Hybrid Cloud Domain Pass-Through Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Facilitating efficient domain pass-through authentication between enterprise application stores and user devices in a hybrid cloud environment is challenging due to difficulties in establishing effective connections and verifying user identities while ensuring security and latency considerations.

Innovation Solution

An internal cloud computing host platform establishes network connections with an external cloud platform, determines accessible resource location connectors, and uses authentication agents to issue one-time tickets or encrypted tokens for user devices to access protected resources, enabling secure and efficient domain pass-through authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If domain pass-through authentication is implemented in a hybrid cloud environment, then user identity verification and secure resource access are improved, but network connection complexity and authentication latency increase

Engineering Contradiction:
Improveuser identity verificationVSAvoidnetwork connection complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication agent as an intermediary component that mediates between the user device and the cloud platforms. This agent simplifies the authentication process by handling the complex verification steps locally, reducing the apparent complexity for users while maintaining reliable identity verification through multiple validation mechanisms including ticket-based authentication and secure token exchange.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into distinct functional components: resource location service for connector discovery, authentication agent for verification, ticketing service for credential management, and cloud configuration service for registration. This segmentation allows each component to handle specific tasks efficiently, reducing overall system complexity while ensuring reliable authentication through specialized processing at each stage.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple resource location connectors are registered for authentication, then authentication reliability is improved, but system complexity and connection establishment time increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidconnection establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-registering multiple resource location connectors with the cloud configuration service before authentication is needed. User devices can query the resource location service to obtain pre-configured connector information, eliminating the need for real-time connector discovery and reducing connection establishment time while maintaining authentication reliability through multiple available connectors.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The resource location service provides feedback to user devices about available connectors and their accessibility status. This feedback mechanism allows the system to dynamically select the most appropriate connector based on current network conditions, reducing connection establishment time while ensuring authentication reliability by having multiple connector options available.

Inventive Principle:
Principle #23Feedback

3Reliability

If secure token encryption and key exchange are performed, then security is improved, but processing time and computational overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system uses token copying and exchange mechanisms where authentication credentials are replicated as secure tokens that can be transmitted and verified without repeatedly performing full cryptographic key exchanges. The authentication agent creates token copies that contain verified identity information, reducing processing time while maintaining security through cryptographic signing and verification of these token copies.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system changes authentication parameters by transitioning from continuous heavy cryptographic operations to efficient token-based verification. Once initial authentication and key exchange are performed, the system uses derived parameters (tokens) that can be verified with lower computational overhead, reducing processing time while maintaining the security established by the initial cryptographic exchange.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3804267B1Domain pass-through authentication in a hybrid cloud environment
Publication Date: 2023.04.26 CITRIX SYSTEMS INC
  • EP3804267B1 patent drawingFigure 1
  • EP3804267B1 patent drawingFigure 2
  • EP3804267B1 patent drawingFigure 3

AI summary

Aspects of the disclosure relate to processing systems using improved domain passthrough authentication techniques. A computing platform may send, to an external cloud computing platform, one or more registration requests that each may cause an RLS endpoint corresponding to each of a plurality of resource location connectors to be stored at the external cloud computing host platform. The computing platform may receive one or more requests for a resource location identifier. The computing platform may determine an accessible resource location connector and may send, to the user device, a corresponding resource location identifier. After receiving a pass-through authentication request, the computing platform may receive, from the ticketing service stored on the external cloud computing platform, a one-time ticket. The computing platform may send, to the user device, the one-time ticket, which may allow the user device to perform pass-through authentication with the external cloud computing platform.