Gateway Authentication via Browser Application for Secure Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for secure access to internal networks from external, potentially non-secure wireless networks are cumbersome for users and vulnerable to attacks, requiring complex setup and authentication processes.
Innovation Solution
A method and gateway system that uses a proxy server and web browser-executable applications to authenticate and authorize terminals, allowing secure access to internal networks via a web browser, using stored authentication data and dynamic connection parameters, with optional encryption and fingerprint protection to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication protocols (LDAP, SAML2.0, Kerberos) are used for secure access to internal networks from external wireless networks, then security is maintained, but user complexity and setup difficulty increase significantly
Solution Approach 1:
The patent introduces a gateway as an intermediary component between the external wireless network and the internal secure network. This gateway simplifies the authentication process by providing a unified access point that handles security protocols, thereby reducing user complexity while maintaining security through centralized control and protocol management.
Solution Approach 2:
The gateway is designed with multi-functional capabilities, supporting multiple authentication protocols (LDAP, SAML2.0, Kerberos) and access methods simultaneously. This universal approach allows diverse authentication mechanisms to be managed through a single interface, reducing the need for users to understand multiple complex protocols while maintaining comprehensive security coverage.
2Reliability
If complex authentication protocols and service directory queries are implemented for secure access control, then access security is ensured, but authentication time and processing delay increase
Solution Approach 1:
The gateway performs preliminary authentication actions by pre-establishing security contexts and caching authentication states. When authentication requests arrive, the gateway can quickly verify credentials against pre-loaded service directory information, reducing the time required for real-time directory queries while maintaining security verification integrity.
Solution Approach 2:
The gateway creates simplified copies or representations of authentication data and service directory information locally. Instead of performing complex real-time queries to the central service directory for every authentication request, the gateway uses local copies for rapid verification, significantly reducing authentication time while maintaining security through periodic synchronization with the central directory.
3Adaptability or versatility
If terminals connect directly to internal networks from external wireless networks, then access flexibility is improved, but network security and vulnerability to malicious attacks increase
Solution Approach 1:
The gateway serves as a security intermediary that all external access requests must pass through. It provides adaptability by supporting multiple access methods and protocols while maintaining security by enforcing authentication and authorization policies at the gateway layer, preventing direct connections that would expose the internal network to external threats.
Solution Approach 2:
The network architecture is segmented into external access zone (wireless network), gateway zone (security boundary), and internal secure zone. This segmentation allows flexible access from external networks while isolating the internal network from direct exposure to external threats. The gateway acts as the controlled boundary between segments, managing all transitions and enforcing security policies.
Data Source
AI summary
One embodiment is an authentication method comprising on receiving a request from the web browser of the terminal, the request including a user identifier, obtaining authentication data that is associated with the user identifier and that is stored in a database of the internal network, configuring a proxy server authorizing access via the access security entity to the internal network for a determined set of connection parameters, generating a first application from the connection parameters of the set, which application is protected using at least one determined portion of the authentication data and being configured to, on being executed by the web browser, set up a connection between the terminal and the proxy server using the parameters, this being done in response to the at least determined portion of the authentication data being supplied and transmitting the first application to the web browser of the terminal.


