication speed is improved, but device storage and security requirements increase

Engineering Contradiction:
Improveauthentication speedVSAvoiddevice storage and security requirements
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent extracts the authentication information storage function from client devices and relocates it to the enterprise gateway. Client devices send authentication credentials to the gateway, which stores and manages the authentication information centrally. This extraction eliminates the need for client devices to store sensitive authentication data locally, reducing device complexity and security requirements while enabling fast authentication through the gateway's centralized storage and retrieval mechanism

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3138257B1Enterprise system authentication and authorization via gateway
Publication Date: 2019.10.23 CITRIX SYSTEMS INC
  • EP3138257B1 patent drawingFigure 1
  • EP3138257B1 patent drawingFigure 2
  • EP3138257B1 patent drawingFigure 3

AI summary

Methods and systems are disclosed for providing approaches to authenticating and authorizing client devices in enterprise systems via a gateway device. The methods and systems may include passing, by a computing device to an enterprise device, a request transmitted by a client device for access to an enterprise resource, and transmitting, by the computing device, authentication credentials associated with the client device with a request for authorization information associated with the enterprise resource. The methods and systems may also include receiving, by the computing device, the authorization information associated with the enterprise resource, transmitting, by the computing device, the request transmitted by the client device for access to the enterprise resource with the received authorization information associated with the enterprise resource, and passing, by the computing device to the client device, information associated with the requested enterprise resource based on the received authorization information associated with the enterprise resource.