Gateway Authentication Consolidation for Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network access systems require multiple authentication servers, which can lead to inefficiencies and increased complexity in managing authentication requests for accessing remote resources.

Innovation Solution

A computer system and method that consolidates authentication by redirecting authentication requests from a gateway device to a single authentication server, which determines and communicates access authorization to both the requester and the target resource server, thereby streamlining the authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple authentication servers are used to authenticate users and client computers separately, then authentication coverage and security are improved, but device complexity and management difficulty increase

Engineering Contradiction:
Improveauthentication coverageVSAvoidnumber of authentication servers
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple authentication functions into a single authentication server that can handle both user authentication and client computer authentication. The authentication server integrates the functionality of separate authentication servers, allowing it to authenticate both users and client computers using the same device, thereby reducing system complexity while maintaining comprehensive authentication coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication server is designed with multi-functionality to perform both user authentication and client computer authentication. By making the authentication server universal, it can handle different types of authentication requests (user logon and client computer logon) without requiring separate dedicated servers for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple authentication servers are deployed to handle different authentication types, then authentication capability is improved, but loss of time and efficiency deteriorate

Engineering Contradiction:
Improveauthentication capabilityVSAvoidauthentication processing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

By merging multiple authentication functions into a single server, the patent eliminates the time delays associated with communicating between multiple authentication servers. The integrated server can handle both user and client authentication requests locally without requiring inter-server communication, thereby reducing authentication processing time while maintaining versatile authentication capabilities.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If authentication requests are forwarded to separate authentication servers, then authentication security is maintained, but device complexity and ease of operation worsen

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent consolidates multiple authentication servers into a single unified authentication server that maintains security through integrated authentication mechanisms. This consolidation simplifies authentication management operations, as administrators now manage only one server rather than multiple separate servers, while security is maintained through the server's comprehensive authentication capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9515991B2Managing authentication requests when accessing networks
Publication Date: 2016.12.06 KYNDRYL INC
  • US9515991B2 patent drawing
  • US9515991B2 patent drawing
  • US9515991B2 patent drawing

AI summary

Techniques for managing authentication requests. At a gateway device to a network, packets of a message intended for said network are received. Fields within payloads of the packets which contain authentication or authorization information are read. The message is redirected to an authentication server. The authentication server determines that a requester who sent the message to the gateway device is authorized to access a target resource specified in the message and responds to the gateway device that the requester is authorized to access the target resource. The gateway device responds to the requester that the requester is authorized to access the target resource. The gateway device notifies a server hosting the target resource that the requester is authorized to access the target resource. If the gateway device receives a subsequent message from the requester to utilize the target resource, the gateway device forwards the message toward the server.