Centralized Identity Broker for Distributed Firewall Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security architectures for IoT devices are inadequate, particularly due to limited processing power, memory, and user interface constraints, making it difficult to integrate them into existing client-server security systems, and traditional network access control methods rely on directory agents that may not ensure reliable or timely updates, especially for distributed firewalls.
Innovation Solution
A system that centrally manages user identities and access policies across distributed firewalls using a broker that receives identity awareness data from directory services, posts it to a distributed data repository, and uses this data to establish firewall rules for controlling network traffic, eliminating the need for individual directory agents at each firewall.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional directory agents are used at each firewall for IP-to-user mappings, then firewalls can control network access based on user identities, but connectivity to directory agents may be unreliable and updates may not be timely
Solution Approach 1:
The patent introduces a centralized identity management server as an intermediary between firewalls and directory agents. This server consolidates IP-to-user mapping data and distributes it to multiple firewalls, eliminating the need for each firewall to directly connect to directory agents. The intermediary resolves the contradiction by providing reliable, centralized access to identity data while simplifying the overall system architecture.
Solution Approach 2:
The patent merges the identity management functionality from multiple distributed directory agents into a single centralized server. Instead of having separate directory agents at each firewall location, the system combines all IP-to-user mapping capabilities in one central repository that serves all firewalls, thereby improving reliability and reducing complexity.
2Adaptability or versatility
If each firewall maintains its own directory agent for access control, then firewalls can operate independently, but updating all firewalls with latest mappings becomes difficult when new firewalls are deployed
Solution Approach 1:
The centralized identity management server acts as an intermediary that automatically distributes updated IP-to-user mappings to all firewalls in the network. When new firewalls are deployed or mappings are updated, the central server pushes the latest data to all connected firewalls simultaneously, eliminating manual update processes and reducing the time required to maintain consistent access control across the entire firewall fleet.
3Ease of operation
If IoT devices are integrated into existing client-server security systems, then network access control can be provided, but limited processing power, memory, and user interface elements make integration difficult
Solution Approach 1:
The patent extracts the complex identity management and authentication logic from the IoT devices themselves and places it in the centralized identity management server. IoT devices only need to present their identities for access control decisions, while the heavy lifting of maintaining IP-to-user mappings, authentication policies, and access control logic is performed by the centralized server. This extraction simplifies IoT device integration while maintaining comprehensive security control.
Data Source
AI summary
In an embodiment, a computer-implemented method comprises receiving, by at least one broker computing devices, identity awareness data from a plurality of directory services in a federation; posting, by the at least one broker computing device, the identity awareness data to a distributed data repository; establishing, at a networking hardware device having a first type, firewall rules using the identity awareness data from the distributed data repository; controlling, by the networking hardware device having the first type, network traffic based on the identity awareness data.


